Utah's State-Endorsed Digital Identity Act, enacted as SB 275 during the 2026 General Session and effective May 6, 2026, is the most comprehensive state digital identity statute passed in the United States to date. It does not simply authorize a digital ID card. It establishes a legal framework: defining individual rights, governing what every participant in the ecosystem may and may not do with identity data, requiring open standards, and creating enforcement mechanisms with teeth. Understanding what the law actually does is the prerequisite for understanding why other states and national organizations are paying attention.
This post works through the major components of the enacted statute, State-Endorsed Digital Identity (SEDI), in terms useful to legislators, governors' policy teams, and government technology leaders. It distinguishes throughout between what SB 275 requires as a matter of law, what the Utah Department of Government Operations' working implementation guide proposes, and what remains to be determined through subsequent rulemaking and implementation.
What the statute actually creates
SB 275 is codified as Utah Code Title 63A, Chapter 20. The administering agency is the Utah Department of Government Operations. The law creates a "State-Endorsed Digital Identity Program" whose central purpose is not to mandate digital IDs but to define the conditions under which the state will endorse them.
That framing is the statute's first and most important architectural choice. The law does not say every Utah resident must obtain a digital identity, or that every agency must deploy a digital system. It says that when the state endorses a digital identity, that endorsement must carry meaningful legal guarantees about rights, privacy, and accountability. A state-endorsed digital identity, as defined in 63A-20-201, is an individual's digital identity that includes a personal digital identifier and that the department has issued. The personal digital identifier must be unique, created by or at the direction of the individual, mathematically provable to be under the holder's control, and transportable to technical infrastructure of the holder's choosing. Notably, this is not a government-assigned number. The individual creates it; the state endorses it.
SEDI is a framework, not a credential type. Multiple credential formats can qualify for endorsement if they satisfy the same statutory requirements. This is a meaningful structural distinction from a government-issued mobile driver's license, which prescribes the credential form. SEDI prescribes the rules of the ecosystem.
Eleven rights with statutory force
The Digital Identity Bill of Rights appears at Utah Code 63A-20-101. These are not design guidelines or policy aspirations. They are enacted law, and they describe what every individual possesses or may claim as a matter of right.
The eleven rights, in abbreviated form, are:
- Innate identity: "An individual possesses an individual identity innate to the individual's existence and independent of the state, which identity is fundamental and inalienable."
- Management and control: the right to manage and control one's digital identity to protect individual privacy.
- Right to physical identity: the right to choose, receive, and use a physical form of state-endorsed identity assertion.
- Freedom from compelled digitization: the right not to be compelled by the state to possess, use, or rely on a digital form of identity in place of a physical one.
- Right to endorsement: the right to state endorsement upon meeting objective, uniform standards, and the right not to have endorsement arbitrarily withheld or revoked.
- Legislative governance: the right to have digital identity systems governed by clear standards established by the Legislature.
- Transparency: the right to access, read, and review the standards and technical specifications on which state digital identity is built.
- Selective disclosure: the right to choose what identity attributes are disclosed in accordance with legislative standards.
- Format neutrality: the right to any service or benefit the individual is otherwise entitled to, regardless of which lawful format or means of identity assertion they choose.
- Freedom from surveillance: the right to be free from surveillance, profiling, tracking, or persistent monitoring of digital identity assertions by the state, except as authorized by law.
- Device sovereignty: the right not to be required by the state to surrender one's device in order to present a digital identity.
Several of these rights represent explicit legislative responses to specific failure modes of earlier digital ID programs. Rights 3 and 4 together guarantee that physical identification remains a genuinely available choice, not just a nominal one. Right 10 addresses issuer surveillance, a structural vulnerability in systems where the credential issuer is notified every time a credential is presented. Right 11 addresses the practice, common enough to require statutory prohibition, of asking individuals to hand over their phones to verification personnel.
Selective disclosure, enumerated as Right 8, warrants emphasis. Under SEDI, an individual proving their age at a bar or an age-gated website is not required to disclose their name, address, or date of birth. They can prove a binary fact (over 21, or over 18) without releasing the underlying attributes. The statute makes this a right, not a feature that an app may or may not implement.
