EXPLANATORY STATEMENT
Issued by authority of the Minister for Finance
Digital ID Act 2024
Digital ID Amendment (Redress Framework and Other Measures) Rules 2025
Section 168 of the Digital ID Act 2024 (Digital ID Act) provides that the Minister may, by legislative instrument, make rules prescribing matters required or permitted by the Digital ID Act to be prescribed by the rules, or necessary or convenient to be prescribed for carrying out or giving effect to the Digital ID Act.
The Digital ID Act establishes a legal framework for a secure and voluntary digital ID system in Australia, enabling individuals to verify their identity online when interacting with government and businesses, while regulating and accrediting service providers to ensure strong governance, security, and consumer protections.
The Digital ID Rules 2024 (Digital ID Rules) establish a robust legal framework governing applications and obligations to participate in the Australian Government Digital ID System (AGDIS).
The Digital ID Amendment (Redress Framework and Other Measures) Rules 2025 (Amendment Rules) amend the Digital ID Rules to strengthen support for users of digital ID services within the AGDIS and improve the efficient operation and regulation of the AGDIS. In particular, the Amendment Rules:
Establish a redress framework under section 88 of the Digital ID Act for cyber security and digital ID fraud incidents relating to accredited services within the AGDIS (Schedule 1).
Establish a streamlined application for approval to participate in the AGDIS, for Commonwealth, State or Territory government relying parties that are receiving previously approved services due to machinery of government (MOG) changes (Schedule 2).
Authorise the Digital ID Data Standards Chair to use the digital ID accreditation trustmark (Schedule 3).
Improve the System Administrator’s oversight of cyber security incidents and digital ID fraud incidents (Schedule 4).
Make transitional provisions for the Amendment Rules amendments (Schedule 5).
Details of the Amendment Rules are set out in Attachment A.
Consistent with the requirements of section 169 of the Digital ID Act and section 17 of the Legislation Act 2003, an exposure draft of the Amendment Rules and its accompanying explanatory statement was publicly consulted upon for a period of at least 28 days from 18 September 2025 to 17 October 2025. During this period, the Department also undertook consultation webinars, virtual roundtables and bilateral meetings, including with organisations representing individuals who may experience barriers when creating or using digital ID.
The Department received 51 submissions, approximately half of which provided feedback about the exposure draft rules. The Department received feedback from a range of parties, including consumer and privacy advocates, inclusion representatives, government agencies, and digital ID service providers.
A Statement of Compatibility with Human Rights is at Attachment B. The Amendment Rules are compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011, and to the extent that they may engage human rights, those limitations are reasonable, necessary and proportionate.
The Amendment Rules are a legislative instrument for the purposes of the Legislation Act 2003.
The Amendment Rules commence on the day after the instrument is registered on the Federal Register of Legislation.
GLOSSARY
This Explanatory Statement uses the following abbreviations and acronyms.
Abbreviation | Definition |
AGDIS | Australian Government Digital ID System |
ASP | Attribute Service Provider |
Data Standards Chair | Digital ID Data Standards Chair |
Digital ID Regulator | The Digital ID Regulator is the Australian Competition and Consumer Commission as defined in section 90 of the Digital ID Act |
ISP | Identity Service Provider |
IXP | Identity Exchange Provider |
MOG | Machinery of government |
Attachment A
Details of the Digital ID Amendment (Redress Framework and Other Measures) Rules 2025
Section 1 – Name
1.1. This section provides that the name of this instrument is the Digital ID Amendment (Redress Framework and Other Measures) Rules 2025 (Amendment Rules).
Section 2 – Commencement
1.2. This instrument commences the day after this instrument is registered on the Federal Register of Legislation.
Section 3 – Authority
1.3. This section provides that this instrument is made under section 168 of the Digital ID Act 2024 (Digital ID Act).
1.4. Section 168 of the Digital ID Act enables the Minister to make legislative instruments, such as the Amendment Rules. The purpose of this section is to set out the authority under which this instrument is made.
Section 4 – Schedules
1.5. This section provides that each instrument that is specified in a Schedule to this instrument is amended or repealed as set out in the applicable items in the Schedule concerned, and any other item in a Schedule to this instrument has effect according to its terms.
1.6. The purpose of this section is to provide for how the amendments in this instrument operate.
Schedule 1—Redress framework
Overview
1.7. Subsection 88(1) of the Digital ID Act relevantly provides that the Digital ID Rules 2024 (Digital ID Rules) must provide for or in relation to a redress framework for incidents that occur in relation to accredited services of accredited entities that are provided within the Australian Digital ID System (AGDIS). The redress framework must be provided for within 12 months of commencement of the Digital ID Act, which was 30 November 2024.
1.8. Subsection 88(2) of the Digital ID Act sets out a list of matters that the Digital ID Rules made for the purposes of subsection 88(1) must deal with.
1.9. Schedule 1 to the Amendment Rules provides for a redress framework for cyber security incidents and digital ID fraud incidents that occur in relation to accredited services of accredited entities within the AGDIS.
1.10. The AGDIS is the digital ID system overseen and maintained by the Digital ID Regulator in accordance with section 58 of the Digital ID Act. The Digital ID Act deals with the accreditation of digital ID services that may operate within digital ID systems including but not limited to the AGDIS. The Digital ID Regulator is supported by the System Administrator who, in accordance with section 95 of the Digital ID Act, is responsible for identifying and managing operational risks, including managing digital ID fraud and cyber security incidents in relation to the AGDIS.
1.11. Chapter 4 of the Digital ID Rules generally prescribes arrangements relating to notifying the System Administrator of incidents in relation to the AGDIS. The redress framework in Chapter 4A augments these existing incident management obligations, to ensure that individuals affected by cyber security and digital ID fraud incidents are appropriately supported. The redress framework focusses on cyber security and digital ID fraud incidents that occur in relation to accredited entities, as these are the kinds of incidents which may result in an adverse outcome or harm for individuals.
1.12. Consistent with the revised Explanatory Statement to the Digital ID Act, the purpose of this redress framework is to support individuals’ ability to efficiently deal with and get assistance in relation to digital ID fraud incidents and cyber security incidents occurring in relation to accredited services provided within the AGDIS.
1.13. Providing individuals with access to appropriate redress is an important element in ensuring the integrity of the AGDIS. It encourages participating accredited entities to be accountable for incidents that occur in relation to their services and to strive for continued improvement, and promotes public confidence in the safeguards and outcomes of using digital ID.
1.14. To support the successful uptake of digital ID by entities and individuals, the redress framework must balance the regulatory burden on entities, which may disincentivise participation in the AGDIS, with the need to provide meaningful redress to affected individuals within the AGDIS, thereby fostering public confidence in the system.
1.15. The Amendment Rules seek to balance these policy considerations by establishing a redress framework that places the following requirements on certain entities within the AGDIS:
to make reasonable attempts to notify individuals affected by a digital ID fraud incident or cyber security incident, where appropriate;
to refer unresolved technical issues which result in an individual being unable to use their digital ID to the System Administrator in certain circumstances, who may then recommend a course of action to the entity;
to provide information, support and assistance to individuals affected by cyber security or digital ID fraud incidents in certain circumstances;
to develop and publish policies relating to complaints;
to develop and publish policies relating to the identification, management and resolution of cyber security incidents and digital ID fraud incidents.
1.16. These requirements include matters which must be dealt with by the Digital ID Rules made for the purposes of subsection 88(1) of the Digital ID Act.
1.17. The redress framework complements broader Commonwealth legislation, such as the Privacy Act 1988 (Privacy Act). It also complements pre-existing provisions in the Digital ID Rules and the Digital ID (Accreditation) Rules 2024 (Accreditation Rules) that deal with providing support and assistance to individuals in relation to cyber security incidents and digital ID fraud incidents. In this way, the digital ID legislative framework will ensure that appropriate safeguards and redress mechanisms are in place for users of digital ID services within the AGDIS.
