EXPLANATORY STATEMENT
Issued by authority of the Minister for Finance
Digital ID Act 2024
Digital ID Amendment (Redress Framework) Rules 2026
Subsection 168(1) of the Digital ID Act 2024 (the Digital ID Act) provides that the Minister may, by legislative instrument, make rules prescribing matters required or permitted by the Digital ID Act to be prescribed by the rules, or necessary or convenient to be prescribed for carrying out or giving effect to that Act.
Subsection 88(1) relevantly provides that within 12 months after the commencement of the Digital ID Act, the Digital ID Rules 2024 (the Digital ID Rules) must provide for or in relation to a redress framework for incidents that occur in relation to accredited services of accredited entities that are provided within the Australian Government Digital ID System (AGDIS).
The Digital ID Amendment (Redress Framework) Rules 2026 (Amendment Rules) amends the Digital ID Rules to strengthen the Redress Framework established under Chapter 4A. The Amendment Rules respond to stakeholder feedback received following commencement of the Digital ID Amendment (Redress Framework and Other Measures) Rules 2025 by reinforcing accountability of certain accredited service providers within the AGDIS to individual digital ID users.
In particular, the Amendment Rules:
- strengthen the notification obligations on current or former Attribute Service Providers or Identity Service Providers in the AGDIS (relevant entities) by narrowing the exceptions to this obligation;
- imposes new record keeping obligations on relevant entities in relation to the notification obligation;
- empower the System Administrator to direct, in writing, relevant entities to apologise or provide an explanation to a digital ID user affected by cyber security or digital ID fraud incidents;
- enable the System Administrator to recommend, in writing, an entity pay an amount of money to an affected digital ID user;
- establish a framework around the exercise of these new powers, including mandatory considerations for both powers, procedural fairness requirements for the directions power and a requirement to inform the Digital ID Regulator; and
- ensure that a direction given by the System Administrator is a merits reviewable decision.
Section 17 of the Legislation Act 2003 imposes a general obligation on the rule-maker to consult before making legislative instruments. Subsection 169(1) of the Digital ID Act relevantly provides that before making or amending any rules, the Minister must cause to be published on the Department’s website, a notice setting out the draft rules or amendments and invite persons to make submissions about the draft rules or amendments.
An exposure draft of the Amendment Rules was released for public consultation from 4 March 2026 to 1 April 2026. The department also invited submissions from key stakeholders, including from entities participating in the AGDIS, relevant industry groups and private sector organisations, social policy and advocacy groups representing community and inclusion interests. The Office of the System Administrator, the Office of the Information Commissioner and the Digital ID Regulator were also consulted on the Amendment Rules.
The department received 22 submissions, with 11 submissions providing substantive feedback on the Amendment Rules. The submissions received broadly supported the changes. Key feedback received focussed on the need for a framework to guide the exercise of the System Administrator’s new powers, including relevant considerations and an opportunity for entities to comment before the powers are exercised. Stakeholders also recommended that causation be considered when determining which entity is responsible for providing redress, noting the multi-entity nature of the AGDIS. A small number of stakeholders sought clarity around the exceptions for notifying individuals and a longer commencement date.
To address this feedback, the Amendment Rules were amended to:
- establish a framework governing the exercise of the System Administrator’s new powers, including mandatory considerations before either power is exercised and an opportunity to comment before a direction is given. Consistent with stakeholder feedback, the mandatory considerations include an entity’s connection to the technical issue, and whether the relevant incident was reasonably foreseeable or could have been addressed before it occurred;
- expand the application of the System Administrator’s powers to entities with the ability to address the technical issue. This reflects stakeholder feedback for these powers to apply to entities that caused or contributed to that issue; and
- change the commencement date from 1 July to 30 September 2026.
The Amendment Rules are subject to disallowance.
Details of the Amendment Rules are set out in Attachment A.
The Amendment Rules are a legislative instrument for the purposes of the Legislation Act 2003.
The Amendment Rules commence on 30 September 2026.
A Statement of Compatibility with Human Rights is at Attachment B.
GLOSSARY
This Explanatory Statement uses the following abbreviations and acronyms.
