Very rough translation (Japanese only) = for the bilingual version, go to https://github.com/sakimura/translations/blob/main/OECD-LEGAL-0491.md
THE COUNCIL,
Having regard to the Convention on the Organisation for Economic Co-operation and Development of December 14, 1960, Article 5 b), HAVING REGARD;
HAVING REGARD to the standards developed by the OECD in the areas of electronic authentication; regulatory policy and governance; agile regulatory governance; international regulatory co-operation; privacy protection and transborder flows of personal data; cross-border co-operation in the enforcement of laws protecting privacy; digital government strategies; cryptography policy; Internet policy making; digital security; children in the digital environment; and open government;
HAVING REGARD to technical standards developed by the European Committee for Standardization (CEN), the European Telecommunications Standards Institute (ETSI), the International Organization for Standardization (ISO), the International Electrotechnical Commission (IEC), the United States National Institute of Standards and Technology (NIST), the World Wide Web Consortium (W3C), and other bodies such as the European Commission, the Financial Action Task Force (FATF), the United Nations Commission on International Trade Law (UNCITRAL), and the World Bank;
RECOGNISING that effective, easy-to-use, secure and trusted digital identity systems can enhance privacy, promote inclusion, and simplify access to a wide range of services, thereby contributing to social and economic value;
RECOGNISING that digital identity can transform how service providers operate and interact with users, both in person and online, by offering an alternative to physical credentials as part of a seamless omnichannel experience;
RECOGNISING that the governance, design and implementation of digital identity systems must be rooted in respect for democratic values and human rights;
RECOGNISING the need to ensure that digital identity solutions are accessible, affordable, usable and equitable for all, and the importance of continuously advancing the inclusion of vulnerable groups and minorities;
RECOGNISING that a rapidly evolving technological environment creates a need for governments to regularly review and assess the opportunities and risks presented by new technologies and architectural paradigms, including cost-benefit analyses and assessments of environmental, privacy, data protection, ethical and human-rights impacts, complemented by open and transparent processes to mitigate harm from potential unintended consequences:
RECOGNISING that the introduction of digital identity systems may create risks, including fraud, identity theft, cybercrime, and potential threats to human rights, privacy and data protection;
RECOGNISING that both the public and private sectors contribute to the success of digital identity systems, and that their respective roles and relative contributions to the digital identity ecosystem may vary across countries;
RECOGNISING that trust among the different actors in the digital identity ecosystem is essential to the proper functioning of digital identity and should be supported by appropriate domestic policies and solutions underpinned by relevant technical standards and technologies;
RECOGNISING that stakeholder engagement and consultation are essential to building public trust in digital identity systems as a whole;
RECOGNISING that Members and non-Members adhering to this Recommendation (hereafter, “Adherents”) have different approaches to developing and refining digital identity systems, reflecting different roles and contributions from the public and private sectors; different underlying identity-management systems (centralised, federated and decentralised); links to civil-registration systems; existing infrastructure; digital maturity; existing adoption of digital identity; trust among actors in the digital identity ecosystem; and public debate concerning the role and nature of digital identity;
RECOGNISING that the varying approaches taken by Adherents create a need for secure and trusted interoperability of digital identity systems across borders, which calls for international co-operation and the development, adoption, alignment or accommodation of the use of technical standards so that all users can consistently access the services they need;
RECOGNISING the value of trust services, such as electronic signatures, electronic timestamps and electronic seals, in supporting the usability of digital identity solutions across borders based on technical standards and regulatory frameworks, including international agreements;
RECOGNISING that while the principles relating to the governance of digital identity for natural and legal persons should be the same, use cases, user experiences, challenges and implementation mechanisms differ, including those relating to privacy and other potential issues;
RECOGNISING the need for international development co-operation to support the governance and financing of digital identity systems in low- and middle-income countries;
CONSIDERING that the governance of digital identity is a shared responsibility across branches and levels of government, and that this Recommendation is therefore relevant to all of them in accordance with their respective national and institutional frameworks, some of which also provide for private-sector responsibilities,
On the proposal of the Public Governance Committee:
I. AGREES that the following definitions are used for the purposes of this Recommendation:
- An attribute is a verified characteristic, quality or feature assigned to a user, such as biometric information, name, date of birth, place of birth, or a unique identifier (including a personal identity number, social security number, company registration number, or address as information in electronic form);
- Authentication means a function for establishing the validity and assurance of the identity claimed by a user, device or other entity in an information and communications system.
