Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Digital Identity Utah topic

No spam. Unsubscribe anytime.

Utah panel: state-endorsed digital ID aims to give individuals control while raising surveillance and private‑sector pressure concerns

3628565 · May 2, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Panelists at a Utah public forum described SB 260’s “state‑endorsed” digital identity approach as an attempt to give individuals control over how and when they use government‑backed digital credentials while acknowledging outstanding technical, governance and privacy risks.

Panelists at a Utah public forum described the state’s move to a “state‑endorsed” digital identity as a deliberate attempt to give individuals control over how and when they use government‑backed digital credentials while acknowledging outstanding technical, governance and privacy risks.

Jay Stanley, policy staff on the privacy team at the American Civil Liberties Union, said Utah’s approach gives other states a model for privacy‑minded digital identity. “Utah has consistently throughout that period, shown superior appreciation and thoughtfulness in the privacy area,” Stanley said, arguing the state’s framework helps privacy advocates persuade other legislatures not to adopt surveillance‑oriented models.

The panel concentrated on SB 260, the 2024–2025 legislative measure described during the session as setting guardrails for a state‑endorsed digital identity. Panelists said the bill emphasizes that individuals — not the state — decide how they disclose their endorsed identity, to whom, which elements are shared, where it is stored and whether to use the digital credential or a physical credential.

Why this matters

Panelists and several audience members said digital credentials can improve security and convenience compared with reused passwords and existing login systems, but they warned that poorly designed systems can become broad surveillance tools. Multiple speakers contrasted models in which a government or identity provider logs every verification event — a capability they called “phone home” or “god mode” — with the Utah policy goal of preventing such centralized tracking.

What the law and state officials propose

Representative Paul Cutler, who sponsored the 2023 verifiable‑credentials bill referenced by the panel, and Alan Fuller, Utah chief information officer, described SB 260 as creating a new category of credential: state endorsed rather than state issued. Fuller said endorsement allows someone who already has a credential from another issuer — for example, a university or another state — to prove it and then receive a Utah endorsement that can be used within the state without creating a live log of every verification.

Joe Jackson, chief technology officer in the Division of Technology Services at the Utah Department of Government Operations, said the state has already piloted verifiable digital credentials for lower‑risk items (off‑highway vehicle training certificates) and saw “tens of thousands” of adoptions. Jackson said the next steps include an RFI (request for information) to evaluate technology, standards and vendor proposals and a report back to the legislature before any full statewide credential rollout.

Technical and governance debates

Panelists repeatedly distinguished between two technical goals: (1) preventing the issuer or the state from keeping a transaction log of every time a credential is used, and (2) preventing third parties or verifiers (for example, merchants or websites) from collecting and sharing more data than needed for a transaction.

Timothy Ruff, a partner at Digital Trust Venture Partners, and other technologists on the panel argued against relying on public blockchains as a general solution for identity, citing privacy, performance and governance concerns. They offered alternative cryptographic and protocol approaches (one panelist cited KERI‑style mechanisms) and emphasized that usable wallets and key‑management are solvable engineering problems if privacy and security are designed in from the start.

Public comments and examples

Several audience members described real‑world privacy problems when clerks scanned physical IDs and full data became visible or stored. Troy Staker, an audience member who said he retired from law enforcement, described a restaurant and liquor‑store experience in which scanned ID data was exposed and expressed support for a mobile ID design that shares only what is necessary (for example, a single age assertion rather than full name, address, birthdate).

Concerns about surveillance and the private sector

Speakers warned that even a privacy‑focused government credential could create pressure from private businesses and websites to require digital identification, potentially concentrating tracking and enabling data brokers. Jay Stanley and others urged policy limits on what private entities can request, and said the state should preserve the right to a paper or physical credential for people who do not want to go digital.

Policy and implementation steps described

- The state will proceed with pilots and an RFI to gather technology and policy recommendations and return to the legislature with findings; lawmakers retain final approval authority for any credential system. - The Division of Driver’s License (in Utah’s public safety structure) is a partner but panelists said they expect a broader governance conversation — including whether a dedicated identity office or independent audit function is needed. - Panelists proposed that the state publish security and privacy standards for any wallets that store a state‑endorsed credential and that a state default wallet be available while allowing citizens to choose certified alternative wallets.

Clarifying details and cited data

Panelists cited a U.S. Government Accountability Office estimate that pandemic‑era unemployment insurance fraud totaled roughly $100 billion to $135 billion as an example of identity‑based fraud the new systems aim to reduce. They also referenced ISO 18013‑5 (mobile driver’s license standards) as a technical standard with phone‑home privacy risks. Panelists credited Utah laws passed in recent sessions — including last year’s privacy bill described by the panel as HB 491 — as groundwork for the current effort.

Next steps and public input

Panelists encouraged public comment and said the RFI and follow‑up legislative report will be opportunities for cities, counties, vendors and privacy organizations to influence standards and governance. No formal votes or final policy approvals were taken at the forum.

Ending

Speakers described the state approach as an attempt to reconcile convenience, security and civil‑liberty protections while acknowledging unresolved questions about governance, interoperability with other states and the private sector’s appetite for identity‑linked data. Officials said pilots, an RFI and a legislative review are the immediate next steps.