Abbreviation | Definition
|
Digital ID Regulator | The Digital ID Regulator as established by section 90 of the Digital ID Act 2024 |
AGDIS | Australian Government Digital ID System |
Digital ID Act | Digital ID Act 2024 |
the Rules or these Rules | Digital ID Rules 2024 |
ASP | Attribute Service Provider |
ISP | Identity Service Provider |
ATTACHMENT A
Details of the Digital ID Amendment (Redress Framework) Rules 2026
Section 1 – Name
- This section provides that the name of this instrument is the Digital ID Amendment (Redress Framework) Rules 2026 (Amendment Rules).
Section 2 – Commencement
- The Amendment Rules commence on 30 September 2026.
Section 3 – Authority
- This section provides that this instrument is made under section 168 of the Digital ID Act 2024 (Digital ID Act).
Section 4 – Schedules
- This section provides that each instrument that is specified in a Schedule to this instrument is amended or repealed as set out in the applicable items in the Schedule concerned, and any other item in a Schedule to this instrument has effect according to its terms.
Schedule 1 – Amendments
Overview
- The purpose of the redress framework is to support individual digital ID users to efficiently obtain assistance in response to digital ID fraud incidents and cyber security incidents (collectively, incidents) that occur in relation to accredited services of accredited entities in the AGDIS. These incidents are defined in section 9 of the Digital ID Act. The Amendment Rules reinforce the accountability of certain current or former ASPs or ISPs, as defined in section 9 of the Digital ID Act, in the AGDIS (relevant entities) towards their consumers through three key changes.
- The Amendment Rules introduce two new powers for the System Administrator and a framework for the exercise of these powers. The System Administrator will be empowered to direct entities to apologise or provide an explanation of the circumstances to an individual affected by who is unable to use their digital ID as a result of a digital ID fraud or cyber security incident. In addition, the System Administrator will be able to recommend that an entity take a course of action to resolve the technical issue or that the entity pay an amount to the affected individual. The recommendation for financial redress is in addition to the System Administrator’s existing powers to recommend a course of action to the entity to resolve a technical issue.
- These powers are enlivened following a cyber security incidents and digital ID fraud incidents where such incidents give rise to technical issues that prevent an individual from using their digital ID. Where an entity becomes aware of an issue that it is unable to resolve without intervention, it must refer that unresolved technical issue to the System Administrator. These powers support the System Administrator in performing their functions under paragraph 95(e) of the Digital ID Act to manage digital ID fraud incidents and cyber security incidents involving entities participating in the AGDIS.
- As a condition of an entity’s participation in the AGDIS, they are required to comply with a direction given by the System Administrator or to notify the System Administrator of how they propose to implement a recommendation, or their reasons for not doing so. These requirements reflect the policy intention for directions to be binding and for recommendations to be voluntary.
- Where an obligation or requirement introduced in these Amendment Rules is not complied with, the Rules are designed to leverage the compliance and enforcement framework set out in Part 2 of Chapter 9 of the Digital ID Act, which specifies the penalties and consequences for non-compliance:
- Sections 127, 128 and 129 of the Digital ID Act broadly provide the Digital ID Regulator with various directions powers to respond to non-compliance with the Digital ID Act and the Digital ID Rules. Non-compliance with a direction may attract a maximum civil penalty of 1,000 penalty units.
- Subsection 130(1) provides that the System Administrator may give a direction to certain entities if it considers it necessary to protect the integrity or performance of the AGDIS. Non-compliance with this direction may attract a maximum civil penalty of 1,000 penalty units: subsection 130(5) of the Digital ID Act refers.
- The Digital ID Regulator also has other powers under the Act to deal with non‑compliance. It may suspend or revoke the accreditation of an accredited entity if it reasonably believes that the accredited entity has contravened or is contravening the Act, as defined in section 9 of the Digital ID Act: paragraphs 25(2)(a) and 26(2)(a) of the Digital ID Act refer. The Digital ID Regulator may also suspend or revoke approval to participate in the AGDIS if the entity has contravened or is contravening the Act: sections 71 and 72 of the Digital ID Act refer.
- In addition, the Amendment Rules narrow the circumstances in which a relevant entity is not required to notify an individual affected by a cyber security or digital ID fraud incident. Broadly, this amendment seeks to encourage entities to notify affected individuals unless it is likely to cause a significant negative impact on the operation of the AGDIS or result in an adverse outcome for the individual.
- The Amendment Rules also introduce additional record-keeping obligations for entities and a requirement for the System Administrator to inform the Digital ID Regulator in writing when a direction or recommendation is given. These obligations are intended to promote accountability and transparency in the handling of incidents, and to support the Digital ID Regulator in monitoring compliance and taking enforcement action where appropriate.