Item 1 – Rule 1.4 (note 1)
1.18. Item 1 substitutes Note 1 to rule 1.4 Definitions.
1.19. The new Note 1:
includes one additional expression - digital ID fraud incident,
renumbers the items to maintain alphabetical order for the list of expressions, and
inserts a pinpoint reference to section 9 of the Digital ID Act in the chapeau to the Note.
1.20. The effect of Item 1 is to inform the reader that the term digital ID fraud incident, as well as the other expressions listed in Note 1, are defined in section 9 of the Digital ID Act.
Item 2 – Rule 1.4 (note 2)
1.21. Item 2 inserts a pinpoint reference in the chapeau to Note 2 to rule 1.4 Definitions.
1.22. The pinpoint reference clarifies that the expressions listed in Note 2 are defined in rule 1.4 of the Accreditation Rules.
Item 3 – After Chapter 4
1.23. This amendment inserts ‘Chapter 4A – Redress Framework’ after Chapter 4 of the Digital ID Rules.
1.24. New Chapter 4A provides for a redress framework in the Digital ID Rules. It contains 5 Parts, with each part dealing with one or more of the matters which the Digital ID Rules must deal with under subsection 88(2) of the Digital ID Act:
Part 1 – Preliminary deals with entities that are covered by the framework, which relates to paragraph 88(2)(a) of the Digital ID Act.
Part 2 – Notifying affected individuals of incidents deals with the matters required by paragraphs 88(2)(b) and (d) of the Digital ID Act.
Part 3 – Referring unresolved technical issues to the System Administrator deals with the matters required by paragraphs 88(2)(b) and (c) of the Digital ID Act.
Part 4 – Providing information, support and assistance to individuals affected by incidents deals with the matters required by 88(2)(e) of the Digital ID Act.
Part 5 – Policies relating to incidents and complaints deals with the matters required by paragraphs 88(2)(b), (f) and (g) of the Digital ID Act.
1.25. The redress framework provides new requirements on Attribute Service Providers (ASP) and Identity Service Providers (ISP) participating in the AGDIS, or whose approval to participate has been suspended or revoked. The scope of this framework strikes a careful balance between the risk of harm to individuals and the AGDIS, as well as the regulatory burden on participating entities.
Part 1 – Preliminary
4A.1 Application of this Chapter
1.26. Subrule 4A.1(1) relevantly provides that, for the purposes of subsection 88(1) of the Digital ID Act, this Chapter provides for a redress framework for incidents that occur in relation to accredited services within the AGDIS.
1.27. Subrule 4A.1(2) sets out the entities to which this Chapter applies. Relevantly, it provides that this Chapter applies to an ASP or an ISP that is a participating entity, or an entity whose approval to participate is suspended or revoked. This provision specifically deals with the matters under paragraph 88(2)(a) of the Digital ID Act, which provides for the entities covered by the framework.
1.28. Rule 1.4 of the Digital ID Rules sets out the definitions in these rules. Relevantly, subrule 1.4(1) provides that unless otherwise specified, expressions defined in the Accreditation Rules have the same meaning in these rules. Accordingly, the terms ‘ASP’ and ‘ISP’ take the meaning as defined in the Accreditation Rules as they are not specified in the Digital ID Rules. The term participating entity is defined in rule 1.4 of the Digital ID Rules, which means an entity that holds an approval to participate in the AGDIS.
1.29. The redress framework only applies to ASPs and ISPs, recognising the role of these accredited entities within the AGDIS which provide digital ID services directly to individuals. Accordingly, they are best placed to assist individuals with digital ID related incidents covered by the Digital ID Act. This approach is consistent with the intent of section 88 of the Digital ID Act, which requires the Digital ID Rules to provide for or in relation to incidents that occur in relation to accredited services of accredited entities that are provided within AGDIS. Entities outside the scope of the redress framework are:
Identity Exchange Providers (IXP) - because they function as technical intermediaries between service providers and they do not hold identity information about individuals.
Participating relying parties - because they are consumers of accredited services in the AGDIS and therefore they have limited visibility or control of incidents originating from accredited entities.
1.30. If an IXP or a participating relying party identifies a cyber security or digital ID fraud incident in relation to an accredited service, the incident is required to be reported to the System Administrator under rule 4.2 of the Digital ID Rules. The System Administrator will work with the appropriate entities to manage the incident.
1.31. Two Notes are inserted under rule 4A.1 to assist the reader. Note 1 informs readers that there are other provisions in the Digital ID Rules and the Accreditation Rules that relate to cyber security incidents and digital ID fraud incidents, although those provisions apply in other broader circumstances (i.e. those provisions are not limited to the provision of accredited services by ASPs and ISPs within the AGDIS).
1.32. Note 2 informs readers that Part 5 of this Chapter has a narrower application than that which is provided for by subrule 4A.1(2) (see rule 4A.6).
Part 2 – Notifying affected individuals of incidents
4A.2 Notifying affected individuals of incidents
1.33. This rule provides for notification to individuals following a cyber security incident or digital ID fraud incident. It specifically engages with the matters in paragraph 88(2)(d) of the of the Digital ID Act, which provides for the redress framework to deal with requirements relating to notifying individuals that are covered by the framework.
1.34. Subrule 4A.2(1) relevantly provides that this rule applies to cyber security incidents or digital ID fraud incidents that occur, or are reasonably suspected of having occurred, in relation to an accredited service provided within the AGDIS by entities to which this Chapter applies. This rule applies to entities as set out in subrule 4A.1(2).
1.35. Subrule 4A.2(2) relevantly provides that an entity must make reasonable attempts to notify each individual affected by the incident.
1.36. This provision recognises that it is in the best interests of the affected individual/s to be aware of cyber security or digital ID fraud incidents in relation to their digital ID. This would enable them to mitigate any flow-on consequences that could impact other transactions or services where they have used their digital ID, and for transparency.
1.37. This provision requires entities to make reasonable attempts to notify the individual, which should be done in consideration of the time and method of the attempt and the likelihood that the attempt would be successful. Reasonable attempts to notify an individual could mean one or more attempts to do so (subsection 23(b) of the Acts Interpretation Act 1901 generally provides that words in the plural include the singular unless the contrary intention appears). This provision recognises that an entity’s reasonable attempt to notify an individual may not be successful. This could be due to myriad reasons, including that the individual is not available or the entity does not have the current contact details of the individual.
1.38. Subrule 4A.2(3) relevantly provides that the requirement in subrule 4A.2(2) to make reasonable attempts to notify each individual affected by the incident, does not apply if the entity is satisfied that the circumstances in paragraphs 4A.2(3)(a) or 4A.2(3)(b) exist.
1.39. Paragraph 4A.2(3)(a) relevantly provides that the requirement to notify does not apply if there is a likelihood of the individual suffering an adverse outcome as a result of an attempted notification. In some circumstances, it may not be appropriate to notify the individual if this could also alert the malicious actor. The purpose of this provision is to ensure that the individual is not inadvertently harmed or left worse-off by an attempt to notify them of an incident.
1.40. Paragraph 4A.2(3)(b) relevantly provides that the requirement to notify does not apply, if notification could reasonably be expected to have a material effect on the operation of the AGDIS. The two factors seek to balance the potential harm to the individual resulting from the incident itself and the risk that in some circumstances, notification may exacerbate harm to the individual or to the operation of the AGDIS.
1.41. Two Notes are inserted under subrule 4A.2(3) to assist the reader. Note 1 informs readers that if an entity notifies an individual, they must also provide certain information, support and assistance to the individual as per rule 4A.5.
1.42. Note 2 informs readers that the term material effect is defined in subrule 1.4(2) of the Digital ID Rules. In this context, a material effect on the AGDIS could be triggered if the notification of the individual could exacerbate the incident to a magnitude that would cause the degradation or loss of functionality within the AGDIS, or limit the ability of an entity to participate in the AGDIS. For example, this could occur if the notification alerted the malicious actor and resulted in a cyber security incident or digital ID fraud incident with greater impact.
