Trust Framework legislation

Measures are in place to protect the information of people, businesses and organisations.

Rules and regulations for digital identity services

Providers must show they meet these rules and regulations to become accredited with the mark under the trust framework for digital identity services.

Rules for digital identity services

The trust framework rules set out the operational requirements for how accredited services are provided, in order to have a safe and trusted digital identity environment. They define how people and organisations should work together to consent to share or validate a user’s information.

Rule categories

The trust framework rules are split into several categories. To become accredited, digital identity service providers must meet the relevant rules for their type of service. This can be more than one category of rules depending on what that service is.

Identification management

Determining the accuracy of information, binding that information to the correct individual or organisation, and enabling the secure reuse of the information.

Privacy and confidentiality

Maintaining the privacy and confidentiality of the information of individuals and organisations.

Security and risk

Ensuring that information is secure and protected from unauthorised modification, use, or loss.

Information and data management

Record-keeping and format of personal and organisational information, to ensure a common understanding of what is shared.

Sharing and facilitation

The sharing of information with relying parties, including authorisation processes. Rules consultation.

Regulations for digital identity services

Digital Identity Services Trust Framework Regulations 2024 (SL 2024/197) – New Zealand Legislation website