Item 1 – Subrule 3.4(1) (at the end of the table)
- Item 1 adds new table items 4 and 5 in the table immediately under subrule 3.4(1).
- Subrule 3.4(1) provides, for the purposes of subsection 64(5) of the Digital ID Act, the approval of an entity described in column 1 of an item of the following table is subject to the conditions specified in column 2 of the item.
- Subsection 64(5) of the Digital ID Act relevantly provides that the Rules may determine that the approval of each entity, or of each entity included in a specified class, to participate in the AGDIS is subject to one or more specified conditions.
- Item 1 complements Item 7 of these Amendment Rules and provides for the consequences of non-compliance with aspects of the amendments in Item 7.
- Item 7 repeals and substitutes current rule 4A.4 with rules 4A.3A and 4A.4 to introduce a new directions and recommendation power within the redress framework, respectively.
- Item 1 adds the obligations in subrules 4A.3A(2) and 4A.4(4) as a condition of participation for an ASP or ISP that is a participating entity, as defined in rule 1.4 of the Digital ID Rules, in the AGDIS.
- Broadly, new subrule 4A.3A(2) enables the System Administrator to give a direction to relevant entities. Table item 4 has the effect that if the entity is given a direction from the System Administrator under subrule 4A.3A(2), the entity’s compliance with that direction is a condition on the entity’s approval to participate in the AGDIS. For example, if the entity is directed under paragraph 4A.3A(2)(a) to provide a digital ID user with an explanation of the circumstances giving rise to the technical issue, the entity’s failure to provide that explanation is a breach of its condition.
- Table item 5 has the effect that if the entity is given a recommendation under subrule 4A.4(1), the entity’s compliance with subrule 4A.4(4) is a condition on the entity’s approval to participate in the AGDIS. New subrule 4A.4(4) require entities to notify the System Administrator, in writing, within 28 days of receiving a recommendation whether they propose to implement the recommendation and, if not, their reasons for not doing so. Table item 5 does not attach a consequence to the entity’s decision not to implement a recommendation given under subrule 4A.4(1); the consequence is attached only to the entity’s compliance with subrule 4A.4(4).
- A breach of an entity’s conditions of participation in the AGDIS enables the Digital ID Regulator to exercise its powers under the Digital ID Act. As outlined earlier, the Digital ID Regulator has a range of powers available under the Digital ID Act to deal with non-compliance, including a range of powers under Part 2 of Chapter 9 of the Digital ID Act, suspending or revoking the entity’s accreditation, or suspending or revoking their participation in the AGDIS: paragraphs 25(2)(a) and 26(2)(a), and sections 71 and 72 of the Digital ID Act, respectively.
Item 2 – Subrule 4A.2(3)
- Subrule 4A.2(3) inserts ‘in respect of an individual affected by the incident’ after ‘subrule (2) does not apply’.
- Previously, subrule 4A.2(3) provided that subrule 4A.2(2) does not apply if the entity is satisfied with a matter in subrule 4A.2(3). Subrule 4A.2(2) provides that the entity must make reasonable attempts to notify each individual affected by the cyber security or digital ID fraud incident.
- This amendment clarifies that the assessment of whether an exception applies is to be undertaken at the level of the individual, on a case-by-case basis. This reflects that, although a single incident may affect multiple individuals, the nature and extent of the risks associated with notification may differ between individuals.
Item 3 – Paragraph 4A.2(3)(b)
- Item 3 omits “material effect” and substitutes with “significant impact” in paragraph 4A.2(3)(b).
- Subrule 4A.2(2) provides that the entity must make reasonable attempts to notify each individual affected by the cyber security or digital ID fraud incident.
- Previously, paragraph 4A.2(3)(b) provided that subrule 4A.2(2) does not apply if the entity is satisfied that notifying the individual would, or could reasonably be expected to, have a material effect on the operation of the AGDIS.
- Subrule 1.4(2) of the Rules provided that “material effect” is defined, in relation to the operation of the AGDIS, to include:
- any degradation or loss of functionality within the AGDIS; and
- any detrimental effect on the ability of an entity that participates in the AGDIS to access the System.
- Item 3 lifts the threshold for the exception to notify an individual by replacing ‘material effect’ with ‘significant impact’ on the operation of the AGDIS. This narrows the circumstances in which the exception applies. The term significant impact is not defined in the Amendment Rules and is intended to take its ordinary meaning. The exception should only be available where notifying an individual would have a consequential or sufficiently serious impact, rather than any negative impact on the AGDIS.