1.43. The requirement to make reasonable attempts to notify an affected individual under rule 4A.2 does not prescribe a specific timeframe within which to do so. This provides for circumstances where it may not be appropriate to notify the individual immediately or at all.
1.44. This rule operates alongside the timeframes in rule 4.2 of the Digital ID Rules. Rule 4.2 generally requires participating entities to notify the System Administrator of all cyber security or digital ID fraud incidents in relation to accredited services that are provided or received within the AGDIS. Subrule 4.2(4) broadly requires notifications to be made soon as practicable after, and in any event no later than 1 business day after becoming aware of the incident. Paragraph 4.2(3)(g) broadly requires those notifications to include information about each individual whose digital ID is affected, whether the individual was informed of the incident, or if not—why the individual has not been informed of the incident.
1.45. The System Administrator notification obligations in rule 4.2 are separate to the redress framework obligations in Chapter 4A. However, they intersect in practice as participating entities are already required to assess whether to notify individuals affected by a cyber security or digital ID fraud incident as soon as practicable after becoming aware of an incident, and to provide their reasoning to the System Administrator. Accordingly, rule 4A.2 does not impose additional timeframes, allowing entities to weigh risks and impacts, such as potential harm to the individual or material affect to the operation of the AGDIS, before notifying individuals. Importantly, while notification to the System Administrator under rule 4.2 must be made within the timeframes specified in subrule 4.2(4), this does not preclude entities from notifying individuals under rule 4A.2 outside of these timeframes.
1.46. The obligation to notify individuals under this rule applies in addition to any obligations an entity may have under Part IIIC of the Privacy Act (relating to the notification of eligible data breaches).
Part 3 – Referring unresolved technical issues to the System Administrator
4A.3 Unresolved technical issues must be referred to the System Administrator
1.47. This rule provides for the referral of unresolved technical issues to the System Administrator where, as a result of a cyber security or digital ID fraud incident, an individual is unable to use their digital ID due to a technical issue with the entity’s service that is within the control of the entity (or another relevant entity). It specifically deals with the matters under paragraph 88(2)(c) of the Digital ID Act which provides for procedures for dealing with incidents.
1.48. The purpose of this rule is to promote trust in the AGDIS by providing individuals with greater confidence that appropriate redress will be provided. It is also intended to promote accountability of entities through referral to the System Administrator.
1.49. Subrule 4A.3(1) sets out the circumstances in which this rule applies, which has two parts:
Paragraph 4A.3(1)(a) relevantly provides that this rule applies if a cyber security or digital ID fraud incident occurs or is reasonably suspected of having occurred in relation to an accredited service within the AGDIS. This rule applies to entities as set out in subrule 4A.1(2).
Paragraph 4A.3(1)(b) relevantly provides that this rule applies if, as a result of the incident, an individual is unable to use their digital ID due to a technical issue with the entity’s service that is within the control of the entity or another entity to which this Chapter applies.
1.50. The term ‘technical issue’ is not defined by these rules. It is intended to capture issues of a technical nature that result in an individual being unable to use their digital ID. This could include persistent technical issues that require manual override for remediation. This provision does not allow for an individual to refer their complaints or disputes directly to the System Administrator.
1.51. The technical issue must be within the control of the entity, or another entity to which this Chapter applies. This is intended to capture technical issues that may require a coordinated response from entities across the AGDIS with support from the System Administrator. It is also intended to exclude technical issues which are within the control of the user from being escalated to the System Administrator. For example, forgotten passwords or non-digital ID technology challenges.
1.52. Subrule 4A.3(2) provides the timeframe within which an entity must refer the technical issue to the System Administrator. Broadly, this requires an entity to refer the technical issue as soon as reasonably practicable after the entity becomes aware of the issue which results in an individual being unable to use their digital ID. If the entity became aware of the technical issue because of a complaint made by the individual, the entity must refer the issue as soon as reasonably practicable and within 28 days after the complaint is made.
1.53. The requirement for the entity to refer the technical issue to the System Administrator within 28 days after the complaint is made provides a service delivery standard to the management of the complaint where it is raised by an individual. This supports the overarching intent of the redress framework to strengthen protection and support for individuals.
1.54. The 28 day maximum timeframe acknowledges that there may be complex issues that require investigation or remediation across multiple entities or systems, however entities must refer as soon as reasonably practicable.
1.55. Subrule 4A.3(3) provides the circumstances that must be met before the entity refers the technical issue to the System Administrator under subrule 4A.3(2).
1.56. The purpose of paragraph 4A.3(3)(a) is to encourage entities to consider whether the issue can be resolved by the entity itself before the referral. Entities should not be referring technical matters which it can resolve itself to the System Administrator. This is also intended to balance the necessity of appropriate referrals with the potential burden on the System Administrator. The effect of the term ‘reasonably satisfied’ is that the entity must be satisfied in the circumstances, to a reasonable level, that the technical issue cannot be resolved without referral to the System Administrator.
1.57. Paragraph 4A.3(3)(b) relevantly provides that if rule 4A.5 is applicable, the entity must comply with that rule before referring to the System Administrator. Rule 4A.5 broadly requires entities to provide information, support and assistance to individuals that have been notified about an incident or that have made a complaint to the entity. The purpose of this paragraph is to ensure that entities have first provided appropriate information, support and assistance to individual in accordance with rule 4A.5, where that rule applies.
1.58. In circumstances where paragraph 4A.3(3)(b) does not apply (i.e., because rule 4A.5 is not applicable), the entity may refer the issue to the System Administrator if paragraph 4A.3(3)(a) does apply. For example, paragraph 4A.5(1)(a) does not apply if the entity has determines that an affected individual should not be notified (e.g., due to a likelihood of harm from the notification), or when the entity becomes aware of the issue other than by complaint made by the individual.
1.59. The Note below subrule 4A.3(3) refers the reader to rule 4A.5.
4A.4 System Administrator may recommend a resolution
1.60. Rule 4A.4 broadly provides that the System Administrator may recommend a resolution to an issue in response to a referral from an entity under rule 4A.3, and provides potential courses of action that may be recommended.
1.61. New rule 4A.4 only applies in relation to referrals from entities under rule 4A.3. This reflects the role of the System Administrator in providing assistance to entities participating in the AGDIS, and that the System Administrator does not provide dispute resolution.
1.62. The policy intent of this rule is for the System Administrator to provide assistance to entities participating in the AGDIS in relation to dealing with incidents. It is also intended to promote individual users’ confidence in the AGDIS by enabling the System Administrator to recommend an independent course of action.
1.63. Subrule 4A.4(2) provides courses of action that the System Administrator may recommend the entity take. This list is not exhaustive; the System Administrator may recommend another course of action to the entity as appropriate. The courses of action set out in subrule 4A.4(2) are intended to strengthen individual users’ confidence in accredited services within the AGDIS by promoting accountability.
1.64. Subrule 4A.4(2) is calibrated to the System Administrator’s functions in supporting entities and coordinating incident management. This provision does not limit the System Administrator’s existing powers under the Digital ID Act. For example, section 130 of the Digital ID Act enables the System Administrator to issue binding directions to entities to protect the integrity or performance of the AGDIS, with civil penalties for non-compliance.
1.65. The recommended resolution provision therefore serves as a proportionate, operational tool that allows the System Administrator to promote best practice and coordination in the first instance, while retaining the capacity to escalate responses through its statutory directions power if necessary.
Part 4 – Providing information, support and assistance to individuals affected by incidents
4A.5 Providing information, support and assistance to individuals affected by incidents
1.66. Rule 4A.5 provides for the provision of information, support and assistance to individuals in certain circumstances. It specifically deals with the matters in paragraph 88(2)(e) of the Digital ID Act, which relates to the provision of information, support and assistance to individuals affected by incidents covered by the framework.