The "no phone home" prohibition
One of the statute's most technically specific provisions appears at 63A-20-301(3): "A state-endorsed digital identity may not include a mechanism that allows the department to monitor, surveil, or track the presentation of a state-endorsed digital identity to another entity."
This language prohibits a class of credential architectures in which the issuing government agency is automatically notified each time a credential is presented. In those architectures, the issuer can construct a log of every transaction: who presented their ID, where, and when. The surveillance risks of such "phone home" designs are well-documented. Governments and private companies can build detailed behavioral profiles from credential transaction logs even when the contents of each individual presentation appear innocuous.
Utah's statute addresses this structurally by prohibiting the mechanism, not just regulating its use. The state cannot build in a back-channel to monitor presentations because the statute makes it illegal for the endorsed credential to include such a mechanism. Jay Stanley of the ACLU specifically praised this provision in his analysis of the law, describing it as a meaningful departure from how most digital identity systems have been designed.
The revocation limitations at 63A-20-301(5) reinforce the same principle from a different direction. The department may only revoke an individual's state-endorsed digital identity in three circumstances: the SEDI has been compromised, the department's endorsement was issued in error or based on fraudulent information, or the holder requests revocation. The state cannot arbitrarily revoke someone's digital identity. This constraint, paired with the surveillance prohibition, reflects a consistent statutory posture: the state endorses identity and may manage obvious integrity failures, but it does not use that endorsement as ongoing leverage over the individual.
Who is bound, and by what
SB 275 creates obligations that extend beyond the issuing agency to every participant in the ecosystem: digital wallet providers, verifiers (the entities that mathematically check credentials), and relying parties (entities that rely on verifier assertions). Each category has specific statutory requirements.
Digital wallet providers under 63A-20-401 must incorporate state-of-the-art identity safeguards, support both online and offline presentation, enable selective disclosure, and enable age-minimum verification without disclosing the actual age or birth date. Critically, wallet providers must maintain a secure log accessible, exportable, and deletable only by the holder, showing what identity attributes were provided and to whom. The holder controls that log. The wallet provider does not retain transaction data on its own behalf. Wallet providers may only process identity attributes when processing is necessary for a presentation, when the holder has received conspicuous notice of what is collected and how it is used, and when the holder consents.
Governmental entities under 63A-20-304 face three specific prohibitions: they may not convey a material benefit for using digital over physical identity, may not withhold services from individuals using physical identity, and may not require device surrender during presentation. New government systems accepting digital identity must accept SEDI within three months after the first SEDI is issued, unless technically infeasible, in which case a plan to achieve acceptance as soon as feasible is required.
Health care providers receiving at least $10,000,000 per year in public funding (63A-20-305) must accept SEDI within two years from issuance of the first credential, if they have a program accepting digital identity.
The Duty of Loyalty
The provision at Utah Code 63A-20-701 is the statute's most conceptually unusual element and arguably its most significant departure from conventional data privacy law.
The statute reads: "The department, a digital wallet provider, a verifier, a relying party, and a digital guardian shall refrain from practices or activities related to the processing of an individual's identity attributes from a digital identity that: (1) conflict with the best interests of an individual; (2) take advantage of or otherwise exploit an individual; (3) result in a disproportionate risk to an individual; (4) are to an individual's detriment; or (5) cause harm to an individual."
Most data privacy frameworks center on notice and consent: an organization can do nearly anything with personal data as long as it discloses the practice and obtains some form of agreement. The Duty of Loyalty creates obligations that exist independently of whether the organization has disclosed its practices and received consent. The question is not whether the individual agreed to something; the question is whether the practice itself serves or harms the individual's interests.
The academic foundation for this approach is explicit in the Utah source documents. The statute's Duty of Loyalty draws directly from Neil M. Richards and Woodrow Hartzog, "A Duty of Loyalty for Privacy Law," 99 Washington University Law Review 961 (2021), which argued that data collectors should be "obligated to act in the best interests of people exposing their data and online experiences, up to the extent of their exposure."