- The ability to consider any detrimental effect or degradation may capture a broad range of impacts, including relatively minor or temporary disruptions to functionality or access. This amendment clarifies that impacts of this kind are not sufficient to justify an exception from the requirement to notify affected individuals of a cyber security or digital ID fraud incident. The exception is intended to apply in limited circumstances where notifying individuals could exacerbate the effect of an incident, for example, by undermining the stability, availability or security of the AGDIS.
- For example, a significant impact may arise where there is an unresolved vulnerability within the system affecting multiple entities, and notifying an individual could reasonably increase the likelihood of that vulnerability being exposed and exploited by malicious actors before it is remediated. In such circumstances, notification may pose a broader risk to the security and stability of the AGDIS, beyond the types of degradation or access impacts captured by the threshold of “material effect”.
Items 4 and 5 – Subrule 4A.2(3) (note 1) and Subrule 4A.2(3) (note 2)
- Item 4 omits ‘Note 1’ and substitutes ‘Note’ under subrule 4A.2(3).
- Item 5 repeals note 2 under subrule 4A.2(3). These Items make consequential amendments to Item 2 of these Amendment Rules.
- The new Note under subrule 4A.2(3) is substantively the same as previous note 1 under that provision.
Item 6 - At the end of rule 4A.2
- Item 6 adds new subrules 4A.2(4) and (5) at the end of rule 4A.2.
- New subrule 4A.2(4) prescribes matters to which an entity must not have regard when determining whether it is satisfied that an exception from the notification obligation in subrule 4A.2(3) applies. In particular, an entity must not have regard to whether notification might result in embarrassment or reputational damage, attract media attention, increase administrative costs or burden, or be related to compliance or enforcement actions being taken or that may be undertaken against them. This requirement ensures that any decision not to notify affected individuals is supported only by an assessment of the impact on those individuals and the AGDIS, such as the integrity and security of the system.
- New subrule 4A.2(5) introduces a record‑keeping requirement where an entity is satisfied that an exception from the notification obligation applies in respect of an individual. In such circumstances, the entity must make a written record of its reasons for reaching that conclusion and retain the record for 3 years from the day it is created. Retaining records for 3 years aligns with the general record keeping requirements in these rules and minimises any potential confusion for entities: rule 6.2 refers.
- This requirement promotes transparency and accountability in the application of the exceptions by ensuring that any decision not to notify an individual is documented and justified by reference to the permitted considerations.
- Rule 4A.2 does not currently prescribe a timeframe for notifying individuals, consistent with the policy for entities to make a risk-based assessment on a case‑by-case basis in determining when it is appropriate to notify an individual. For example, in some cases, entities may need time to verify trusted contact details for affected individuals. As these considerations vary depending on the nature of the incident and the information available, it was not considered appropriate to prescribe a notification timeframe under rule 4A.2.
- Recognising that the digital ID legislative framework was only established in late 2024, the record keeping requirement in new subrule 4A.2(5) will support data collection on how entities are meeting their notification obligation. This evidence will inform future consideration of whether adjustments to rule 4A.2 is appropriate.
Item 7 – Rule 4A.4
- Item 7 repeals rule 4A.4 and substitutes new rules 4A.3A and 4A.4.
- Rule 4A.3 provides that unresolved technical issues must be referred to the System Administrator.
- Previously, rule 4A.4 provided for the System Administrator to recommend a resolution where it receives a referral from an entity under rule 4A.3. Relevantly, previous subrule 4A.4(2) provided that a course of action recommended by the System Administrator may include that the entity provide the individual with an explanation of the circumstances giving rise to the technical issue or issue an apology to the individual. This provision did not attach a consequence to an entity’s decision not to comply with the recommendation.
- The Amendment Rules repeals rule 4A.4 and replaces it rules 4A.3A and 4A.4, which enables the System Administrator to:
- direct an entity to provide affected individuals with an explanation of the circumstances giving rise to the technical issue, and/or issue an apology to the individual; and/or
- recommend a course of action to the entity to resolve the technical issue, and/or recommend that an entity pay an amount to the individual.
Rule 4A.3A System Administrator may give directions
- New rule 4A.3A introduces a new directions power for the System Administrator which is engaged if a technical issue within the control of an entity to which this Chapter applies is referred to the System Administrator under rule 4A.3. This provision also provides for a framework in relation to the exercise of this power.
