Most digital identity frameworks treat privacy as a compliance problem: provide adequate notice, obtain consent, document the data flows. If individuals click "agree," the organization is covered.
Utah's State-Endorsed Digital Identity (SEDI) program takes a different approach. Embedded in its 2026 legislation is a provision called the Duty of Loyalty, which does not ask whether individuals consented to a particular use of their identity data. It asks whether that use actually serves them. The distinction has significant practical consequences for how digital identity systems must be designed and governed, and it represents one of the more novel ideas in recent state privacy legislation.
What the Duty of Loyalty Requires
The Duty of Loyalty appears in Utah Code 63A-20-701. Its language is deliberately broad. The statute requires that the Utah Department of Government Operations, digital wallet providers, verifiers, relying parties, and digital guardians "shall refrain from practices or activities related to the processing of an individual's identity attributes from a digital identity that:
(1) conflict with the best interests of an individual; (2) take advantage of or otherwise exploit an individual; (3) result in a disproportionate risk to an individual; (4) are to an individual's detriment; or (5) cause harm to an individual."
The obligation runs to every actor in the SEDI ecosystem, not just the state agency that issues credentials. A private wallet provider handling identity attributes on behalf of a holder falls under this duty. So does a business relying on a verifier's assertion about a customer's age. So does a government agency accepting a credential to confirm residency for a benefits program. In a well-functioning SEDI ecosystem, the Duty of Loyalty is not a constraint on a single entity; it is a standard applied across the entire chain of interactions.
Why This Departs From Conventional Privacy Law
The dominant model in U.S. privacy law is notice and consent. An organization discloses its data practices, often in a privacy policy that runs thousands of words and governs dozens of use cases. The individual acknowledges the policy, usually by clicking a button or continuing to use a service. From that point, the organization has a legal basis for most of its intended processing.
This framework has been criticized on practical grounds for decades. Privacy policies are rarely read, consent flows are rarely understood, and because consent establishes a floor rather than a ceiling, organizations can design disclosure flows to maximize what they are permitted to do.
The Duty of Loyalty changes this structure. An organization bound by it cannot simply argue that it disclosed a practice and got a click. It must show that the practice serves the individual whose identity is being processed, or at least does not harm them. The obligation runs to the person, not to a compliance checklist.
This is not a novel idea in law. Fiduciary duties in finance, medicine, and law require advisors, doctors, and attorneys to place client interests above their own. The specific articulation in SEDI draws on academic work by Neil M. Richards and Woodrow Hartzog, who argued in "A Duty of Loyalty for Privacy Law" (99 Washington University Law Review 961, 2021) that data collectors "would be obligated to act in the best interests of people exposing their data and online experiences, up to the extent of their exposure" and "prohibited from designing digital tools and processing data in a way that conflicts with trusting parties' best interests." Utah did not invent this concept; it enacted it. The SEDI statute directly incorporates Richards and Hartzog's framework as a legally binding obligation. Because the duty falls on every actor that handles identity attributes, understanding how verifiable digital credentials work technically, including the cryptographic mechanisms that underpin identity attributes and presentations, helps clarify why the governance obligation attaches to specific technical actors in the credential chain.
The Full Ecosystem Scope
The Duty of Loyalty applies to a notably wide set of participants. Understanding why requires understanding how a SEDI credential actually moves through a transaction.
When a holder presents a SEDI credential, the presentation runs through a digital wallet, is cryptographically checked by a verifier, and relied upon by a relying party. A digital guardian may manage this process on behalf of a minor or someone unable to manage their own identity. At each stage, an entity handles identity attributes belonging to a real person. A verifier retaining more data than required, a wallet provider monetizing usage patterns, a relying party passing on identity information for unrelated purposes: all fall within the duty's reach.
Utah's State-Endorsed Digital Identity framework is designed as a whole-ecosystem governance structure rather than a set of rules applied only to the state issuer. The Duty of Loyalty is one of the clearest expressions of that design intent.
