New Zealand - Digital Identity Services (2024)

Digital Identity Services Trust Framework Rules 2024

New Zealand

RAI-NZ-NA-DISTRXA-2024
Effective: November 7, 2024
In Force (Amended)(In Force (Amended))
RegulationGovernance and OversightConformity Assessment and RegistrationData Protection and Privacy
Export PDF

The Digital Identity Services Trust Framework Rules 2024 set technical, operational, privacy and security requirements for providers seeking accreditation under New Zealand's Trust Framework. They establish service-specific rules (information, binding, authentication, credential, facilitation), privacy minimisation, security governance, information management and authorisation requirements to support trusted digital identity services.

Summary

The Digital Identity Services Trust Framework Rules 2024 (the Rules) implement the operational and technical requirements that Trust Framework providers and their accredited services must meet to obtain and maintain accreditation under the Digital Identity Services Trust Framework Act 2023. The Rules define the scope of accredited services — information, binding, authentication, credential and facilitation services — and prescribe standards and assurance requirements for each category. They require Trust Framework providers to follow specified Identification Standards (Information Assurance Standard, Binding Assurance Standard, Authentication Assurance Standard, Federation Assurance Standard and other referenced standards such as W3C Verifiable Credentials and relevant ISO standards) when issuing, binding, authenticating, presenting, revoking and managing credentials.

Privacy and data minimisation are core elements: the Rules require minimising privacy risk, ethical information management, adherence to the Privacy Act 2020, explicit user consent for sharing, and recordkeeping obligations. Security and risk management provisions mandate security governance, information security controls (aligned with the New Zealand Information Security Manual where applicable), physical and personnel security, threat and risk reviews, incident reporting, and regular reviews of security management plans. The Rules also require applicants for accreditation to obtain independent evaluations in security, privacy and identification management, and set out criteria for assessment of providers and services, including requirements that providers be New Zealand residents or government agencies and do not pose a risk to national security or interests.

Regulatory and administrative provisions are set out in accompanying Regulations (SL 2024/197) and in the Digital Identity Services Trust Framework Act 2023. The Regulations prescribe accreditation processes, required application information, certification of third-party assessors, accreditation duration (three-year expiry by default), complaints and dispute resolution procedures, six-monthly and annual reporting, incident notification, and retention/secure storage obligations. The Rules are intended to be living documents, amended periodically (approximately twice yearly) to keep pace with technical developments; consolidated and amendment versions are published by the Department of Internal Affairs. Enforcement mechanisms include accreditation suspension, revocation, notice and remedial requirements under the Act and Regulations, and expectations of public and industry reporting. The Rules emphasise interoperability, portability, and alignment with international standards to facilitate secure, portable digital credential ecosystems while protecting fundamental rights and privacy.

Full article

Read full text ↗

Overview

The Digital Identity Services Trust Framework Rules 2024 (the Rules) provide the operational, technical and governance requirements that Trust Framework providers must meet to become and remain accredited under the Digital Identity Services Trust Framework Act 2023. They cover five accredited service categories — information, binding, authentication, credential and facilitation — and require conformance with specified Identification Standards and recognised technical standards such as the W3C Verifiable Credentials and relevant ISO standards. The Department of Internal Affairs publishes and maintains the Rules and consolidated versions; the authoritative consolidated PDF is published by the Department of Internal Affairs. The Rules are designed to support secure, privacy-preserving, and interoperable digital identity transactions between users and relying parties, while setting expectations for security governance, privacy safeguards, recordkeeping and independent evaluation. For the official consolidated Rules and guidance, see the Department of Internal Affairs Trust Framework pages and the consolidated PDF available from the Department. Department of Internal Affairs - Trust Framework and Digital Identity Services Trust Framework Rules 2024 (consolidated PDF).

Definitions

The Rules include precise definitions to ensure consistent interpretation across the Trust Framework. Key defined terms include accredited digital identity service (information, binding, authentication, credential, facilitation), authenticator, binding, binding assurance, authentication assurance, credential, derived assertion, facilitation mechanism (e.g., digital wallets), flash pass (non-cryptographic presentation) and portability. Many definitions cross-reference the Digital Identity Services Trust Framework Act 2023, the Privacy Act 2020 and the New Zealand Information Security Manual (NZISM). The Rules distinguish between Actors (TF providers, users, relying parties, verifiers, issuers) and System Components (facilitation mechanisms, credential services, binding and authentication services) to allocate obligations and assurance requirements clearly.

Governance and Institutional Framework

The Department of Internal Affairs administers the Rules (acting as the administering agency) and the Trust Framework Authority (TF Authority) established under the Act oversees accreditation, the register of accredited providers, and compliance activities. The Trust Framework Board advises on updates and standards; the Minister for Digitising Government makes the Rules on the Board’s recommendation. The Regulations (SL 2024/197) set the process for applications, certification of third-party assessors, independent evaluations and accreditation duration. Accreditation decisions require evidence of organisational capability, security and privacy controls, complaints processes, and national interest/security checks. The framework mandates public-facing complaints procedures and industry dispute resolution where applicable, and requires providers to submit periodic reporting, incident notifications and retain records in secure storage. See the TF legislation and the Regulations for procedural roles: Digital Identity Services Trust Framework Regulations 2024 and the Department of Internal Affairs Trust Framework pages (DIA Trust Framework).