- Broadly, under this provision, the System Administrator may direct an entity to do either or both of the actions in subrule 4A.3A(2); that is, to apologise or provide an explanation of the circumstances giving rise to the technical issue to the individual.
- The direction may be given to an entity who has control over a technical issue which has been referred to the System Administrator under rule 4A.3. As the AGDIS involves multiple relevant entities, more than one entity could have control over a technical issue, which means a direction may be given to any of those entities.
- The purpose of this provision is to ensure that the relevant entities are accountable to individual digital ID users and provide redress in the form of an apology or explanation of the circumstances giving rise to the technical issue.
- Subrule 4A.3A(1) provides for the scope of rule 4A.3A in setting out the circumstances in which this rule applies.
- Subrule 4A.3A(2) provides that the System Administrator may give a written direction to the entity requiring the entity to do, within the period (if any) specified in the direction, either or both, provide the individual with an explanation of the circumstances giving rise to the technical issue, and/or, issue an apology to the individual. The Note under subrule 4A.3A(2) clarifies that compliance with a direction by a participating entity is a condition on the entity’s approval to participate in the AGDIS, as provided in item 4 of the table in subrule 3.4(1).
- The effect of this provision and Item 1 is that if the entity fails to comply with a direction, it is a breach of their condition of participation in the AGDIS. This will enable the Digital ID Regulator to take compliance and enforcement actions, such as suspension or revocation of the entities’ approval to participate in AGDIS, under the Digital ID Act. This reflects the System Administrator’s role in managing digital ID fraud incidents and cyber security incidents, and the Digital ID Regulator’s role in ensuring compliance with the digital ID legislative framework.
- Subrule 4A.3A(3) sets out matters to which the System Administrator must have regard, and may have regard, in determining whether to give a direction. The effect of this provision is that the System Administrator must consider each of the 7 mandatory considerations in determining whether to give a direction, in addition to any other matters it considers relevant.
- Broadly, the System Administrator must consider the seriousness and scale of the relevant incident, its impact on the individual (including financial consequences and the period during which the digital ID was unavailable), the entity’s conduct in resolving the issue and whether it acted in good faith in dealing with individuals and entities in the AGDIS, the extent to which the entity caused or contributed to the issue, and whether the incident was reasonably foreseeable or could have been mitigated.
- The considerations are intended to support a proportionate exercise of the direction power by the System Administrator and signal the expected behaviour within the AGDIS to entities.
- Subrule 4A.3A(4) provides that a direction must be in writing and must specify the reasons for the direction. These requirements support transparency by ensuring that the basis for the direction is clearly articulated to the receiving entity. Outside of these requirements, the Amendment Rules do not provide the method of how a written direction is to be given to the entity.
- Subrules 4A.3A(5) and (6) establish a show cause process. Broadly, before giving a direction, the System Administrator must give the entity a written notice of the proposed direction, including the reasons for it, and invite the entity to respond in writing within 28 days. The entity’s response must show why the System Administrator should not give the direction to that entity.
- These requirements support procedural fairness by ensuring that the entity is informed of the proposed direction and the reasons for it and is given a reasonable opportunity to respond before a decision is made. The show cause process allows the System Administrator to consider any relevant information provided by the entity, such as the entity’s explanation of the circumstances of the technical issue and its actions in response, before determining whether a direction should be given.
- Subrule 4A.3A(7) provides that, where an entity is directed to issue an apology to the individual, the entity may state that the apology does not constitute an express or implied admission of fault or liability in connection with the technical issue. This provision is intended to enable an entity to comply with a direction without affecting its legal position. It does not determine, limit or otherwise affect any liability of the entity, or any rights or remedies that may otherwise arise in connection with the technical issue.
- Subrule 4A.3A(8) requires the System Administrator to give written notice to the Digital ID Regulator where a direction has been given, including the reasons for the direction. This requirement supports the Digital ID Regulator’s regulatory functions by ensuring visibility of the exercise of the System Administrator’s direction powers.
Rule 4A.4 System Administrator may recommend a resolution
- New rule 4A.4 strengthens and expands the System Administrator’s existing recommendation power and provides a framework around the exercise of this power. Previously, the System Administrator could only recommend a course of action to an entity to resolve a technical issue. This amendment enables the System Administrator to also recommend that the entity pay an amount of money to the individual. Any recommendation must be given in writing and specify the reasons for the recommendation. These changes reinforce accountability of entities to individual digital ID users and encourage the provision of appropriate redress.