How It Connects to the Rest of SEDI's Privacy Architecture
The Duty of Loyalty does not operate in isolation. It sits within a set of interlocking statutory provisions that together define how identity data may be handled throughout the SEDI ecosystem.
The processing restrictions in Utah Code 63A-20-702 specify that records of presentations may only be processed for the primary purpose of that presentation, or as required by law. Information provided during a presentation may only be used for the purpose for which the holder originally disclosed it, and may only be used, retained, sold, or shared if the holder has received conspicuous notice and has expressly authorized it, or if required by law.
The "no phone home" provision (63A-20-301(3)) requires that a state-endorsed digital identity not include any mechanism that allows the department to monitor, surveil, or track presentations to other entities. The statute's language speaks to what may be included in a credential, not merely what data may be used after the fact, which suggests a design-level prohibition rather than a use restriction. As of September 2026, official implementation standards have not yet been published by the Department of Government Operations; whether those standards will specify this as a hard architectural requirement rather than a behavioral one remains to be seen.
Wallet providers face a further set of obligations under 63A-20-401: they may only process identity attributes when processing is necessary for a presentation, when the holder has received clear notice of what is collected, how it is used, the purpose, and the retention period, and when the holder has consented. The wallet must also maintain a secure log of presentations, accessible and deletable only by the holder, showing what attributes were provided and to whom.
Together, these provisions describe a privacy architecture in which legal obligations are expressed through specific technical constraints rather than through policies that sit above system design. The Duty of Loyalty gives that architecture its normative foundation: whatever specific mechanisms exist, the overarching obligation is to avoid practices that harm the individual.
Independent Assessment
Jay Stanley of the ACLU has published one of the most substantive independent analyses of Utah's SEDI legislation, calling it "the best effort we have yet seen in a state to square privacy protections with the looming dangers to civil liberties that flow from digital identities." The Duty of Loyalty is, in his assessment, the law's "most striking feature," representing a structural departure from the notice-and-consent model that dominates privacy regulation. The ACLU's endorsement carries weight precisely because they have been skeptical of digital identity programs that lack strong individual protections.
As with any new legal framework, the strength of the Duty of Loyalty will be demonstrated through implementation and enforcement over time. The eleven enumerated rights in the Digital Identity Bill of Rights provide the statutory foundation that the duty is designed to reinforce, and the legislative audit mandated for 2028 creates a formal checkpoint for evaluating how effectively these provisions are operating in practice.
What It Means for System Design
For implementers, the Duty of Loyalty has direct architectural implications, even before it is tested in enforcement.
An organization subject to the duty has an affirmative reason to minimize the identity data it collects, retain it for the shortest time necessary, and design its systems to make misuse difficult rather than simply prohibited. Selective disclosure, which allows a holder to prove a specific attribute, such as being over 21, without revealing the underlying birth date or any other information, is directly aligned with the duty's requirements: requesting more information than a transaction requires creates disproportionate risk, which the duty prohibits.
The same logic applies to data retention. A verifier that retains full identity attributes after a transaction has concluded is holding data that no longer serves the purpose of the presentation. Under the processing restrictions in 63A-20-702, this is already prohibited. Under the Duty of Loyalty, retaining that data also works against the individual's interests by creating unnecessary exposure to breach, misuse, or sale. The two provisions reinforce each other.
For wallet providers, the duty creates a baseline against which product decisions can be evaluated. A feature that monetizes user behavior, aggregates presentation patterns across contexts, or defaults to broader data retention than the individual would choose if given a clear explanation is at risk of violating the duty regardless of whether the individual clicked through a consent flow. The duty requires organizations to ask whether a practice actually serves the person, not whether it can be disclosed in a way the person might accept.
How privacy and user control work in practice within digital identity systems, including how architectural choices create or constrain meaningful individual control, provides useful context for evaluating these product decisions.
