Utah 2025 Regular Session

Utah Senate Bill SB0260 Compare Versions

OldNewDifferences
1-Enrolled Copy S.B. 260
1+02-11 10:20 S.B. 260
22 1
33 Individual Digital Identity Amendments
44 2025 GENERAL SESSION
55 STATE OF UTAH
66 Chief Sponsor: Kirk A. Cullimore
7-House Sponsor: Paul A. Cutler
7+House Sponsor:
88 2
99
1010 3
1111 LONG TITLE
1212 4
1313 General Description:
1414 5
1515 This bill enacts provisions related to a state-endorsed digital identity.
1616 6
1717 Highlighted Provisions:
1818 7
1919 This bill:
2020 8
2121 ▸ defines terms;
2222 9
2323 ▸ establishes guiding principles for the implementation of a state-endorsed digital identity;
2424 10
2525 ▸ outlines state policy regarding state-endorsed digital identity;
2626 11
2727 ▸ creates requirements for a state-endorsed digital identity program; and
2828 12
2929 ▸ requires the Department of Government Operations to study and make recommendations
3030 13
3131 regarding the implementation of a state-endorsed digital identity.
3232 14
3333 Money Appropriated in this Bill:
3434 15
3535 None
3636 16
3737 Other Special Clauses:
3838 17
3939 None
4040 18
4141 Utah Code Sections Affected:
4242 19
4343 ENACTS:
4444 20
4545 63A-16-1201, Utah Code Annotated 1953
4646 21
4747 63A-16-1202, Utah Code Annotated 1953
4848 22
4949 63A-16-1203, Utah Code Annotated 1953
5050 23
5151
5252 24
5353 Be it enacted by the Legislature of the state of Utah:
5454 25
5555 Section 1. Section 63A-16-1201 is enacted to read:
5656 26
5757
5858 Part 12. State-endorsed Digital Identity
5959 27
60-63A-16-1201 . Definitions. S.B. 260 Enrolled Copy
60+63A-16-1201 . Definitions.
6161 28
6262 As used in this part:
6363 29
6464 (1) "Biometric data" means the same as that term is defined in Section 13-61-101.
6565 30
6666 (2) "Chief privacy officer" means the chief privacy officer appointed in accordance with
67+ S.B. 260 S.B. 260 02-11 10:20
6768 31
6869 Section 63A-19-302.
6970 32
7071 (3) "Digital identity" means an electronic record that an individual may use to assert the
7172 33
7273 individual's identity.
7374 34
7475 (4) "Governmental entity" means the same as that term is described in Section 63G-2-103.
7576 35
7677 (5)(a) "Guardian" means an individual or entity authorized to act on behalf of an
7778 36
7879 individual.
7980 37
8081 (b) "Guardian" includes:
8182 38
8283 (i) a representative designated by an individual;
8384 39
8485 (ii) the parent or legal guardian of an unemancipated minor; or
8586 40
8687 (iii) the legal guardian of a legally incapacitated individual.
8788 41
8889 (6)(a) "Identity" means any attribute used to identify or distinguish a specific individual.
8990 42
9091 (b) "Identity" includes an individual's:
9192 43
9293 (i) personal data;
9394 44
9495 (ii) biometric data;
9596 45
9697 (iii) physical and non-physical characteristics;
9798 46
9899 (iv) image or likeness;
99100 47
100101 (v) signature; and
101102 48
102103 (vi) any other unique physical or digital identifier related to the individual.
103104 49
104105 (7) "Individual" means the same as that term is described in Section 63G-2-103.
105106 50
106107 (8)(a) "Mobile communication device" means any wireless communication device with
107108 51
108109 Internet capability capable of displaying or providing a state-endorsed digital identity.
109110 52
110111 (b) "Mobile communication device" includes a:
111112 53
112113 (i) cellular telephone; or
113114 54
114115 (ii) wireless tablet.
115116 55
116117 (9) "Office" means the Office of Data Privacy created in Section 63A-19-301.
117118 56
118119 (10) "Person" means the same as that term is defined in Section 63G-2-103.
119120 57
120121 (11) "Personal data" means the same as that term is defined in Section 63A-19-101.
