Main laws

New Zealand Act

Digital Identity Services Trust Framework Act 2023

It creates governance, accreditation marks, a public register, complaints and enforcement processes.

In forceNew ZealandPlain-English guide6 practical checks

Plain-English explainers, not legal advice. Use the linked official source for section-level detail, and get advice for your situation.

Get legal help

Start here

Quick read

  • This Act affects businesses that develop, operate, or rely on digital identity services.
  • It introduces accreditation for providers, ongoing duties for handling identity information, and controls on using accreditation marks.

Likely relevant if

  • Businesses developing or operating digital identity products that enable users to share personal or organisational information digitally
  • Fintech, payments, and lending businesses using digital identity tools for customer onboarding or verification
  • Online marketplaces, platforms, and service providers relying on identity information in transactions

Check first

  • Only collect, use, or share personal or organisational information for accredited services when authorised and compliant with TF rules and regulations
  • Use accreditation marks strictly according to the TF authority’s published terms
  • Maintain required records and provide information to the TF authority as required or on request once regulations specify these obligations

What this Act does

The Act creates a formal trust framework for digital identity services in New Zealand. It enables certain digital identity services and their providers to become accredited, identified as accredited, and monitored through a dedicated governance structure.

This framework aims to increase trust and security in digital identity transactions for individuals and organisations.

Practical sense check

  • Check if your product or workflow allows users to share personal or organisational identity information digitally
  • Decide if your business wants to become accredited or use an accredited provider
  • Review marketing, contracts, or onboarding materials for references to accreditation
  • Ensure your team understands the Act covers both individuals and organisations in identity transactions
  • Assess if your service involves identity verification, linking identity information, or secure sharing

Who is in scope and who is usually out

The Act primarily targets accredited digital identity providers (TF providers) and the accredited services they offer. It also applies to relying parties - businesses or organisations that depend on information shared through accredited services.

Businesses that are not accredited providers but use digital identity services should understand the meaning and limits of accreditation. The Act prohibits anyone from falsely representing themselves or their services as accredited.

Everyday trigger points for businesses

The Act becomes relevant at common business moments, not only during regulatory investigations. Key trigger points include launching identity products, applying for accreditation, updating service details, or responding to security or privacy incidents.

Practical sense check

  • Launching a digital identity product or feature
  • Applying for accreditation, renewal, reconsideration, or provisional accreditation
  • Changing key business information after applying or becoming accredited
  • Using an accreditation mark on websites, apps, proposals, or customer documents
  • Responding to requests for information from the TF authority

Core obligations for accredited providers

Accredited providers must follow ongoing duties under the Act. They must only collect, use, or share personal or organisational information when authorised and in compliance with TF rules and regulations. Providers must maintain governance, records, and incident response processes that support the accredited service.

Practical sense check

  • Confirm authorisation before handling personal or organisational information
  • Identify and comply with applicable TF rules and regulations for each accredited service
  • Control the use and display of accreditation marks according to TF authority terms
  • Maintain records as required once regulations specify record-keeping obligations
  • Notify the TF authority promptly of changes to key or specified information

Accreditation marks, the register and marketing claims

The Act authorises the use of accreditation marks approved by the TF board to identify accredited services. The TF authority publishes terms of use for these marks, which providers must follow.

Businesses relying on accredited services should verify providers using the public register before integrating or promoting their services.

Complaints, enforcement and penalties

The Act provides a complaints process, dispute resolution scheme, and investigation powers for the TF authority. Remedies for breaches include public warnings, additional record-keeping or reporting requirements, compliance orders, suspension, or cancellation of accreditation.

The Act creates offences with penalties for misrepresenting accreditation status, providing false information, or obstructing the TF authority.

Practical sense check

  • Misrepresenting yourself or your service as accredited: fine up to $50,000 for individuals, $200,000 for bodies corporate
  • Using accreditation marks without authorisation or contrary to terms: similar penalties apply
  • Providing false or misleading information to the TF authority: fines up to $50,000 for individuals, $200,000 for bodies corporate
  • Obstructing or hindering the TF authority in its functions: fines up to $50,000 for individuals, $200,000 for bodies corporate
  • Failure to comply with compliance or enforcement orders can lead to suspension or cancellation of accreditation

For small or growing providers, governance weaknesses such as inaccurate accreditation claims, poor change notification, or incomplete records pose the greatest risk. These issues can escalate to enforcement actions or offences.

Common questions

Does the Act require all digital identity services to be accredited?

No. The Act does not ban non-accredited digital identity services but prohibits misrepresenting them as accredited.

What penalties apply for misusing accreditation marks?

Individuals can be fined up to $50,000 and bodies corporate up to $200,000 for misuse or false representation related to accreditation marks.

When does the Act come into force?

The Act comes into force on dates set by Order in Council, or if not brought into force earlier, on 1 July 2024.

Are privacy obligations affected by this Act?

No. The Privacy Act 2020 continues to apply alongside the Digital Identity Services Trust Framework Act.

Who should notify the TF authority of changes to key information?

Accredited providers must notify the TF authority of changes to key or specified information as required by the Act.

Related topics

How Sprintlaw can help