- A credential (such as a driving licence, identity card, permit or qualification) is a set of 1 or more electronically recorded and verifiable assertions concerning a user, created by a credential issuer. Some Adherents may refer to or understand the terms attribute and credential interchangeably depending on context;
- A credential issuer means any public or private entity that issues credentials to users;
- A digital identity is a set of electronically captured and stored attributes and/or credentials that can be used to prove characteristics, qualities, features or claims about a user and, where required, support the unique identification of that user;
- The digital identity ecosystem comprises the various actors involved in digital identity systems, including policy makers, regulators, government oversight bodies, technical standard-setting bodies, digital identity solution providers, credential issuers, service providers, civil society organisations and users.
- The digital identity lifecycle means the sequence of stages and processes involved in managing a digital identity from creation to termination, including identity proofing; enrolment or registration; issuance; use; potential loss or theft; expiration or revocation; and maintenance or recovery;
- A digital identity solution is a tangible and/or intangible unit that enables a user to store, retrieve and share attributes and/or credentials and is used for authentication to online or offline services;
- A digital identity solution provider means any public or private entity that issues digital identity solutions to users;
- A digital identity system means the system as a whole in which digital identity solutions, credentials and attributes are provided to users and relied upon by service providers, including policies, regulatory frameworks, trust frameworks, technical standards, and roles and responsibilities;
- A level of assurance (LoA) means the degree of confidence a service provider can have in a user’s claimed identity, determined by the practices adopted by a digital identity solution provider when issuing a given digital identity solution;
- A service provider means any public or private entity that relies on secure and trusted digital identity solutions for user authentication and verification of attributes or credentials in order to provide a service, whether online or offline;
- A trust framework is a common set of requirements for digital identity solutions, including cybersecurity requirements, followed by digital identity solution providers to foster trust within the digital identity ecosystem. Requirements may be divided into different levels of assurance (LoA).
- A user means a natural or legal person, or a natural person representing a natural or legal person. In a cross-border scenario, a user should be understood as a natural or legal person from another jurisdiction.
Developing User-Centred and Inclusive Digital Identity
II. RECOMMENDS that Adherents design and implement digital identity systems that respond to the needs of users and service providers. To this end, Adherents should:
- Take account of the domestic context, including digital maturity and existing digital identity developments, when considering the design, implementation or iteration of digital identity systems;
- Use service-design methods to ensure that digital identity systems meet user needs and achieve accessible, ethical and equitable outcomes, in particular by:
a) identifying the needs of users, service providers and other affected parties;
b) considering the end-to-end user experience across the digital identity lifecycle;
c) measuring operational performance in order to improve digital identity systems and solutions as appropriate. - Encourage the development of digital identity solutions that are portable for users across:
a) location: including in person, remotely, at all levels of government, and across borders;
b) technology: available through the most convenient device, mobile form factor or communications medium and unconstrained by the speed or quality of Internet connectivity;
c) sectors: enabling access not only to public services but also, as appropriate, to the wider economy. - Encourage the development of privacy-preserving and consent-based digital identity solutions that give users greater ownership of their attributes and credentials and enable them to control more easily and securely which attributes and credentials they share, when, and with whom.
III. RECOMMENDS that Adherents prioritise inclusion and minimise barriers to access to and use of digital identity. To this end, Adherents should:
- Improve access throughout the digital identity lifecycle in response to the needs of users, including vulnerable groups and minorities, to promote accessibility, affordability, usability and equity, and increase access to secure and trusted digital identity solutions.