- If an entity receives a recommendation, they are required to notify the System Administrator of whether they propose to implement that recommendation. It is not a requirement that the entity implements the recommendation. This amendment is intended to support building an evidence base of how entities engage with digital ID users and to identify whether additional user supports may be required in the future.
- As the Digital ID legislative framework was established in 2024, the inclusion of recommendations which may be voluntarily accepted by entities was considered appropriate at this stage. This approach reflects that financial redress or a course of action to revolve technical issues may be an appropriate remedy for individuals adversely affected by a cyber security or digital ID fraud incident in some circumstances.
- The Amendment Rules do not prescribe any courses of action that the System Administrator may recommend to a relevant entity under paragraph 4A.4(2)(a), or a detailed methodology for calculating an amount to pay to an individual under paragraph 4A.4(2)(b). This approach reflects and supports a flexible, case-by-case assessment of outcomes the System Administrator deems appropriate following their considerations.
- This recommendation power does not affect existing requirements on relevant entities under the Digital ID Rules and Digital ID (Accreditation) Rules 2024, such as a requirement to provide support to individuals under rules 4.11 and 4.30 of the Digital ID (Accreditation) Rules 2024. It also does not affect the System Administrator’s existing powers under the Digital ID Act, such as the power under section 130 to give directions to protect the integrity or performance of the AGDIS.
- It is open for the Digital ID Regulator to take into account whether the entity implements the recommendation and its reasons for not doing so as part of their considerations on whether it is appropriate for an entity to be an accredited entity, or participate in the AGDIS under paragraphs 25(2)(e) or paragraph 71(2)(e) of the Digital ID Act, respectively. In making this determination, the Regulator may have regard to whether the entity is a fit and proper person and any matters it considers relevant under paragraph 12(b) of the Digital ID Act.
- Subrule 4A.4(1) provides that, where a technical issue within the control of an entity has been referred under rule 4A.3, the System Administrator may recommend a course of action to resolve the issue, and/or recommend that the entity pay an amount to the individual.
- Subrule 4A.4(2) sets out matters to which the System Administrator must have regard, and may have regard, in determining whether to make a recommendation. The effect of this provision is that the System Administrator must consider each of the 7 mandatory considerations in determining whether to give a recommendation, in addition to any other matters it considers relevant.
- The mandatory considerations for determining whether to make a recommendation are identical to the mandatory considerations for giving a direction. This recognises that the policy intention and the circumstances which enliven the directions power and the recommendation power are the same. That is, these considerations are intended to support a proportionate exercise of the recommendation power by the System Administrator and to signal the expected behaviour within the AGDIS to entities.
- Unlike the directions power, a show cause notice is not required before the System Administrator recommends a resolution. This reflects that complying with a recommendation is voluntary for entities.
- Subrule 4A.4(3) provides that a recommendation must be in writing and must specify the reasons for the recommendation. These requirements support transparency by ensuring that the basis for the recommendation is clearly articulated to the entity. Outside of these requirements, the Amendment Rules do not provide the method of how a written recommendation is to be given to the entity.
- Subrule 4A.4(4) requires an entity that receives a recommendation to give written notice to the System Administrator stating whether the entity proposes to implement the recommendation and, if not, the reasons for not doing so.
- The Note under subrule 4A.4(4) provides that compliance with this subrule by a participating entity is a condition on the entity’s approval to participate in the AGDIS: see item 5 of the table in subrule 3.4(1).
- The effect of this provision and Item 1 is that if the entity fails to notify the System Administrator on how it proposes to respond to the recommendation, it is a breach of their condition of participation in the AGDIS. This will enable the Digital ID Regulator to take compliance and enforcement actions, such as suspension or revocation to an entity’s approval to participate in the AGDIS, as provided by the Digital ID Act.
- The purpose of attaching a consequence of non-compliance only to subrule 4A.4(4) is to build an understanding of how entities respond to, and support, the digital ID users, and whether recommendations are being appropriately considered even if they are not implemented. This information will assist with determining whether digital ID users need further support and whether additional regulatory measures may be appropriate.
- Subrule 4A.4(5) provides that this notice must be given in writing within 28 days after the recommendation is received.
- The 28 day timeframe and written record requirement promote timely engagement between the System Administrator and the entity receiving the recommendation. As the reply has consequences under subrule 4A.4(4), this timeframe provides entities with a reasonable opportunity to assess the recommendation, consider implementation, or where appropriate, provide reasons for not doing so.
