Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Digital Identity Utah topic
No spam. Unsubscribe anytime.
Utah panel: state-endorsed digital ID aims to give individuals control while raising surveillance and private‑sector pressure concerns
Summary
Panelists at a Utah public forum described SB 260’s “state‑endorsed” digital identity approach as an attempt to give individuals control over how and when they use government‑backed digital credentials while acknowledging outstanding technical, governance and privacy risks.
Get email alerts on the Digital Identity Utah topic
No spam. Unsubscribe anytime.
Panelists at a Utah public forum described the state’s move to a “state‑endorsed” digital identity as a deliberate attempt to give individuals control over how and when they use government‑backed digital credentials while acknowledging outstanding technical, governance and privacy risks.
Jay Stanley, policy staff on the privacy team at the American Civil Liberties Union, said Utah’s approach gives other states a model for privacy‑minded digital identity. “Utah has consistently throughout that period, shown superior appreciation and thoughtfulness in the privacy area,” Stanley said, arguing the state’s framework helps privacy advocates persuade other legislatures not to adopt surveillance‑oriented models.
The panel concentrated on SB 260, the 2024–2025 legislative measure described during the session as setting guardrails for a state‑endorsed digital identity. Panelists said the bill emphasizes that individuals — not the state — decide how they disclose their endorsed identity, to whom, which elements are shared, where it is stored and whether to use the digital credential or a physical credential.
Why this matters
Panelists and several audience members said digital credentials can improve security and convenience compared with reused passwords and existing login systems, but they warned that poorly designed systems can become broad surveillance tools. Multiple speakers contrasted models in which a government or identity provider logs every verification event — a capability they called “phone home” or “god mode” — with the Utah policy goal of preventing such centralized tracking.
What the law and state officials propose
Representative Paul Cutler, who sponsored the 2023 verifiable‑credentials bill referenced by the panel, and Alan Fuller, Utah chief information officer, described SB 260 as creating a new category of credential: state endorsed rather than state issued. Fuller said endorsement allows someone who already has a credential from another issuer — for example, a university or another state — to prove it and then receive a Utah endorsement that can be used within the state without creating a live log of every verification.
Joe Jackson, chief technology officer in the Division of Technology Services at the Utah Department of Government Operations, said the state has already piloted verifiable digital credentials for lower‑risk items (off‑highway vehicle training certificates) and saw “tens of thousands” of adoptions. Jackson said the next steps include an RFI (request for information) to evaluate technology, standards and vendor proposals and a report back to the legislature before any full statewide credential rollout.
Technical and governance debates
Panelists repeatedly distinguished between two technical goals: (1) preventing the issuer or the state from keeping a transaction log of every time a credential is used, and (2) preventing third parties or verifiers (for example, merchants or websites) from collecting and sharing more data than needed for a transaction.
Timothy Ruff, a partner at Digital Trust Venture Partners, and other technologists on the panel argued against relying on public blockchains as a general solution for identity, citing privacy, performance and governance concerns. They offered alternative cryptographic and protocol approaches (one panelist cited KERI‑style mechanisms) and emphasized that usable wallets and key‑management are solvable engineering problems if privacy and security are designed in from the start.
Public comments and examples
Several audience members described real‑world privacy problems when clerks scanned physical IDs and full data became visible or stored. Troy Staker, an audience member who said he retired from law enforcement, described a restaurant and liquor‑store experience in which scanned ID data was exposed and expressed support for a mobile ID design that shares only what is necessary (for example, a single age assertion rather than full name, address, birthdate).
Concerns about surveillance and the private sector
Speakers warned that even a privacy‑focused government credential could create pressure from private businesses and websites to require digital identification, potentially concentrating tracking and enabling data brokers. Jay Stanley and others urged policy limits on what private entities can request, and said the state should preserve the right to a paper or physical credential for people who do not want to go digital.
Policy and implementation steps described
- The state will proceed with pilots and an RFI to gather technology and policy recommendations and return to the legislature with findings; lawmakers retain final approval authority for any credential system. - The Division of Driver’s License (in Utah’s public safety structure) is a partner but panelists said they expect a broader governance conversation — including whether a dedicated identity office or independent audit function is needed. - Panelists proposed that the state publish security and privacy standards for any wallets that store a state‑endorsed credential and that a state default wallet be available while allowing citizens to choose certified alternative wallets.
Clarifying details and cited data
Panelists cited a U.S. Government Accountability Office estimate that pandemic‑era unemployment insurance fraud totaled roughly $100 billion to $135 billion as an example of identity‑based fraud the new systems aim to reduce. They also referenced ISO 18013‑5 (mobile driver’s license standards) as a technical standard with phone‑home privacy risks. Panelists credited Utah laws passed in recent sessions — including last year’s privacy bill described by the panel as HB 491 — as groundwork for the current effort.
Next steps and public input
Panelists encouraged public comment and said the RFI and follow‑up legislative report will be opportunities for cities, counties, vendors and privacy organizations to influence standards and governance. No formal votes or final policy approvals were taken at the forum.
Ending
Speakers described the state approach as an attempt to reconcile convenience, security and civil‑liberty protections while acknowledging unresolved questions about governance, interoperability with other states and the private sector’s appetite for identity‑linked data. Officials said pilots, an RFI and a legislative review are the immediate next steps.
