States have been exploring digital identity through a range of approaches: mobile driver's license pilots, benefits verification modernization, workforce credential programs, digital wallet apps, and agency login portals. Each represents a different entry point into the same underlying question: can the state give residents a secure, convenient way to prove who they are? That question has been a reasonable starting point regardless of which approach a state took first.
But the question is changing. As those early programs mature and as the political and commercial stakes around digital identity grow, state leaders are increasingly facing a harder set of choices: not just whether to issue a digital credential, but what rules should govern the entire ecosystem around it. Who controls the wallet? What data can verifiers collect and keep? Can the state track where and when residents present their credentials? What happens when a vendor exits the market? What protections apply when a private company demands digital identification as a condition of service?
Utah's State-Endorsed Digital Identity (SEDI) framework, enacted through SB 275 in the 2026 General Session, represents one answer to those harder questions.
The credential is not the hard problem
States have become reasonably good at issuing digital credentials. ISO/IEC 18013-5-compliant mobile driver's licenses are available in a significant number of states. Universities and workforce agencies are exploring W3C Verifiable Credentials for diplomas, professional licenses, and employment records. TSA accepts mDLs at a growing list of checkpoints. The technical baseline for issuing cryptographically verifiable digital credentials, across multiple formats and use cases, now exists.
But issuing a credential is only one layer of a digital identity system. A credential needs a wallet to live in, verifiers to accept it, protocols that govern what information is requested and how long data is retained, and some account of what residents are entitled to when the ecosystem works against them.
Verifiable digital credentials can be cryptographically strong while still sitting inside an ecosystem that collects far more data than any individual transaction requires, routes that data to third parties, makes wallet choice practically impossible, and allows the issuing government to monitor every presentation. The credential format does not determine the ecosystem rules. That requires separate, deliberate governance.
This is the distinction SEDI is organized around. As digital identity becomes policy infrastructure, the governance layer matters as much as the technical layer. Credential quality and ecosystem quality are different things.
The policy choices every state will face
Utah's specific provisions illustrate the range of decisions any state building a digital identity program will eventually need to make, whether explicitly or by default.
Surveillance architecture. Utah's statute contains an explicit "no phone home" prohibition at 63A-20-301(3): the issuing government cannot be silently notified each time a resident presents their credential. Many digital credential architectures require checking back with the issuer for revocation status; Utah's law prohibits that design pattern. States that do not address this question explicitly tend to default to issuer-side architectures that centralize visibility, producing a system where the state accumulates a record of where residents present their identity.
Wallet choice and vendor concentration. If a state issues a digital credential that only works in one wallet application, residents have no meaningful choice of provider, and the wallet developer acquires significant leverage over both the state and its residents. Utah's framework requires open standards and prohibits architectures that allow any single wallet provider to control the ecosystem. The ACLU's analysis specifically praised this provision, noting that it prevents Apple, Google, and Samsung from monopolizing digital wallet control.
Selective disclosure. Selective disclosure allows a resident to prove a specific fact from their credential (that they are over 21, for example) without revealing their name, date of birth, or address. Utah's statute enshrines this as a right under 63A-20-101(8). Making it real requires credential formats and wallet software that implement attribute-level disclosure, and verifier protocols that ask only for what is needed. The right exists in statute, but delivering it requires engineering choices made early in implementation.
Data processing restrictions. What can a verifier or wallet provider do with identity data after a transaction is complete? Utah's statute requires that records may only be processed for the primary purpose of the presentation, and that information may only be used, retained, sold, or shared following conspicuous notice to and express authorization by the holder (63A-20-702). Without explicit processing restrictions, identity infrastructure can become data collection infrastructure. What it means for a system to be resident-centric turns significantly on this question.
Voluntary participation. Utah's statute explicitly preserves the right to physical identity (63A-20-101(3)) and prohibits government entities from penalizing residents who use physical rather than digital identification (63A-20-304). States that issue digital credentials without addressing this question often find that physical alternatives quietly become second-class options as digital workflows get prioritized.
The Duty of Loyalty: a new governance concept
One provision of SEDI is conceptually novel enough to warrant attention from any state considering its own framework: the Duty of Loyalty, codified at 63A-20-701.
Rather than relying on notice and consent, the Duty of Loyalty creates affirmative obligations: all ecosystem participants must refrain from practices that conflict with an individual's best interests, take advantage of an individual, result in disproportionate risk, cause detriment, or cause harm. These obligations apply regardless of what disclosures were made or what consent was obtained. The concept draws directly from academic work by Neil M. Richards and Woodrow Hartzog, who proposed that data collectors bound by a duty of loyalty should be obligated to act in the best interests of the people who trust them with their data.
The ACLU describes it as the law's "most striking feature," noting that if enforced it could offer broad privacy protection beyond anything achievable through notice-and-consent frameworks. They also flag the limitation: enforcement depends on the attorney general's willingness to pursue cases, and key terms will be difficult to establish in litigation. These are legitimate concerns that SEDI's implementation will need to answer. But the framework establishes a standard that places user interests structurally above operator interests, which is a different starting point than most privacy regimes.
What remains unsettled
Utah's SEDI framework addresses a broader set of ecosystem questions than any comparable legislation. But significant questions remain open. The statute's private-sector protections are its most notable gap: government entities are constrained, but private companies face no comparable restrictions on demanding digital identification. Multistate interoperability remains early-stage, with the Kantara Initiative named as the organizational home for a multistate SEDI consortium and more than 25 states participating in discussions, but mutual recognition and cross-jurisdictional enforcement are still being developed. And the implementation timeline for Utah's own program depends on progress that is ongoing: the Implementation Guide is a working draft, official standards have not been published, and no SEDI credentials have yet been issued.
What SEDI asks of states
For state CIOs, governors' offices, and digital service leaders, the practical question is what the SEDI model implies for their own programs.
The most durable lesson from Utah's approach is the structural commitment to separating ecosystem governance from the technology stack. The law establishes rights first, then derives technical requirements from those rights. A state that starts from a technology procurement decision and works backward to governance is building on a less stable foundation, because the vendor's design choices become the de facto governance framework.
Digital ID programs can stall for many reasons, but programs that centralize control in a single vendor or create architectures that residents perceive as surveillance tend to face the most durable resistance. Utah's statute is an attempt to address both risks through enforceable rights rather than vendor promises.
The open standards requirement (63A-20-301(2)(e)) is a specific and meaningful commitment to preventing lock-in. Open standards alone do not guarantee interoperability, but they create the preconditions for a competitive ecosystem. A state that procures a proprietary credential format has foreclosed those options in ways that are expensive to reverse.
The questions SEDI is trying to answer are not uniquely Utah questions. Any state expanding digital identity infrastructure will face choices about surveillance architecture, wallet competition, selective disclosure, data processing restrictions, and the practical viability of nondigital alternatives. States that address those questions explicitly and early are building more durable programs than those that defer them.
About SpruceID: SpruceID builds digital trust infrastructure for government. We help states and cities modernize identity, security, and service delivery — from digital wallets and SSO to fraud prevention and workflow optimization. Our standards-based technology and public-sector expertise ensure every project advances a more secure, interoperable, and citizen-centric digital future.