Key Focus Areas

The Rules concentrate on several interlocking policy and technical areas. Identification management ensures attributes and entity binding meet Information Assurance, Binding Assurance and Authentication Assurance standards. Credential lifecycle controls mandate adherence to the Federation Assurance Standard and approved credential formats (W3C Verifiable Credentials or specified ISO standards); credentials must be revocable and support portability. Privacy rules require minimisation of privacy risk, ethical information management, and alignment with the Privacy Act 2020; user consent and clear authorisation flows are emphasised (including informed authorisations). Security and risk rules cover security governance, information security aligned with NZISM, physical and personnel security, security risk assessments and security management plans with periodic reviews. Information and data governance rules prescribe recordkeeping, retention periods, secure storage/disposal and reporting. The Rules also include operational controls for facilitation services (wallets) such as presentation behaviours, prohibitions on server retrieval in some contexts, and guidance on preventing flash-pass reliance without cryptographic verification.

Implementation Framework

Implementation is operationalised through accreditation, independent evaluation and conformity processes. Applicants must submit comprehensive profile information (Schedules 2 and 3), independent evaluations in security, privacy and identification management, and evidence that they are New Zealand residents or NZ government agencies (or meet the residency criteria) and will not present national security risks. The TF Authority may certify third-party assessors to undertake evaluations. Accreditation typically expires after three years unless renewed. The Rules and Regulations set procedural requirements for application content, assessment criteria and documentation standards. Providers must implement security management plans, privacy impact assessments, information and data management plans, and maintain an accessible complaints process that accounts for tikanga Māori where applicable. The Department of Internal Affairs publishes guidance, consolidated rules and amendment notices and seeks targeted consultation when technical changes are proposed. The consolidated Rules and amendment history are available from the Department of Internal Affairs and are updated periodically.

Monitoring and Evaluation

Monitoring relies on multiple mechanisms: independent evaluations on application, periodic reporting (six-monthly and annual reports required by the Regulations), incident notification obligations, on-site or remote assessments, and the TF Authority’s oversight powers. The Rules encourage continuous review cycles for security and privacy controls (security management plan reviews, information and privacy plan reviews) and specify recordkeeping and retention obligations to support audits and investigations. The Department of Internal Affairs publishes amendment timelines and engages in targeted consultation given the technical nature of the rules; the Board recommends rule changes to the Minister, and the Minister makes the Rules formally via Gazette notice. Providers are expected to support regulatory oversight by furnishing reports and cooperating with audits and independent evaluators.

Penalties, Liability, and Appeals

The Rules sit within a regulatory architecture that includes corrective and enforcement measures under the Act and associated Regulations. Enforcement tools include accreditation conditions, requirements to implement remediation, suspension or revocation of accreditation, and publication of enforcement actions. Providers must maintain complaints processes and cooperate with dispute resolution mechanisms. Liability and redress follow from the Act’s enforcement framework and general civil remedies (including contractual liabilities and liabilities under privacy and consumer protection law). Appeals and review procedures are available through statutory channels (administrative review processes and judicial review where applicable). The Regulations also require accessible complaints handling and industry-specific dispute resolution where available, helping provide routes for affected users and relying parties to seek resolution.

Relationship to Other Instruments

The Rules are tightly linked to the Digital Identity Services Trust Framework Act 2023 and to the Digital Identity Services Trust Framework Regulations 2024 (SL 2024/197). They cross-reference the Privacy Act 2020, the New Zealand Information Security Manual (NZISM), and identification standards published by the Department of Internal Affairs. Technical interoperability provisions reference W3C and ISO standards for verifiable credentials and mobile driving licences (ISO 18013-5). The Rules do not create a central identity database; instead, they prescribe how distributed credentials and facilitation services should operate while ensuring privacy-preserving practices consistent with existing privacy and information security law. See the Act and Regulations for statutory authority, and the NZISM and Privacy Act for complementary obligations.

International Alignment

The Rules promote alignment with recognised international technical standards and best practices to support interoperability and portability of credentials across borders. Credential formats authorised in the Rules include the W3C Verifiable Credential Data Model and relevant ISO series (e.g., ISO 18013-5, ISO 23220), reflecting an explicit policy decision to rely on widely-adopted standards. The framework also recognises the importance of international security standards and prudent cryptographic practices and anticipates periodic review of cryptographic method requirements to remain consistent with global developments. The Department of Internal Affairs monitors international developments and may update the Rules to maintain compatibility with international credential and identity ecosystems.

Implementation Timeline

EventDateNotes
Order in Council (Regulations made)2024-09-23Regulations enacted by Governor-General in Council.
Gazette notice of Rules2024-10-11Minister for Digitising Government notified the Rules will come into force.
Rules come into force (original)2024-11-08Original Rules commencement date per Gazette.
Regulations commencement2024-10-24Regulations came into force to establish accreditation processes.
Consolidated Rules (amendment)2025-07-24Consolidated version incorporating 2025-1 amendments published by DIA.

Compliance Checklist

RequirementCompliant? (Yes/No)Evidence
Provider is a New Zealand resident or NZ government agencyYes/NoCompany formation documents; residency evidence
Independent evaluations for security, privacy, identificationYes/NoIndependent evaluator reports
Security management plan and periodic reviewYes/NoPlan document; review logs
Privacy impact assessment and data minimisation measuresYes/NoPIA documentation; design artifacts
Credential format compliance (W3C or ISO)Yes/NoTechnical specification; conformance test results
Complaints process publicly availableYes/NoPublished complaints policy; dispute resolution links

Sources and References

SourceType
Department of Internal Affairs — Trust Framework for Digital Identity (rules and consolidated PDF links)Primary Source
Digital Identity Services Trust Framework Rules 2024 (consolidated PDF) — Department of Internal AffairsPrimary Source
Digital Identity Services Trust Framework Regulations 2024 (SL 2024/197) — New Zealand LegislationPrimary Source
Notification of Digital Identity Services Trust Framework Rules 2024 — New Zealand GazettePrimary Source

© Regulations.AI · updated on 13-Jun-2026