1.67. This rule applies to entities as set out in subrule 4A.1(2).
1.68. Subrule 4A.5(1) sets out two circumstances in which an entity must provide information, support and assistance to an individual affected by a cyber security or digital ID fraud incident:
Paragraph 4A.5(1)(a) relevantly provides that the rule applies if an individual is notified under subrule 4A.2(2); alternatively
Paragraph 4A.5(1)(b) relevantly provides that the rule applies when an entity becomes aware of a technical issue mentioned in rule 4A.3 because of a complaint made by an individual.
1.69. Subrule 4A.5(2) provides for the types of information, support and assistance that must be provided:
Paragraph 4A.5(2)(a) relevantly provides that an entity must direct the individual to public resources, including information published by the entity on the resolution of incidents and the entity’s complaint processes. The effect of this paragraph is that the entity must have available information which would assist the individual in relation to the incident and increase their understanding of the resolution and complaints processes. This provision is designed to facilitate entities in empowering individuals to take appropriate actions in the circumstances to mitigate the impact of the cyber security or digital ID fraud incident.
Paragraph 4A.5(2)(b) relevantly provides that if the individual is unable to use their digital ID due to a technical issue with the entity’s service that is within the control of another entity to which this Chapter applies, the entity must provide reasonable assistance to help an individual identify another entity and its contact details.
1.70. This rule is intended to operate alongside rules 4A.7 and 4A.8, which relate to developing and publishing policies on incident identification and complaint management.
1.71. As set out in Note 1 under subrule 4A.1(2), this rule operates alongside other provisions in the Digital ID Rules and the Accreditation Rules that also deal with providing support and assistance to individuals in relation to cyber security incidents and digital ID fraud incidents.
Part 5 – Policies relating to incidents and complaints
4A.6 Application of this Part
1.72. Rule 4A.6 broadly provides that this Part does not apply to an ASP or an ISP whose approval to participate is suspended or has been revoked.
1.73. This Part relates to the development and publication of certain policies about the management, identification and resolution of cyber security and digital ID fraud incidents. The effect of this rule is that an entity who is not, at the relevant time, participating in the AGDIS is not subject to these requirements.
1.74. Under section 9 of the Digital ID Act, an entity participates in the AGDIS at a particular time if amongst other things, at that time, the entity holds an approval under section 62 to participate in the AGDIS. Subsection 71(13) of the Digital ID Act relevantly provides that if the approval of an entity to participate in the AGDIS is suspended, the entity is taken not to hold the approval while it is suspended.
1.75. The purpose of this provision is to ensure that regulatory burden is appropriately placed on entities who are participating in the AGDIS and ensure they continue to have policies which would be relied upon by digital ID users.
1.76. Consistent with the scope of the redress framework, this Part does not apply to IXPs or participating relying parties. As ISPs and ASPs are best placed to respond to individuals affected by cyber security or digital ID fraud incidents arising in relation to accredited services within the AGDIS, they are subject to the framework’s obligations to directly support individuals affected by those incidents, and accordingly, the obligations to publish incident management and complaint handling policies.
1.77. Participating relying parties are required to have written plans in place prior to applying for approval to participate in the AGDIS, including a cyber security plan (subrule 3.3(2)(a) of the Digital ID Rules) and a digital ID fraud management plan (subrule 3.3(2)(b) of the Digital ID Rules). These plans are not required to be published but must be reviewed at least once per year.
4A.7 Policies relating to the identification etc. of incidents
1.78. This rule relevantly provides that an entity must develop and publish policies relating to the identification, management and resolution of cyber security incidents and digital ID fraud incidents in relation to its accredited services within the AGDIS. It specifically deals with the matters under paragraph 88(2)(f) of the Digital ID Act which provides for the development and publication of policies relating to identification, management and resolution of incidents covered by the framework.
1.79. This rule applies to an ASP or an ISP that is a participating entity, as defined in the Digital ID Rules. As per rule 4A.6, this rule does not apply to an ASP or an ISP whose approval to participate is suspended or has been revoked. This is because an entity whose approval to participate is suspended or revoked does not hold approval to participate in the AGDIS and therefore may not provide or receive services within the AGDIS (subsection 71(13) of the Digital ID Act).
1.80. The effect of this rule is to impose an obligation on entities to have published policies which deal with cyber security incidents and digital ID fraud incidents. The policies could be published on the entity’s website or via other means to ensure public access.
1.81. The policies must deal with each of the matters in this rule and in relation to each of the entity’s accredited services. For example, if an entity is both an ISP and ASP within the AGDIS, its policies must relate to the identification, management and resolution of cyber security and digital ID fraud incidents for its services as an ISP and an ASP. These policies could be contained in a single document or multiple documents.
1.82. This rule does not prescribe how the policies must be presented or made accessible to users. Accredited entities are subject to usability and accessibility requirements for public-facing accredited services and related information, as set out in the Accreditation Rules. These include requirements to undertake WCAG testing of public-facing information related to accredited services (rule 3.15 of the Accreditation Rules) and comply with accessibility requirements under rule 4.49 of the Accreditation Rules.
1.83. Specifically, entities must present public-facing information related to accredited services in a clear and simple manner, using plain language that is easy to understand (paragraph 4.49(1)(b)), and take reasonable steps to ensure public-facing information is available in multiple accessible formats (paragraph 4.49(1)(c)). In addition, entities must have written processes and procedures to allow individuals to seek assistance or otherwise resolve disputes or complaints in relation to the entity’s public-facing accredited service (paragraph 4.49(6)(a)).
1.84. Importantly, this rule does not require entities to publish policies containing sensitive operational details or information which may benefit threat actors, such as hackers, or provide insights which would negatively affect the AGDIS or digital ID users. The purpose of this rule is to provide assurances to digital ID users that entities providing accredited services within the AGDIS have policies in place around these incidents.
4A.8 Policies relating to complaints by individuals
1.85. This rule relevantly provides that an entity must develop and publish policies relating to complaints by individuals relating to cyber security incidents and digital ID fraud incidents. This rule is intended to enhance transparency, empower individuals to navigate complaint options confidently, and reinforce trust in the Digital ID system. This rule specifically deals with the matters under paragraph 88(2)(g) of the Digital ID Act, which provides for the development and publication of policies relating to complaints by individuals.
1.86. Subrule 4A.8(1) relevantly provides that entities must develop and publish policies relating to complaints by individuals relating to cyber security incidents and digital ID fraud incidents that occur, or are reasonably suspected of having occurred, in relation to the accredited services provided by the entity within the AGDIS. Similarly to rule 4A.7, this rule applies to an ASP or an ISP that is a participating entity; it does not apply to an ASP or an ISP whose approval to participate is suspended or has been revoked. The policies could be published on the entity’s website or via other means to ensure public access.
1.87. Subrule 4A.8(2) provides the minimum content requirements for the complaints policies. The inclusion of these matters in the complaints policies are intended to support individuals to make complaints should they wish to do so, and to provide transparency of the process, procedures and timeframes for dealing with a complaint.
1.88. Subrule 4A.8(3) relevantly provides that this rule may be complied with by way of developing and publishing a policy that relates to complaints generally or in relation to other matters outside of cyber security incidents and digital ID fraud incidents. That is, the entity need not create unique complaints policies for its Digital ID accredited services, so long as the matters in subrules 4A.8(1) and 4A.8(2) are dealt with.
1.89. The effect of this rule is to impose an obligation on entities to have published policies which deal with how an entity will manage complaints made by individuals relating to cyber security incidents and digital ID fraud incidents. The policies could be published on the entity’s website or via other means to ensure public access.
1.90. Similar to rule 4A.7, the effect of rule 4A.8 is that published policies must deal with each of the entity’s accredited services. For example, if an entity is both an ISP and ASP within the AGDIS, its policies must relate to dealing with individual complaints for its services as an ISP and an ASP. These policies could be contained in a single document or multiple documents.
1.91. As described in relation to rule 4A.7, rule 4A.8 does not prescribe how the policies must be presented or made accessible to users. Accredited entities are subject to usability and accessibility requirements for public-facing accredited services and related information, as set out in the Accreditation Rules.
Schedule 2—Machinery of government changes
Overview
1.92. The AGDIS enables individuals to verify their identity online for certain government services. The AGDIS is overseen and maintained by the Digital ID Regulator under section 58 of the Digital ID Act.