121122 58
122123 (12) "Physical identity" means a physical record that an individual may use to prove the
123124 59
124125 individual's identity issued by:
125126 60
126127 (a) a governmental entity;
127128 61
128129 (b) the equivalent of a governmental entity in another state;
129-- 2 - Enrolled Copy S.B. 260
130130 62
131131 (c) the federal government; or
132132 63
133133 (d) another country.
134134 64
135135 (13) "State-endorsed digital identity" means an individual's digital identity that:
136+- 2 - 02-11 10:20 S.B. 260
136137 65
137138 (a) is controlled by the individual; and
138139 66
139140 (b) has been officially recognized by the state.
140141 67
141142 (14) "State-endorsed digital identity program" means a state initiative which is designed to
142143 68
143144 develop methods, policies, and procedures to endorse an individual's digital identity.
144145 69
145146 (15) "System" means the technological infrastructure, processes, and procedures used to
146147 70
147148 create, store, manage, and validate a state-endorsed digital identity.
148149 71
149150 Section 2. Section 63A-16-1202 is enacted to read:
150151 72
151152 63A-16-1202 . State digital identity policy.
152153 73
153154 (1) It is the policy of Utah that:
154155 74
155156 (a) each individual has a unique identity;
156157 75
157158 (b) the state does not establish an individual's identity;
158159 76
159160 (c) the state may, in certain circumstances, recognize and endorse an individual's
160161 77
161162 identity;
162163 78
163164 (d) the state is obligated to respect an individual's privacy interest associated with the
164165 79
165166 individual's identity;
166167 80
167168 (e) the state is the only governmental entity that may endorse an individual's digital
168169 81
169170 identity for the purpose of establishing a state-endorsed digital identity;
170171 82
171172 (f) the state may only endorse an individual's digital identity if the state-endorsed digital
172173 83
173174 identity program is expressly authorized by the Legislature;
174175 84
175176 (g) an individual whose digital identity has been endorsed by the state is entitled to:
176177 85
177178 (i) choose:
178179 86
179180 (A) how the individual discloses the individual's state-endorsed digital identity;
180181 87
181182 (B) to whom the individual discloses the individual's state-endorsed digital
182183 88
183184 identity;
184185 89
185186 (C) which elements of the individual's state-endorsed digital identity to disclose;
186187 90
187188 (D) where the individual's state-endorsed digital identity is stored; and
188189 91
189190 (E) whether to use a state-endorsed digital identity or physical identity to prove
190191 92
191192 the individual's identity;
192193 93
193194 (ii) allow a governmental entity or a person to use information related to the
194195 94
195196 individual's use of the individual's state-endorsed digital identity for a purpose
196197 95
197198 other than the primary purpose for which the governmental entity or person
198-- 3 - S.B. 260 Enrolled Copy
199199 96
200200 collected the information; and
201201 97
202202 (iii) have a guardian obtain or use a state-endorsed digital identity on the individual's
203203 98
204204 behalf;
205+- 3 - S.B. 260 02-11 10:20
205206 99
206207 (h) a governmental entity or person that accepts a state-endorsed digital identity shall:
207208 100
208209 (i) collect, use, and retain an individual's state-endorsed digital identity in a secure
209210 101
210211 manner; and
211212 102
212213 (ii) comply with the requirements of this part through technological means;
213214 103
214215 (i) a governmental entity may not:
215216 104
216217 (i) convey a material benefit upon an individual for using a state-endorsed digital
217218 105
218219 identity instead of a physical identity; or
219220 106
220221 (ii) withhold services or benefits from an individual if the individual uses a physical
221222 107
222223 identity or is otherwise unable to use a state-endorsed digital identity; and
223224 108
224225 (j) a governmental entity or a person may not require an individual to surrender the
225226 109
226227 individual's mobile communication device to verify the individual's identity.