- Subrule 4A.4(6) requires the System Administrator to give written notice to the Digital ID Regulator where a recommendation has been made, including the reasons for the recommendation and the entity’s response. Consistent with subrule 4A.3A(8), this requirement supports the Digital ID Regulator’s regulatory functions by ensuring visibility of the exercise of the recommendation power and the entity’s response.
Item 8 – Chapter 6A – Review of Decisions
- Item 8 inserts new ‘Chapter 6A – Review of decisions’ after Chapter 6 in new rule 6A.1.
- Subrule 6A.1(1) provides that the rule is made for the purposes of subsection 137(2) of the Digital ID Act. Subsection 137(2) of the Digital ID Act provides that the Rules may also provide that a decision made under a specified provision of this Act is a reviewable decision; and the Rules may specify the entity who is an affected entity for the reviewable decision.
- Subrule 6A.1(2) provides that a decision referred to in column 1 of an item of the following table is a reviewable decision. An entity referred to in column 2 of the item is the affected entity for the decision.
- Column 1 of the table under subrule 6A.1(2) provides that a decision by the System Administrator to give a direction to an entity under subrule 4A.3A(2) is a reviewable decision and column 2 provides for the ‘affected entity’ who can seek review of the decision being the entity subject to the direction.
- Table item 1 provides that a decision by the System Administrator to give a direction to an entity under subrule 4A.3A(2) is a reviewable decision. The affected entity is the entity to which the direction is given.
- The effect of this amendment is to enable an entity subject to a direction under subrule 4A.3A(2) to seek merits review of the System Administrator’s decision to give a direction. This amendment recognises that a direction under subrule 4A.3A(2) is binding and could affect the entity’s participation in the AGDIS or their accreditation. As such, it is important for the System Administrator’s decision to be reviewable by the Administrative Review Tribunal. Providing access to review ensures openness and accountability of decisions made under the Redress Framework.
- In contrast, a recommendation made under subrule 4A.4(1) is not a reviewable decision. This reflects the non-binding nature of a recommendation and that the recommendation itself does not create or seek to impose a legal consequence on the rights and interests of an entity.
- An entity’s failure to comply with the requirements in subrule 4A.4(4), which is a breach of their condition, is also not a reviewable decision. This is to reflect that whether the entity complies is a matter of fact. Any compliance and enforcement action taken by the Digital ID Regulator in relation to the entity’s breach of that condition will be subject to any merits review provided under the Digital ID Act.
Item 9 – At the end of Chapter 7
- Item 9 adds rule 7.2 ‘Application of amendments made by the Digital ID Amendment (Redress Framework) Rules 2026’ to set out the transitional application of the amendments introduced by these Amendment Rules.
- Subrule 7.2(1) provides that rule 4A.2, as amended by these Rules, applies in relation to incidents that occur, or are reasonably suspected of having occurred, on or after the day this rule commences.
- Subrule 7.2(2) provides that rule 4A.3A, as inserted by these Rules, applies in relation to referrals made on or after the day this rule commences.
- Subrule 7.2(3) provides that rule 4A.4, as amended by these Rules, applies in relation to referrals made on or after the day this rule commences.
- The purpose and effect of rule 7.2 is to provide for the prospective application of the amendments made by the Amendment Rules.
ATTACHMENT B
Statement of Compatibility with Human Rights
Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011
Digital ID Amendment (Redress Framework) Rules 2026
- The Digital ID Amendment (Redress Framework) Rules 2026 (Amendment Rules) are compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.
Overview of the Rules
- The Amendment Rules amend the Digital ID Rules 2024 (the Rules) to strengthen the operation of the redress framework established in Chapter 4A of the Rules, which supports individuals affected by digital ID fraud incidents and cyber security incidents relating to accredited services of accredited entities within the Australian Government Digital ID System (AGDIS).
- Private sector entities can apply to participate in the AGDIS from late 2026. As the system grows in scale and complexity, the availability of clear, accessible and effective mechanisms to address adverse impacts on individuals becomes increasingly important to maintaining trust and confidence in the system.
- The Amendment Rules support meaningful participation in the AGDIS and contribute to the protection of human rights, including the right to privacy and the availability of accessible and effective remedies where individuals experience harm.