1.93. In general, relying parties, as defined in section 9 of the Digital ID Act, must apply to the Digital ID Regulator for approval to participate in the AGDIS under section 61 of the Digital ID Act. Relying parties may apply for approval to provide, or provide access to, a service as a condition of their approval to participate under subsection 64(3). The Digital ID Regulator can approve the relying party under section 62 of the Digital ID Act and may impose conditions on the approval to participate, including conditions relating to the services a relying party may provide or provide access to under subsection 64(2).
1.94. An approval to participate cannot be transferred or extended to another entity. Broadly, under section 70, the Digital ID Regulator can vary an entity’s name in its approval.
1.95. A government participating relying party, as defined in section 9 of the Digital ID Act, can be affected by a Machinery of Government (MOG) change. A MOG change is often, though not always, accompanied by a change to administrative arrangements orders that transfers certain functions, or responsibility for administering certain legislation, from one ministerial portfolio to another. A MOG change can also involve the transfer of functions between entities within the same ministerial portfolio. In either circumstance, if that entity’s service/s within AGDIS is expected to transfer to a different entity, the entity receiving the service will need to seek approval to provide that service within the AGDIS. This means that the provision of that service could be disrupted if there are prolonged delays to the application process.
1.96. The Amendment Rules create a streamlined application process which aims to minimise the disruption to services within the AGDIS when a MOG occurs, and to reduce administrative and regulatory burden. It recognises that MOG changes are a routine aspect of government administration and that functions may transfer between entities, at relatively short notice, without substantial alteration to the nature of the services provided, the conditions or the risk environment under which services are delivered. It supports a more efficient approval process while maintaining the integrity of the AGDIS.
1.97. The new streamlined application provisions reduce the mandatory matters that the Digital ID Regulator must consider in approving a relying party to participate in the AGDIS in the relevant circumstances. The streamlined application process applies to administrative aspects of seeking an approval to participate. The streamlined application process does not change obligations in relation to compliance with security or privacy standards or to report cyber security or fraud incidents.
1.98. The AGDIS Register is maintained by the Digital ID Regulator. It provides details for all entities that are approved to participate in the AGDIS. If the Digital ID Regulator approves the streamlined application, the entity and the affected services will be reflected in the AGDIS Register.
Item 1 – subrule 1.4(2)
1.99. Item 1 inserts three new definitional terms into subrule 1.4(2).
1.100. The new terms are: receiving entity, transferring entity and streamlined application.
1.101. This amendment provides for new terms to be defined by reference to the new definition of streamlined applications in new rule 1.5.
Item 2 – After rule 1.4
1.102. Item 2 inserts new rule 1.5 ‘Meaning of streamlined application’ after rule 1.4.
1.5 Meaning of streamlined application
1.103. New rule 1.5 provides for the meaning of streamlined application. It relevantly provides that streamlined application means an application under section 61 of the Digital ID Act made by an entity (the receiving entity) where certain requirements are met.
1.104. First, the receiving entity is of a kind mentioned in paragraphs (c), (d), (e), (f) and (g) of the definition of entity in the Digital ID Act. Broadly, these entities are an Australian Commonwealth, State or Territory or government entity.
1.105. The effect of this requirement is that only entities of the kind in paragraphs (c) to (g) of the definition of entity in the Act can make a streamlined application. While a receiving entity does not have to be of the same kind of entity as a transferring entity, they must be an entity of a kind in paragraphs (c) to (g) of the definition of entity in the Act. The purpose of these requirements is to limit the kinds of entities that can make a streamlined application, as these applications are not intended to be available for all entities.
1.106. Second, the transferring entity is of a kind mentioned in paragraphs (c), (d), (e), (f) and (g) of the definition of entity in the Digital ID Act, and is also approved as a participating relying party to provide, or to provide access to, one or more services within the AGDIS.
1.107. Third, a function of the transferring entity that includes the provision of the approved services is, or is reasonably expected to be, transferred to the receiving entity due to a MOG change. The effect of this provision is to enable receiving entities to submit a streamlined application when a MOG has occurred, or in anticipation of a pending MOG change as soon as it is announced, e.g. through a government announcement.
1.108. As receiving entities will only provide services after the MOG changes take effect, there is a risk that the receiving entity’s application will not be considered and processed until after the MOG change occurs. This may result in the receiving entity not having the requisite approval to provide the services after the MOG change. As MOG changes commonly involve a delay between announcement and implementation, the provision enables applications before the MOG change takes effect. This maximises the time available for the Digital ID Regulator to assess and approve the application before the date that the MOG changes take effect.
1.109. Fourth, the application is for approval to provide, or to provide access to, one or more of the approved services of the transferring entity. While approval to participate broadly enables an entity to participate in the AGDIS, the conditions attached to that approval specify the particular services the relying party is authorised to provide or to provide access to.
1.110. Conditions relating to services may be imposed either on application by the relying party or on the Digital ID Regulator’s own initiative, as provided for in subsection 64(3) of the Digital ID Act. Accordingly, a streamlined application will necessarily include a request for a condition under subsection 64(3), to authorise the provision of the same service/s delivered by the transferring entity.
1.111. The effect and purpose of the definition of streamlined application is to confine its operation to the limited circumstances of a Commonwealth, State or Territory government MOG change. In these circumstances the nature of the services, governance structures, and risk environment is likely to remain substantially unchanged. As a result, the full application requirements may not be necessary. It remains open for the Digital ID Regulator to exercise any of its powers under the Digital ID Act, such as those related to seeking further information from the applicant.
1.112. “Machinery of government” is not defined in the Amendment Rules and it is intended for the ordinary meaning of the term to apply. MOG is a well-established concept in Australian government administration and it is understood to refer to changes in the structure or responsibilities of government entities, such as the transfer of functions between those entities. It is envisaged that the streamlined applications will apply in circumstances where the provision of relevant services within the AGDIS will be transferred to another government entity.
1.113. Streamlined applications are limited to an applicant seeking to participate in the AGDIS as a participating relying party. These amendments do not affect accredited entities (as defined in section 9 of the Digital ID Act) and they are not able to make streamlined applications. Accredited entities have additional, privacy, security, usability and other compliance obligations given their role in providing digital ID services.
1.114. An entity cannot provide services (or access to services) in the AGDIS before its participation start day, as set out in paragraph 64(1)(d) of the Digital ID Act. This date is determined by the Digital ID Regulator and specified in the participation approval notice under paragraph 62(6)(d). Entities expecting to receive a function that delivers AGDIS services due to a MOG change, should apply for approval and seek a condition authorising provision of the service/s before acquiring the relevant function. The approval may be granted to take effect from the date the MOG change occurs. Entities that do not yet exist cannot apply as they are not an entity under the Digital ID Act.
1.115. MOG changes may introduce considerations around service continuity, particularly where a new entity is established. The Digital ID Act allows for multiple entities to concurrently hold approval to provide the same service/s within the AGDIS. If both the transferring and receiving entities intend to operate within the AGDIS, prior to connecting and delivering services each entity must be approved to participate in the AGDIS with a condition to provide the same service/s (to satisfy the requirements for providing or receiving services within the AGDIS as set out in item 4 of subsection 59(1)). The Digital ID Regulator is responsible for determining whether approvals for the same service/s may be granted to multiple entities.
Item 3 - Before subrule 2.2(1)
1.116. Item 3 inserts new subrule 2.2(1A) before subrule 2.2(1).
1.117. New subrule 2.2(1A) provides that this rule does not apply in relation to a streamlined application.
1.118. In considering whether to approve an entity to participate in the AGDIS, paragraph 62(1)(e) of the Digital ID Act relevantly requires the Digital ID Regulator to be satisfied that it is appropriate to approve the entity to participate in the system. In making this assessment, the Digital ID Regulator may have regard to if an applicant is a fit and proper person under subsection 62(2) of the Digital ID Act.