227228 110
228229 (2) The state may not endorse an individual's digital identity unless:
229230 111
230231 (a) the state has verified an individual's identity before endorsement;
231232 112
232233 (b) the state-endorsed digital identity:
233234 113
234235 (i) incorporates state-of-the-art safeguards for protecting the individual's identity;
235236 114
236237 (ii) includes methods to establish authenticity;
237238 115
238239 (iii) is easy for an individual to adopt and use; and
239240 116
240241 (iv) is compatible with a wide variety of technological systems without sacrificing
241242 117
242243 privacy or security;
243244 118
244245 (c) the state provides clear information to an individual regarding how the individual
245246 119
246247 may:
247248 120
248249 (i) maintain and control the individual's state-endorsed digital identity;
249250 121
250251 (ii) use the individual's state-endorsed digital identity;
251252 122
252253 (iii) limit access to:
253254 123
254255 (A) the individual's state-endorsed digital identity; and
255256 124
256257 (B) any elements of the individual's identity disclosed by the state-endorsed digital
257258 125
258259 identity; and
259260 126
260261 (iv) obtain a new state-endorsed digital identity if the individual's state-endorsed
261262 127
262263 digital identity is compromised;
263264 128
264265 (d) the state ensures that when an individual uses a state-endorsed digital identity:
265266 129
266267 (i) any record of the individual's use:
267-- 4 - Enrolled Copy S.B. 260
268268 130
269269 (A) is only used for the primary purpose for which the individual disclosed the
270270 131
271271 state-endorsed digital identity; and
272272 132
273273 (B) is not disclosed, shared, or compared by the governmental entity or person
274+- 4 - 02-11 10:20 S.B. 260
274275 133
275276 receiving the state-endorsed digital identity; and
276277 134
277278 (ii) the use is free from surveillance, visibility, tracking, or monitoring by any other
278279 135
279280 governmental entity or person; and
280281 136
281282 (e) the state-endorsed digital identity enables an individual to:
282283 137
283284 (i) selectively disclose elements of the individual's identity; and
284285 138
285286 (ii) verify that the individual's age satisfies an age requirement without revealing the
286287 139
287288 individual's age or date of birth.
288289 140
289290 (3) The state may only revoke or withdraw the state's endorsement of an individual's
290291 141
291292 state-endorsed digital identity if:
292293 142
293294 (a) the state-endorsed digital identity has been compromised;
294295 143
295296 (b) the state's endorsement was:
296297 144
297298 (i) issued in error; or
298299 145
299300 (ii) based on fraudulent information; or
300301 146
301302 (c) the individual requests that the state revoke or withdraw the endorsement of the
302303 147
303304 individual's state-endorsed digital identity.
304305 148
305306 Section 3. Section 63A-16-1203 is enacted to read:
306307 149
307308 63A-16-1203 . Department duties.
308309 150
309310 (1) The department shall:
310311 151
311312 (a) explore ways in which the state may implement a state-endorsed digital identity
312313 152
313314 program consistent with the state policy expressed in Section 63A-16-1202;
314315 153
315316 (b) study and identify best practices regarding the use of a digital identity;
316317 154
317318 (c) propose policies, procedures, standards, and technology that should be incorporated
318319 155
319320 in the state-endorsed digital identity program;
320321 156
321322 (d) examine how the state-endorsed digital identity program may be implemented in the
322323 157
323324 most cost-effective manner possible using state resources that are already available;
324325 158
325326 and
326327 159
327328 (e) evaluate and make recommendations regarding any changes to existing statutes,
328329 160
329330 rules, or policies that may be necessary to facilitate the creation of a state-endorsed
330331 161
331332 digital identity program.
332333 162
333334 (2) In performing the duties described in Subsection (1), the department shall consult with:
334335 163
335336 (a) the chief information officer;
336-- 5 - S.B. 260 Enrolled Copy
337337 164
338338 (b) the chief privacy officer;
339339 165
340340 (c) the Utah League of Cities and Towns;
341341 166
342342 (d) the Utah Association of Counties; and
343+- 5 - S.B. 260 02-11 10:20
343344 167
344345 (e) individuals who have relevant expertise, including representatives from:
345346 168
346347 (i) governmental entities;
347348 169
348349 (ii) other states; and
349350 170
350351 (iii) the private sector.
351352 171
352353 (3) The department shall report to the Public Utilities, Energy, and Technology Interim
353354 172
354355 Committee regarding the duties described in Subsection (1) and recommendations for
355356 173
356357 the implementation of a state-endorsed digital identity program on or before October 31
357358 174
358359 of each year.
359360 175
360361 Section 4. Effective Date.
361362 176
362363 This bill takes effect on May 7, 2025.
363364 - 6 -