This is a structural argument about what privacy law should require, not merely a stronger version of consent-based protection. Utah has adopted it as binding law on every participant in the SEDI ecosystem. Whether it proves enforceable as written is a different question, discussed below.
Open standards and why the statute specifies them
Utah Code 63A-20-301(2)(e) requires the department to select open technological standards that are publicly available and free from licensing fees and patent restrictions. This requirement is not incidental.
Digital identity ecosystems built on proprietary standards create vendor lock-in: the state becomes dependent on whichever vendor controls the format, and individuals cannot move their credentials between wallet providers without that vendor's cooperation. Open standards allow multiple vendors to build conformant wallets and verification tools without requiring the state to negotiate licensing terms with each one, and without requiring individuals to use a specific wallet provider.
The statute does not specify which open standards the department must adopt. That determination falls to the implementation process. The working implementation guide (Version 0.1.0-draft, May 2026), published at sedi.utah.gov, identifies specific technical standards including ISO/IEC 18013-5 and 18013-7 (mobile document standards), W3C Verifiable Credentials, and NIST SP 800-63-4 (identity proofing guidelines), but the guide explicitly states it represents an interpretation of statutory requirements rather than authoritative guidance. Official implementation standards are to be published by the Department of Government Operations.
The connection to Utah's mobile driver's license program is relevant here. Utah placed a sunset date of January 1, 2027 on its existing mobile driver's license under Utah Code 53-3-235. The decision to sunset the parallel mDL program rather than run both in parallel was deliberate: two competing digital ID systems operating under different rules would create confusion about which protections apply and potentially allow a less-protected system to dominate in practice. Understanding how verifiable digital credentials work as a category helps clarify why credential format and ecosystem governance are related but distinct questions.
Enforcement and its limits
Utah's enforcement framework centers on the data privacy ombudsperson, who receives complaints and may refer matters to the attorney general. The attorney general may issue civil investigative demands, bring civil actions to enjoin violations, and seek damages, restitution, and disgorgement. Courts may award injunctive and declaratory relief, equitable relief, actual damages, costs, and reasonable attorney fees.
There is no private right of action. Individuals cannot sue directly for violations of their rights under the statute; they must file a complaint and rely on the ombudsperson and attorney general to act. Stanley's ACLU analysis identifies this as a significant structural weakness. Under-resourced attorneys general, he notes, may lack the motivation or capacity to pursue "novel, broad civil claims against powerful technology companies." The strength of the Duty of Loyalty and the Bill of Rights depends substantially on the attorney general's willingness to enforce them.
The legislature built in a checkpoint: the Office of the Legislative Auditor General must conduct an audit beginning January 1, 2028, with the report completed by October 31, 2028. The audit will evaluate compliance, surveillance and tracking restrictions, program effectiveness, and long-term program placement, and recommend statutory changes. Beginning January 1, 2027, the department must annually report to the Economic Development and Workforce Services Interim Committee on implementation metrics, security incidents, public comments, vendor ecosystem status (including the number of conformant digital wallets and verifier tools), and recommended statutory changes.
These mechanisms matter because the statutory text, however strong, cannot enforce itself. Whether the rights enumerated in 63A-20-101 translate into practical guarantees for Utah residents will depend on implementation quality, attorney general enforcement posture, and the audit findings that arrive in 2028.
What the statute leaves open
SB 275 is explicit and detailed about the state-to-individual relationship and about ecosystem participant obligations. It is considerably thinner on private-sector interactions.
The statute prohibits government entities from penalizing physical-ID users and requires government acceptance of SEDI credentials. But it does not restrict private businesses from demanding digital identification or conditioning service on its use. The ACLU analysis identifies this as the law's most serious gap: without explicit limits, private companies could create practical pressure to adopt digital ID even if the state itself cannot compel it. The statute requires verifiers to specify purposes for identity attribute requests, but does not meaningfully restrict what purposes qualify.