- Take measures to ensure that natural persons who do not wish to access or use a digital identity solution are not restricted in accessing essential services, including in the public and private sectors.
- Foster inclusive and collaborative stakeholder engagement in the design, development and implementation of digital identity systems to ensure transparency, accountability, and alignment with users’ needs and expectations.
- Raise awareness of the benefits and safe use of digital identity and of how digital identity systems protect users, while making risks clear and identifying means of mitigating potential harm.
- Provide support through appropriate means to users who face challenges in accessing or using digital identity solutions, and identify opportunities to improve users’ skills and capabilities.
- Monitor and evaluate the effectiveness of digital identity systems, and publicly report on their effectiveness in prioritising inclusion and minimising barriers to access to and use of digital identity.
Strengthening the Governance of Digital Identity
IV. RECOMMENDS that Adherents take a strategic approach to digital identity and define roles and responsibilities throughout the digital identity ecosystem. To this end, Adherents should:
- Present, through a dedicated strategy or as part of a broader strategy, a long-term vision for realising the benefits and mitigating the risks of digital identity in the public sector and the wider economy;
- Ensure national strategic leadership and oversight of implementation, and define and communicate domestic roles and responsibilities within the digital identity ecosystem;
- Facilitate co-operation and co-ordination among government bodies and competent authorities at all levels of government, where necessary and applicable;
- Take measures to ensure that government bodies and competent authorities at all levels of government, and other relevant actors where applicable, are responsible for managing, monitoring and protecting the digital identity ecosystem, including protecting users’ rights and prioritising inclusion;
- Foster co-operation between the public and private sectors and support the development of a healthy market for digital identity solutions that encourages innovation and competition and explores the potential value of alternative models and technologies;
- Establish a national or regional trust framework, or align with a relevant regional trust framework where applicable, to set common requirements, including cybersecurity requirements, for digital identity solution providers to foster trust within the digital identity ecosystem;
- Establish clear responsibility for the regulation and oversight of digital identity systems so that the rights of users and affected parties are protected and appropriate and effective mechanisms for dispute resolution, redress and recovery are in place;
- Promote sustainable and resilient digital identity systems by considering the environmental impact of technology choices and the need for continuing investment that reflects the costs borne by all relevant actors throughout the digital identity lifecycle;
- Oversee digital identity systems to respond to emerging needs, threats, risks and opportunities.
V. RECOMMENDS that Adherents protect privacy and prioritise security to ensure trust in digital identity systems. To this end, Adherents should:
- Recognise that security is foundational to the design of trusted digital identity systems, and ensure that digital identity solution providers and solutions comply with all relevant requirements in a manner consistent with defined levels of assurance (LoA) and/or a risk-based approach, to protect users, service providers and society, particularly from identity theft and alteration.
- Treat user control, privacy and data protection as fundamental principles of digital identity systems and promote privacy-by-design and privacy-by-default approaches. This includes informed consent, integrity, confidentiality, selective disclosure, purpose specification, and limitations on the collection and use of personal data. It also includes considering the need for specific standards and mechanisms aimed at protecting against misuse of particular categories of personal data, especially biometric data.
- Prevent users from leaving unnecessary trails of personal data when accessing different services using digital identity solutions, and prevent the aggregation of datasets across services.
- Enforce accountability obligations under existing data-protection and privacy laws.
- Implement robust measures to ensure that any attributes and credentials shared through digital identity solutions are accurate, complete, up to date and relevant.
- Identify specific needs concerning how to safely accommodate and protect children, vulnerable groups and minorities in the design and use of digital identity systems.
- Where deemed necessary, consider measures to establish legally recognised mechanisms for users to nominate another person or delegate authority to represent them. These mechanisms must be visible, manageable and traceable by users.
