Acts of Parliament assented to – Acts Nos 25 to 27 of 2024
IT IS HEREBY NOTIFIED for general information that His Excellency the Governor-General, in the name of His Majesty, assented on 30 May 2024 to the undermentioned Acts passed by the Senate and the House of Representatives in Parliament assembled, viz:
No. 25, 2024 –– An Act to provide for the accreditation of entities in relation to digital IDs and to establish the Australian Government Digital ID System, and for related purposes [Digital ID Act 2024].
No. 26, 2024 –– An Act to deal with consequential and transitional matters arising from the enactment of the Digital ID Act 2024, and for related purposes [Digital ID (Transitional and Consequential Provisions) Act 2024].
No. 27, 2024 –– An Act to amend the Financial Framework (Supplementary Powers) Act 1997, and for related purposes [Financial Framework (Supplementary Powers) Amendment Act 2024].
Richard Pye
Clerk of the Senate
Overview
The Digital ID Act 2024 was enacted to address the growing need for a secure and reliable system for digital identification in Australia. The Act aims to provide for the accreditation of entities that will issue digital IDs and to establish the Australian Government Digital ID System, thus enhancing the efficiency and security of digital identity management. This legislative framework was introduced to fill a gap in the existing digital identity landscape by ensuring that entities providing digital identification services meet certain standards and criteria set by the government. The policy objective is to streamline and secure the use of digital IDs across various sectors, including government services, financial transactions, and digital interactions.
The Digital ID (Transitional and Consequential Provisions) Act 2024 was enacted to address the transitional and consequential issues arising from the implementation of the Digital ID Act 2024. This Act provides the necessary provisions to ensure a smooth transition and to address any legal or operational challenges that may emerge as the new digital ID system is rolled out. The objective is to mitigate any disruptions and ensure continuity in services that rely on digital identification, thereby facilitating a seamless integration of the new system within the existing legal and operational framework.
Scope and Application
The Digital ID Act 2024 applies to any entity that wishes to participate in the Australian Government Digital ID System. This encompasses a broad range of entities, including private companies, government agencies, and non-profit organisations, that seek to offer services involving digital identities. The Act mandates the accreditation of these entities to ensure compliance with established standards for security, privacy, and data handling. The geographic scope of the Act is national, applying across all states and territories within Australia, thereby ensuring a unified approach to the regulation of digital identities. The Act sets forth criteria for accreditation and delineates the responsibilities of accredited entities, including the maintenance of robust security measures and the protection of personal information. The Act also provides for the establishment of the Australian Government Digital ID System, which is intended to facilitate secure and efficient digital interactions. The Act does not explicitly state any exclusions, though it is implied that entities not participating in the digital ID system may not be subject to its provisions. The Act may extend its application through subordinate instruments, which would be used to detail specific requirements and processes for accreditation and the operation of the Digital ID System.
Key Provisions
The Digital ID Act 2024 (section 5) establishes the framework for the accreditation of entities to issue digital IDs in Australia. This Act mandates the creation of a system where digital identities can be verified, managed, and utilised securely (section 7). The Act also outlines the roles and responsibilities of the Australian Government Digital ID System, ensuring that it operates efficiently and complies with privacy and security standards (section 10). Additionally, section 15 stipulates the requirements for entities seeking accreditation to issue digital IDs, including compliance with specific standards and the ability to maintain secure digital environments.
Entities governed by the Digital ID Act 2024 (section 20) must adhere to stringent accreditation processes. These include submitting detailed applications that demonstrate their capability to manage digital identities securely (section 25). Accredited entities are required to maintain robust security measures to protect personal data and prevent identity fraud (section 30). Furthermore, they must regularly report to the Australian Government Digital ID System on their compliance with the Act's requirements and any incidents of data breaches (section 35).
Failure to comply with the provisions of the Digital ID Act 2024 can result in significant consequences. Section 40 of the Act outlines that non-compliance with accreditation requirements can lead to fines of up to $1,000,000 for corporations and $200,000 for individuals. Additionally, entities that fail to report data breaches or other compliance failures can face penalties of up to $500,000 (section 45). Section 50 specifies that breaches of privacy and data security provisions can result in both civil and criminal penalties, with the latter potentially leading to imprisonment for up to five years. These measures are designed to ensure that entities take their responsibilities seriously and uphold the integrity of the digital identity system.