The Duty of Loyalty's vague terms ("best interests," "harm," "disproportionate risk") are another open question. These concepts are difficult to operationalize and difficult to prove in litigation, as the ACLU notes. The strength of this provision will depend largely on how courts and the attorney general interpret it when enforcement actions arise.
Transaction log defaults also raise a practical concern the statute does not resolve. Wallets must maintain secure logs that holders can export and delete. But whether holders will exercise that right depends on whether deletion is a prominent default option or a buried setting. The ACLU recommends limiting default retention to days or weeks, a decision the statute leaves to implementation rather than mandating as law.
Multistate interoperability is aspirational rather than established. Utah's "Protecting Liberty" policy document invites other states to join a SEDI Consortium, and the campaign context has attracted significant multistate interest, with more than 25 states exploring whether to adopt similar frameworks at the April 2026 SEDI Summit, and a multistate consortium coordinated through the Kantara Initiative under discussion. What mutual recognition of credentials, cross-jurisdictional enforcement, and shared governance structures would look like in practice is not specified in statute and has not yet been negotiated.
What the statute does establish, precisely
For all the nuance above, SB 275 establishes several things with specificity:
Participation is voluntary. Utah Code 63A-20-302(5) states directly: "An individual is not required to apply for or obtain a state-endorsed digital identity." This is not a policy statement; it is an enacted legal requirement that the program must maintain voluntary participation. Government entities cannot create material advantages for digital over physical identity.
The issuer cannot surveil presentations. The "no phone home" prohibition at 63A-20-301(3) is a technical architecture requirement, not a use restriction. The state must build or select systems where the surveillance mechanism is absent.
Revocation is constrained. Three circumstances only: compromise, fraudulent issuance, or holder request. The state cannot revoke someone's digital identity arbitrarily or in response to unrelated conduct.
Data handling is restricted at the source. Information provided to obtain a SEDI may only be used for issuing and managing the credential, used as the individual authorizes, retained as long as necessary for those purposes, maintained within a state-controlled data center within Utah, and disclosed to the subject or to a person with a warrant or court order. The state cannot monetize the enrollment data.
All ecosystem participants, including private wallet providers and commercial verifiers, are bound by the Duty of Loyalty and processing restrictions, not only government agencies.
Digital wallet certification under SEDI is designed to support an open ecosystem: no single vendor can monopolize wallet access, because any wallet meeting the conformance requirements can participate. The degree to which this prevents practical monopolization depends on how rigorously conformance is defined and enforced in the implementation standards the department has not yet published.
A framework under construction
Utah SB 275 is the enacted law; the infrastructure that makes it real is still being built. The first SEDI has not yet been issued. Official implementation standards have not been published. The audit that will evaluate whether the statute's privacy and surveillance protections are working in practice will not begin until 2028.
That is not a criticism of the framework. Statutory enactment precedes implementation by design. The statute establishes the rules; the department must now build systems that comply with them. Utah's earlier progress in turning digital identity principles into statutory form informed the current law's structure, and the implementation guide reflects real technical judgment about how to operationalize the statutory requirements.
For state legislators and policy leaders examining SEDI as a model, the relevant question is not whether Utah has solved digital identity but whether its statutory architecture is the right starting point. The 11 rights, the Duty of Loyalty, the "no phone home" prohibition, the open standards requirement, the voluntary participation guarantee, and the revocation constraints together represent a coherent attempt to define what trustworthy government-endorsed digital identity infrastructure requires. The gaps the ACLU identifies are real, and most of them are addressable through follow-on legislation, implementation standards, or both.
SpruceID submitted formal recommendations to Utah's SEDI Request for Information, focused on translating these statutory principles into concrete technical requirements across credential architecture, wallet interoperability, and verification systems. For an analysis of how SEDI's statutory provisions map to specific implementation decisions, see our guide to how the law's principles translate into technical requirements.
Building digital services that scale take the right foundation.
About SpruceID: SpruceID builds digital trust infrastructure for government. We help states and cities modernize identity, security, and service delivery — from digital wallets and SSO to fraud prevention and workflow optimization. Our standards-based technology and public-sector expertise ensure every project advances a more secure, interoperable, and citizen-centric digital future.