- In particular the Amendment Rules:
- support the right to privacy by limiting the circumstances in which Attribute Service Providers or Identity Service Providers in the AGDIS may withhold notification, ensuring affected digital ID users are informed where their personal information may be affected;
- promotes accountability and transparency through clearer record-keeping requirements for relevant accredited entities;
- provides for effective remedies by enabling the System Administrator to give written directions to relevant accredited entities to apologise or provide an explanation to an affected digital ID user and to recommend financial payment to an affected digital ID user where appropriate;
- promotes procedural fairness by outlining how these powers are to be exercised including key considerations and notification to the Digital ID Regulator; and
- supports the right to a fair hearing by confirming that directions made by the System Administrator are subject to review by the Administrative Review Tribunal.
Human rights implications
- The Amendment Rules engage the following rights:
- the right to an effective remedy (Article 2(3) of the ICCPR); and
- the right to privacy (Article 17 of the ICCPR).
Right to an Effective Remedy
- Article 2(3) of the ICCPR requires that individuals have access to an effective remedy where their rights have been adversely affected, including through accessible and effective administrative mechanisms.
- The Amendment Rules promote this right by strengthening mechanisms within the redress framework for individuals affected by digital ID fraud incidents or cyber security incidents. In particular:
- directions under the Amendment Rules may require entities to provide explanations or apologies to affected individuals, supporting transparency and acknowledgement of impacts; and
- recommendations made by the System Administrator provide a clear and reasoned suggestion supporting the entity to identify actions that may be appropriate to consider, including that an amount be paid in appropriate circumstances, to support resolution of issues and to improve outcomes for affected individuals.
- These measures enhance the operation and clarity of redress processes and support effective, timely and consistent administrative responses to cyber security or digital ID fraud incidents, including by facilitating outcomes that respond to the non‑monetary impacts experienced by affected individuals.
Right to Privacy
- Article 17 of the ICCPR protects individuals against arbitrary or unlawful interference with their privacy, including in relation to the collection, use and disclosure of personal information.
- Under the Rules, certain entities must make reasonable attempts to notify each individual affected by a cyber security or digital ID fraud incident. Entities will need to deal with personal information in notifying an affected individual. This notification obligation is subject to limited exceptions. The Amendment Rules engage this right by narrowing the exception where these entities do not need to notify an affected digital ID user.
- Under the Amendment Rules, entities must not have regard to certain matters, such as the entity’s reputational damage or administrative costs, in determining whether to notify an affected individual. The Amendment Rules also provide that an entity must provide an explanation of the circumstances giving rise to a technical issue, and/or issue an apology to an affected digital ID user, where directed to do so by the System Administrator.
- While entities will generally already hold personal information about the affected digital ID user to whom they provide services, complying with the Amendment Rules may require the collection, use, or disclosure of additional personal information, or the use or disclosure of that information for a specific purpose connected with a digital ID fraud or cyber security incident.
- To the extent that these activities engage the right to privacy under Article 17 of the ICCPR, any interference is reasonable, necessary and proportionate to achieving a legitimate objective. The objective of the Amendment Rules is to ensure that affected individuals are notified in a timely manner and can receive an appropriate redress outcome, such as an explanation or apology, where they are adversely affected by a digital ID fraud or cyber security incident. These measures support a user‑centred approach to notification and redress within the Digital ID Redress Framework. They also assist individuals to understand the nature and impact of an incident affecting their digital ID. Timely and more consistent notification enables affected individuals to take appropriate steps to respond to, and mitigate, potential impacts from malicious activity.
- The scope of any personal information handling is limited to what is required to enable entities to comply with these notification and redress obligations and is therefore targeted and not arbitrary. In addition, any collection, use or disclosure of personal information remains subject to the existing safeguards in the Digital ID Act and the Privacy Act 1988, which regulate how personal information may be handled and provide oversight and accountability mechanisms.
- The Amendment Rules strengthen procedural requirements that support the protection against arbitrary interference with privacy under Article 17 by ensuring decisions which impact an individuals’ personal information are made on a recorded, reasoned and transparent basis.
- The Amendment Rules are consistent with the right to privacy under Article 17 of the ICCPR.
Conclusion on overall compatibility with human rights
- The Amendment Rules are compatible with human rights because they promote the right to an effective remedy and support the protection of privacy and the right to fair trial and public hearing. To the extent that they may limit the right to privacy, those limitations are reasonable, necessary and proportionate.
Senator the Hon Katy Gallagher, Minister for Finance