The Broader Policy Significance
Utah's decision to enact a statutory Duty of Loyalty represents one of the more significant policy moves in recent state digital identity legislation, not because it solves every problem, but because it changes the normative framework.
Most current digital identity legislation in the United States focuses on credential formats, interoperability standards, and acceptance requirements. These are important questions. But they largely take for granted that the data handling practices of credential issuers, wallet providers, and verifiers will be governed by existing privacy law, which defaults to notice and consent. SEDI asks a harder question: given that every presentation of a digital identity involves the disclosure of sensitive personal attributes to one or more parties, what obligations do those parties owe to the individual?
The Richards and Hartzog paper that underlies SEDI's Duty of Loyalty characterizes this kind of obligation as a potential "revolution in data privacy law." That framing is aspirational. The statute's language is strong in principle and genuinely novel. Whether it produces substantive protection depends on implementation quality, regulatory guidance, enforcement capacity, and legislative follow-up on the gaps the ACLU has identified.
What it does accomplish now is to establish a legal standard against which practices can be evaluated and, eventually, challenged. For a framework that places individual rights at the top of its values hierarchy, building a legally binding obligation of loyalty toward individuals into the statute is a meaningful structural choice. It makes the rights in the Digital Identity Bill of Rights something more than aspirational language by giving them an enforcement path that does not depend entirely on proving a specific prohibited act.
For policymakers in other states considering digital identity legislation, the Duty of Loyalty is worth examining carefully, both for what it requires and for the gaps that Utah's experience will help clarify. The concept of affirmative obligations toward individuals whose identity data is being processed, grounded in fiduciary-style thinking, offers a different foundation than notice-and-consent frameworks, and the coming years of SEDI implementation will generate practical evidence about what that foundation actually supports.
Questions That Remain Open
The Duty of Loyalty establishes an obligation without defining its full scope. Several practical questions will need to be resolved through implementation guidance, enforcement, or future legislation.
What constitutes a disproportionate risk? The term appears in the statute without definition. Risk to an individual varies by context: an age verification for alcohol purchase has a different risk profile than an identity assertion supporting access to financial services. Regulators or courts will need to develop a framework for assessing proportionality.
How does the duty apply to secondary uses? If a wallet provider aggregates information about presentation patterns across its entire user base and uses that aggregate data for product development, is that a practice that "takes advantage of" individual users? The processing restrictions in 63A-20-702 limit use of data from specific presentations, but the Duty of Loyalty's scope regarding derived or aggregated data is not specified.
What does enforcement look like without a private right of action? The ombudsperson-to-attorney-general pathway may work well for systemic violations by large actors. It is less clear how individual harms that fall below the threshold likely to attract AG attention will be addressed.
How will the duty apply as AI systems become involved in identity processing? The "Protecting Liberty" document that preceded SEDI legislation identified agentic AI as a potential application for the framework. If an AI system processes SEDI attributes as part of an automated decision, who holds the duty of loyalty to the individual, and how is it enforced when the processing is non-transparent?
These are not arguments that the Duty of Loyalty is unworkable. They are the questions that any serious implementation program will need to address. The ACLU's assessment suggests that with follow-up legislation to close the gaps, Utah's SEDI could become a model for privacy-protective digital identity. The Duty of Loyalty is the provision that makes that aspiration plausible.
If you are working on digital identity implementation and have questions about how governance obligations translate into credential architecture, we welcome the conversation. As digital identity becomes policy infrastructure across more states, the Duty of Loyalty offers a model for grounding that infrastructure in enforceable obligations rather than voluntary best practices.
About SpruceID: SpruceID builds digital trust infrastructure for government. We help states and cities modernize identity, security, and service delivery — from digital wallets and SSO to fraud prevention and workflow optimization. Our standards-based technology and public-sector expertise ensure every project advances a more secure, interoperable, and citizen-centric digital future.