As digital technology evolves, our dependence on personal information and data continues to grow. Yet many government-provided ID systems do not always give sufficient consideration to user privacy and freedom. Against this background, Utah’s “SB2601 has attracted attention for taking a different approach and fundamentally strengthening both privacy protection and users’ autonomy over data management (Chang (2025), among others). This article examines its characteristics and how it differs from other digital ID systems.


Unique Features of SB260

SB260 differs greatly from other government-provided ID systems in the following respects.

Respect for Individual Autonomy
SB260 explicitly provides that “the state does not define an individual’s identity” (§ 63A-16-1202). It further provides that “the state may, in certain circumstances, recognize and authenticate an individual’s identity.” Under many conventional government ID systems, the government has the authority to define and recognize an individual’s identity, and the individual’s existence depends on government recognition. SB260’s new approach is fundamentally different. SB260 recognizes that human beings already exist in their own right, with the state acting as a facilitator that helps them be recognized and manage state authentication in the manner prescribed by law. SB260 emphasizes individual autonomy. Under the former approach, a person’s existence can be denied through a lack of government recognition; under the latter, that cannot occur.

Prohibition of Surveillance and Data Sharing
SB260 strictly prohibits surveillance and information sharing by government agencies and other parties when a digital ID is presented. For example, a business to which ID information is presented may not use it for marketing or surveillance. These rules prevent unnecessary sharing of user data and promote transparency in data management.

Selective Disclosure of Information
Many physical identity documents disclose all information, such as address and age, but SB260 calls for technology that enables “selective disclosure.” Even when age verification is required, for example, there is no need to share the actual date of birth or address. This prevents unnecessary disclosure of personal information.

No Compelled Surrender of a Device
SB260 provides that a person cannot be compelled to surrender a mobile device during digital identity verification. This eliminates the possibility that law enforcement or other government personnel could demand access to the device and ensures protection of the personal data it contains. This is quite different from a system in which the verifier takes possession of the device and can do this and that with it.

Use of Digital Identity Is Entirely Voluntary
Unlike other identity systems, SB260 emphasizes that use of digital identity is entirely voluntary. Government agencies may not compel its use or offer incentives to encourage its use. This accommodates residents who are unfamiliar with technology or do not wish to use digital tools.2


Comparison with Other ID Systems: What Is Different?

Surveillance and data collection are concerns with many government-provided IDs. Some systems may use personal information for marketing or data analysis, but SB260 expressly prohibits this. Other systems may also make digital ID mandatory, leaving users no choice. SB260, by contrast, is entirely voluntary and stands out for its user-centric design.

As a result, SB260 is attracting attention as a forward-looking digital ID system that prioritizes privacy and gives users full control over their data. This user-driven approach may influence digital ID development not only throughout the United States but around the world.


Conclusion: A New Reference Point

for the Digital Age

Utah’s SB260 can be regarded as an important milestone shaping the future of digital ID. By comprehensively guaranteeing user autonomy, privacy protection, and freedom of choice, it sets itself apart from other government-provided ID systems.

As for the quality of the document itself, there are various points that concern me from a standards perspective, such as defining Identity as “Identity means any attribute used to identify or distinguish a specific individual,” and stating that “(a)each individual has a unique identity;”. Nevertheless, SB260 not only sets new standards for individual freedom and data management; it may also become widely recognized as a model in which technology and law work in harmony to realize a user-oriented world, influencing the development of secure and safe ID systems for the digital age in jurisdictions that institutionalize digital ID in the future. It will be fascinating to see how the U.S. states respond.

(References)

Footnotes

  1. Effective May 7, 2025
  2. That said, I personally prefer an approach like Denmark’s, in which support is provided through “digital scribes.”