1.119. Section 12 of the Digital ID Act relevantly provides that if the Digital ID Regulator does have regard to whether the entity is a fit and proper person, it:
must have regard to the matters (if any) specified in the Digital ID Rules; and
may have regard to any other matters the Digital ID Regulator considers relevant.
1.120. Rule 2.2 outlines the mandatory relevant matters to which the Digital ID Regulator must have regard if considering whether an entity is a fit and proper person. These matters broadly include the history of regulatory contravention, corporate disqualification, criminal convictions and privacy breaches involving the entity’s key personnel.
1.121. The effect of proposed new subrule 2.2(1A) is to enable the Digital ID Regulator to not consider these mandatory matters in the context of a streamlined application, because following a MOG change the receiving entity’s risk profile is often substantially unchanged.
Item 4 - After rule 2.2
1.122. Item 4 inserts a new rule 2.3 ‘Mandatory relevant matters—government entities affected by a machinery of government change’.
2.3 Mandatory relevant matters—government entities affected by a machinery of government change
1.123. Broadly, new rule 2.3 sets out the mandatory relevant matters which the Digital ID Regulator must have regard to in determining whether a receiving entity, as described in subrule 1.4(2) and 1.5, is a fit and proper person.
1.124. Subrule 2.3(1) provides that this rule applies in relation to a streamlined application. The effect of this provision is to limit the application of the matters in this provision to a streamlined application.
1.125. Subrule 2.3(2) provides that in considering whether the receiving entity is a fit and proper person, the Digital ID Regulator must have regard to whether the approval to participate held by the transferring entity has ever been suspended or revoked.
1.126. New subrule 2.3(3) mirrors paragraph 2.2(1)(j) of the fit and proper considerations, reflecting that if a post-MOG receiving entity has substantially similar processes and personnel within the business unit/s providing the approved service/s, and their risk profile remains unchanged, the most relevant fit and proper consideration remains the previous and current status of the transferring entity’s approval. Where an entity has previously had its approval suspended or revoked, this may indicate weaknesses in its internal processes and may require greater scrutiny.
1.127. If the Digital ID Regulator chooses to have regard to whether the entity is a fit and proper person, it can rely on paragraph 12(b) to have regard to any other matters it considers relevant to whether the entity is a fit and proper person.
Item 5 - Rule 3.1 (after the heading)
1.128. Item 5 inserts a new subrule 3.1(1) after the heading.
1.129. The effect of item 5 is to exclude streamlined applications from the mandatory requirements in Part 1, Chapter 3 of the Digital ID Rules.
1.130. Rule 3.1 generally provides that Part 1 of Chapter 3 sets out the additional requirements that must be met before the Digital ID Regulator may approve an entity to participate in the AGDIS. Rules 3.2 and 3.3 broadly set out requirements for relying parties seeking approval to participate in the AGDIS, including System Administrator notification procedures, risk assessments, cyber security and digital ID fraud management plans, and disaster recovery and business continuity plans.
1.131. Excluding streamlined applications from the requirements in rules 3.2 and 3.3 acknowledges that the assessments and documentation required by rules 3.2 and 3.3 have been previously created and may not need to be reassessed in the circumstances of a MOG change.
1.132. It remains open for the Digital ID Regulator to exercise any of its powers under the Digital ID Act to determine whether the entity should be approved to participate in the AGDIS. For example, subsection 142(1) of the Digital ID Act relevantly provides that the Digital ID Regulator may require the applicant to provide such further information or documents in relation to the application as the Digital ID Regulator reasonably requires.
Item 6 - Rule 3.1
1.133. Item 6 numbers the existing text of Rule 3.1 as subrule (2), to make space for the new subrule (1) immediately before it. Item 6 is a consequential amendment only.
Schedule 3—Authorised entities for trustmarks
Item 1 – Paragraph 5.4(2)(c)
1.134. Item 1 omits ‘and’ from the end of paragraph 5.4(2)(c) of the Digital ID Rules.
1.135. This amendment is consequential to the amendment in Item 2 of Schedule Digital ID Amendment (Redress Framework and Other Measures) Rules 2025 which adds a new paragraph at the end of subrule 5.4(2).
Item 2 – At the end of subrule 5.4(2)
1.136. Item 2 adds a new paragraph at the end of subrule 5.4(2) of the Digital ID Rules.
1.137. Broadly, this Item adds the Data Standards Chair to the list of entities authorised to use or display the Digital ID Accreditation Trustmark (digital ID trustmark) in connection with their statutory functions.
1.138. Chapter 8 of the Digital ID Act establishes the use and regulation of digital ID trustmarks. Section 116 of the Digital ID Act provides a simplified outline of Chapter 8, generally providing that the Digital ID Rules may set out marks, symbols, logos or designs (called digital ID trustmarks) that may or must be used by accredited entities and participating relying parties.
1.139. Subsection 118(1) of the Digital ID Act relevantly provides that an entity is authorised to use the digital ID trustmark if the entity is permitted or required by the Digital ID Rules, and the entity complies with any conditions prescribed in relation to the use or display of the digital ID trustmark.
1.140. Chapter 5 of the Digital ID Rules provides for the digital ID trustmarks. Rule 5.1 generally provides that Chapter 5 specifies the digital ID trustmark that may be used, and the conditions in relation to the use or display of that digital ID trustmark, by:
an accredited entity, for the purposes of paragraph 117(1) of the Digital ID Act (subrule 5.1(1)); and
an entity specified in rule 5.4 (authorised entity) for the purposes of paragraph 168(1)(b) of the Digital ID Act (subrule 5.1(2)).
1.141. Rule 5.2 provides that the digital ID trustmark specified in item of Schedule 1 is known as the Digital ID Accreditation Trustmark and may be used by an accredited entity and an authorised entity.
1.142. The purpose of the Digital ID Accreditation Trustmark is to be a visual indicator to signal that an entity is an accredited entity, for the purposes of, and in accordance with conditions, set out in Rule 5.3. This is designed to promote confidence in accredited services amongst Australian consumers and businesses.
1.143. The Digital ID Act also enables the Digital ID Rules to provide for other trustmarks, such as for participants in the Australian Government Digital ID System. However, the Digital ID Accreditation Trustmark is currently the only digital ID trustmark.
1.144. In general terms, the effect of rule 5.4 is to prescribe the conditions for which an authorised entity can use or display the digital ID trustmark.
1.145. Subrule 5.4(2) provides a list of entities that are authorised to use or display the digital ID trustmark. These entities are not accredited entities; they are government entities that are authorised to use the trustmark in connection with their statutory functions and other purposes as outlined in 5.4(3) relating to education about or promoting the objects of the Digital ID Act.
1.146. Subrule 5.4(2) currently includes the following authorised entities: the Digital ID Regulator, the System Administrator, the Information Commissioner, and the Secretary of the Department of Finance.
1.147. This amendment adds the Data Standards Chair to that list, which has the effect of enabling the Data Standards Chair to use or display the digital ID trustmark in accordance with the purposes outlined in subrule 5.4(3).
1.148. These purposes relate to the use or display of the digital ID trustmark in connection with the entity’s statutory functions under the Digital ID Act and for other purposes relating to education about or promoting the objects of the Act.
1.149. The Data Standards Chair is a statutory role established under section 101 of the Digital ID Act. Generally, under section 102 of the Digital ID Act, the Data Standards Chair is responsible for making and reviewing Digital ID Data Standards, which provide for the technical and operational requirements of the Australian Government Digital ID system, and the accreditation scheme.
1.150. Prescribing the Chair as an authorised entity to use the digital ID trustmark ensures that the trustmark can be used as part of materials that may be developed by the Chair to support their performance of their statutory functions.
1.151. The amendment does not extend the Chair’s authority to use the digital ID trustmark beyond the purposes outlined in subrule 5.4(3). Care must be taken to ensure that use of the trustmark is limited to what is authorised under section 118 of the Act.
1.152. Like other authorised entities listed in subrule 5.4(2), use of this trustmark by the Chair is not intended to imply that the Chair has been accredited or operates an accredited service.
Schedule 4—Reportable incidents
Overview
1.153. Rule 4.2 of the Digital ID Rules broadly outlines the obligations on all entities participating in the AGDIS (including IXPs, ASPs, ISPs and participating relying parties, even if their approval is suspended or revoked) to notify the System Administrator of any cyber security or digital ID fraud incidents that occur or are reasonably suspected to have occurred in relation to accredited services.
1.154. Subrule 4.2(3) broadly sets out the information that must be included in notifications. Subrule 4.2(4) generally provides that notifications must be made as soon as practicable and no later than one business day after the entity becomes aware of the incident.
1.155. Schedule 4 to the Amendment Rules enhances the System Administrator’s oversight of those notified incidents.
Item 1 – At the end of rule 4.2
1.156. This amendment introduces subrules (7), (8) and (9) at the end of rule 4.2 of the Digital ID Rules.
1.157. New subrule 4.2(7) relevantly provides that if the System Administrator receives a notification under subrule 4.2(2), the System Administrator may direct any entity of a kind mentioned in subrule 4.2(1) who has interacted with a digital ID affected by the incident to conduct an investigation into the incident. This directions power operates alongside the System Administrator’s powers under the Digital ID Act.
1.158. The purpose of this provision is to increase efficiencies for the System Administrator in exercising its functions under the Digital ID Act. In particular, this supports the System Administrator in managing digital ID fraud incidents and cyber security incidents involving entities participating in the AGDIS, consistently with its function under paragraph 95(e) of the Digital ID Act.
1.159. New subrule 4.2(8) sets out procedural requirements for the entity once directed to conduct an investigation. Specifically, that entity must begin the investigation as soon as reasonably practicable and must provide the System Administrator with a summary of the findings of the investigation as soon as reasonably practicable after the investigation is complete.
1.160. New subrule 4.2(9) relevantly provides that if an investigation exceeds a period of 28 days, the entity must provide the System Administrator with updates on the progress of the investigation immediately after the 28 days and at least once every 28 days until the investigation is complete. The intent of this subrule is to provide the System Administrator with oversight of the progress of ongoing investigations and to provide a touch point for entities undertaking investigations.
1.161. The requirement to provide a progress at least every 28 days, does not preclude a progress update from being provided more frequently than every 28 days.
Schedule 5—Application, saving and transitional provisions
Item 1 – After Chapter 6
1.163. This amendment introduces ‘Chapter 7 – Application, saving and transitional provisions’ after Chapter 6 in the Digital ID Rules, and new rule 7.1.
7.1 Application of amendments made by the Digital ID Amendment (Redress Framework and Other Measures) Rules 2025
1.164. New rule 7.1 sets out the application provisions for the amendments made by the Amendment Rules.
1.165. Subrule 7.1(1) defines amending Rules as the Digital ID Amendment (Redress Framework and Other Measures) Rules 2025, and defines commencement day as the day on which those rules commence.
1.166. Subrule 7.1(2) provides that new subrules 4.2(7), (8) and (9) apply in relation to notifications received by the System Administrator on or after the commencement day.
1.167. Subrule 7.1(3) provides that new rules 4A.2 and 4A.3 apply in relation to incidents that occur, or are reasonably suspected of having occurred, on or after the commencement day.
1.168. Subrule 7.1(4) provides that new rules 4A.7 and 4A.8 apply to entities to which the redress framework in new Chapter 4A applies, on and after 1 July 2026. This transition period provides entities with sufficient time to develop and publish such policies, noting that the new requirements do not require the entity to develop a standalone complaints policy for only digital ID related incidents. This also acknowledges existing requirements under the Accreditation Rules, including for entities to maintain processes and procedures relating to incidents, such as subrules 4.16(3) and 4.34(3) of the Accreditation Rules.
Attachment B
Statement of Compatibility with Human Rights
Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.
Digital ID Amendment (Redress Framework and Other Measures) Rules 2025
2.1 The Digital ID Amendment (Redress Framework and Other Measures) Rules 2025 (Amendment Rules) amends the Digital ID Rules to strengthen support for users of digital ID services within the Australian Government Digital ID System (AGDIS) and improve the efficient operation and regulation of the AGDIS. In particular, the Amendment Rules:
Establish a redress framework under section 88 of the Digital ID Act 2024 (Digital ID Act) for cyber security and digital ID fraud incidents relating to accredited services within the AGDIS (Schedule 1).
Establish a streamlined application for approval to participate in the AGDIS, for Commonwealth, State or Territory government relying parties that are receiving previously approved services due to machinery of government (MOG) changes (Schedule 2).
Authorise the Digital ID Data Standards Chair to use the digital ID accreditation trustmark (Schedule 3).
Improve the System Administrator’s oversight of cyber security incidents and digital ID fraud incidents (Schedule 4).
Make transitional provisions for the amendments (Schedule 5).
Schedule 1—Redress framework
Overview
2.2 Schedule 1 to the Amendment Rules establishes a redress framework (new Chapter 4A) for users of accredited services within the AGDIS, which have been affected by cyber security and digital ID fraud incidents. The framework establishes obligations in relation to:
notifying individuals affected by cyber security and digital ID fraud incidents
providing information and assistance to affected individuals
referring unresolved technical issues to the System Administrator
publishing complaints policies and publishing incident management policies.
Human rights implications
Protection from arbitrary or unlawful interference with privacy
2.3 The principal human right engaged by Schedule 1 to the Amendment Rules is the protection against arbitrary or unlawful interference with privacy under Article 17 of the International Covenant on Civil and Political Rights (ICCPR), which generally states that:
No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honour and reputation.
Everyone has the right to the protection of the law against such interference or attacks.
2.4 Article 16 of the Convention on the Rights of the Child (CROC) and Article 22 of the Convention on the Rights of Persons with Disabilities (CRPD) contain similar rights.
2.5 The redress framework contains a number of amendments that represent new privacy and other protections for individuals, rather than matters that would negatively impact on their privacy rights. The Amendment Rules advance privacy protection in the following ways.
Incident notification and assistance
2.6 Entities will be required to make reasonable attempts to notify individuals affected by a cyber security or digital ID fraud incident, unless the notification could result in the individual suffering an adverse outcome or have a material effect on the operation of the AGDIS. Decisions to notify individuals require case‑by‑case consideration of potential harms, averting notifications or attempted notifications which are likely to cause harm.
2.7 Where notification is given, the entity must provide information and reasonable assistance, including directing individuals to relevant public resources and helping them identify the appropriate contact point where another entity controls the relevant service. These requirements will facilitate timely, targeted support for digital ID users, and will help individuals better understand (and effectively take steps to control) the handling of their personal information associated with their digital IDs.
Escalation of unresolved technical issues
2.8 If an incident results in an individual being unable to use their digital ID due to a technical issue within an entity’s control (or another relevant participating entity’s control), and the entity cannot resolve the issue, the entity must refer the matter to the System Administrator within specified timeframes. This is a privacy-enhancing measure, as it will assist the System Administrator to take steps to ensure the AGDIS is operating in a secure manner and supports limiting the duration and extent of any privacy or service impacts on individuals.
2.9 The System Administrator will be able to recommend a course of action, which may include explanations or apologies to the individual. This is a positive measure as it has the potential to ensure that there is openness and transparency for individuals in relation to their digital IDs.
2.10 Although this referral process would involve disclosure of an individual’s information to the System Administrator, disclosure is tightly constrained by the Digital ID Act. Relevantly, section 151 generally establishes a criminal offence for entrusted persons, including the System Administrator and relevant staff, who use or disclose protected information outside the authorised exceptions in section 152. These safeguards ensure that any personal information received is handled lawfully and securely.
2.11 To the extent that personal information is disclosed to the System Administrator under the referral obligation, the targeted oversight supports timely remediation, thereby enhancing the overall resilience of the AGDIS.
2.12 There is limited engagement with the right to privacy and to the extent it is engaged, it is reasonable and proportionate. The powers are purpose-specific, apply only to entities directly connected to the incident, and are subject to ongoing reporting obligations. These measures promote transparency and accountability while ensuring that privacy is protected in the context of incident response.
Right to an effective remedy
2.13 Article 2(3) of the ICCPR requires that individuals have access to an effective remedy when their rights or freedoms are violated.
2.14 The redress framework promotes this right by requiring entities to publish clear complaints policies, to provide information and assistance where notification occurs, and to refer unresolved technical issues to the System Administrator.
Transparent, accessible complaints pathways
2.15 The rules require publication of policies for the identification, management and resolution of incidents and for handling complaints, including contact points, procedures (with a simplified outline) and timeframes. These publication obligations will promote transparency and efficiency in relation to entities’ incident management and complaint handling processes, and should facilitate entities being able to respond more quickly in the event of an incident. A transition period is provided for entities to develop and publish these policies, supporting orderly implementation and public awareness.
2.16 These measures enhance transparency, accessibility and accountability, ensuring that individuals have practical avenues to raise concerns and seek resolution when their digital ID services are disrupted by cyber security or fraud incidents, or where an individual cannot use their digital ID due to an unresolved technical issue. While the framework does not create judicial remedies, it complements existing legal rights by embedding administrative processes that support timely and effective redress.
Conclusion
2.17 Schedule 1 to the Amendment Rules is compatible with human rights, as it promotes or positively engages human rights.
Schedule 2—Machinery of government changes
Overview
2.18 Schedule 2 to the Amendment Rules introduces a streamlined application pathway for government entities seeking approval to participate in the AGDIS when relevant functions transfer between government entities due to a machinery of government (MOG) change. This measure is intended to preserve continuity of services while maintaining system integrity and regulatory oversight.
2.19 Under section 61 of the Digital ID Act, relying parties must apply to the Digital ID Regulator for approval to participate in the AGDIS. The Digital ID Regulator can approve applications and may impose conditions on an approval, including conditions relating to the services that relying party may provide. An approval cannot be transferred or extended to another entity. This means that where a government function is transferred from one entity to another due to a MOG change, the receiving entity must submit a new application.
2.20 To minimise disruption to services within the AGDIS resulting from MOG changes, the amendments in Schedule 2 streamline the application process for certain government entities by reducing the mandatory matters the Digital ID Regulator must consider when assessing such applications.
2.21 The matters excluded from mandatory consideration are those that, in the context of a MOG change, are unlikely to have materially changed. The measure supports continuity of service for individuals while preserving the requirement that receiving entities meet all obligations applicable to participating relying parties once approved.
2.22 The streamlined pathway established by Schedule 2 does not permit new or expanded handling of personal information. Importantly, any receiving entities approved under this pathway must still obtain a fresh express consent from individuals before providing services that involve using or disclosing personal attributes. This ensures that individuals retain control over how their personal information is used.
2.23 The Digital ID Regulator’s decisions under the streamlined application pathway are administrative and subject to the existing review mechanisms in the Digital ID Act.
Human rights implications
2.24 Schedule 2 to the Amendment Rules does not substantively engage the right to privacy under Article 17 of the International Covenant on Civil and Political Rights (ICCPR), nor equivalent rights under Article 16 of the Convention on the Rights of the Child (CROC) or Article 22 of the Convention on the Rights of Persons with Disabilities (CRPD).
2.25 The measure does not alter the scope of personal information handling or reduce existing privacy safeguards. Individuals retain control over their personal information through the requirement for fresh consent, and receiving entities must comply with all privacy obligations under the Digital ID Act and associated rules.
Conclusion
2.26 Schedule 2 to the Amendment Rules is compatible with human rights as it does not substantively raise any human rights issues.
Schedule 3— Authorised entities for trustmarks
Overview
2.27 Schedule 3 to the Amendment Rules authorises the Digital ID Data Standards Chair to use the digital ID accreditation trustmark in accordance with their statutory functions.
Human rights implications
2.28 Schedule 3 to the Amendment Rules does not engage any of the applicable human rights and freedoms.
2.29 The purpose of these amendments is to authorise the Digital ID Data Standards Chair to use a digital ID trustmark. Rule 5.4 authorises certain entities to use or display a digital ID trustmark, being the Digital ID Accreditation Trustmark defined in rule 5.2. This amendment adds the Chair to the list of authorised entities and requires the Chair to use the trustmark for the purposes set out in subrule 5.4(2).
Conclusion
2.30 The Amendment Rules are compatible with human rights as it does not raise any human rights issues.
Schedule 4—Reportable incidents
Overview
2.31 Schedule 4 to the Amendment Rules strengthens the cyber security and digital ID fraud incident management framework in the AGDIS by expanding the powers of the System Administrator in relation to reportable incidents. Specifically, the System Administrator is empowered to direct any relevant entity that has interacted with a digital ID affected by a notified incident to conduct an investigation. The entity must commence the investigation as soon as reasonably practicable, provide progress updates every 28 days until completion, and provide a summary of findings once complete.
Human rights implications
Protection from arbitrary or unlawful interference with privacy
2.32 Schedule 4 to the Amendment Rules engages the right of protection against arbitrary or unlawful interference with privacy under Article 17 of the International Covenant on Civil and Political Rights (ICCPR), which states that:
No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honour and reputation.
Everyone has the right to the protection of the law against such interference or attacks.
2.33 Similar rights are contained in Article 16 of the Convention on the Rights of the Child (CROC) and Article 22 of the Convention on the Rights of Persons with Disabilities (CRPD).
2.34 Schedule 4 to the Amendment Rules enhances the System Administrator’s oversight and management of digital ID fraud and cyber security incidents in the AGDIS, and increases accountability of entities that interact with affected digital IDs.
2.35 Rule 4.2 of the Digital ID Rules broadly requires entities to notify the System Administrator of such incidents, including information about affected individuals, such as whether they have been informed of the incident. This process may involve the disclosure of personal information.
2.36 The amendment introduces new powers for the System Administrator to direct entities that have interacted with a compromised digital ID to investigate the incident. While this may involve further use or disclosure of personal information, it is tightly constrained by the Digital ID Act. Relevantly, section 151 generally establishes a criminal offence for entrusted persons, including the System Administrator and relevant staff, who use or disclose protected information outside the authorised exceptions in section 152. These safeguards ensure that any personal information received is handled lawfully and securely.
2.37 To the extent that personal information is disclosed to the System Administrator under these new powers, the amendment advances privacy protection by strengthening the System Administrator’s ability to identify, contain and mitigate risks to individuals whose digital IDs may have been compromised. This targeted oversight helps prevent further misuse of personal information and supports timely remediation, thereby enhancing the overall resilience of the AGDIS.
2.38 There is limited engagement with the right to privacy and to the extent it is engaged, it is reasonable and proportionate. The powers are purpose-specific, apply only to entities directly connected to the incident, and are subject to ongoing reporting obligations. These measures promote transparency and accountability while ensuring that privacy is protected in the context of incident response.
Conclusion
2.39 Schedule 4 to the Amendment Rules is compatible with human rights, as it promotes or positively engages human rights.
Schedule 5—Application, saving and transitional provisions
Overview
2.40 Schedule 5 to the Amendment Rules sets out application, saving and transitional provisions relating to the commencement and application of the measures. Schedule 5 broadly provides that:
Obligations under the redress framework (Schedule 1) in relation to notifying individuals affected by cyber security or digital ID fraud incidents, and to referring unresolved technical issues to the System Administrator, apply to incidents occurring on or after commencement of the Amendment Rules.
New reportable incident investigation powers and obligations (Schedule 4) apply to incident notifications received on or after the commencement date.
Obligations under the redress framework (Schedule 1) to publish policies on incident management and complaints apply to relevant entities from 1 July 2026.
2.41 All commencement and application provisions are prospective.
Human rights implications
2.42 Schedule 5 does not engage any human rights.
Conclusion
2.43 Schedule 5 to the Amendment Rules does not engage human rights issues.