- Promote the use of open standards and open-source software in the design of digital identity systems and other relevant activities to mitigate risks associated with users, service providers and society relying on a single hardware or software vendor.
VI. RECOMMENDS that Adherents align their legal and regulatory frameworks and provide resources to enable interoperability. To this end, Adherents should:
- Ensure, as necessary, that domestic policies, laws, rules and guidance concerning digital identity systems cover issues such as governance, liability, privacy, resilience and security in order to promote and facilitate interoperability and portability across locations, technologies and sectors.
- Ensure technological and vendor neutrality, provided digital identity solutions meet all relevant security requirements, and promote the use of internationally recognised technical standards and certifications.
- Provide access to a catalogue of resources to support service providers in onboarding to digital identity systems, such as common technical components, documentation or appropriate technical support.
- Support the creation of mechanisms such as regulatory sandboxes that provide safe and controlled environments for exploring the risks and opportunities of emerging technologies and updates to digital identity systems that may affect interoperability.
- Monitor and report, as necessary, on compliance throughout the digital identity ecosystem with existing domestic rules and internationally recognised technical standards.
Enabling Cross-Border Use of Digital Identity
VII. RECOMMENDS that Adherents identify the evolving needs of users and service providers in different cross-border scenarios. To this end, Adherents should:
- Identify priority use cases for cross-border interoperability of digital identity systems based on users’ experiences and contexts, by identifying activities that require the sharing of attributes and/or credentials across different jurisdictions.
- Co-operate internationally to identify the needs of service providers in other jurisdictions for recognising, integrating and trusting digital identity solutions.
- Identify risks associated with cross-border interoperability of digital identity systems and related use cases, and adopt mitigation measures as necessary.
VIII. RECOMMENDS that Adherents co-operate internationally to establish a basis of trust in other countries’ digital identity systems and issued digital identities. To this end, Adherents should:
- Designate a domestic contact point to engage, as appropriate and applicable, with international counterparts and activities supporting cross-border digital identity.
- Engage in international regulatory co-operation to enable cross-border interoperability of digital identity systems, including by assessing and/or mapping the alignment, compatibility and equivalence of existing legal requirements, trust frameworks and technical standards; exploring co-operation through free trade agreements; and identifying opportunities for cross-border regulatory experimentation.
- Engage in bilateral and multilateral co-operation with relevant stakeholders throughout the digital identity ecosystem by participating in work on international technical standards, exchanging experiences and best practices, and aligning innovation programmes.
- Ensure that cross-border interoperability of digital identity does not cause foreign users to be unfairly discriminated against when accessing essential services or commercial transactions.
- Work to clarify standards of liability associated with the use of digital identity in cross-border transactions.
- For cross-border public services, where appropriate, enable specified public-sector identity attributes stored abroad to be checked against attributes or information shared about a user through a digital authentication process, ensuring that the identity and digital identity of the user seeking access to the service correspond.
- Create a roadmap outlining the steps necessary to enable:
- a) digital identity solutions recognised domestically, and associated attributes and credentials, to be used internationally;
- b) digital identity solutions recognised abroad, and associated attributes and credentials, to be used domestically.
IX. CALLS ON all stakeholders in the digital identity ecosystem to implement this Recommendation or, as appropriate to their roles, support and promote its implementation.
X. INVITES the Secretary-General to disseminate this Recommendation.
XI. INVITES Adherents to disseminate this Recommendation at all levels of government.
XII. INVITES non-Adherents to take due account of and adhere to this Recommendation.
XIII. INSTRUCTS the Public Governance Committee to:
a) serve as a forum for exchanging information on the implementation of this Recommendation and foster multistakeholder dialogue concerning user-centred and inclusive digital identity systems, the governance of digital identity systems, and the cross-border use of digital identity to access public- and private-sector services;
b) monitor activities and emerging trends in digital identity that may affect implementation of this Recommendation through the collection and analysis of relevant data and dissemination of findings to relevant bodies;
c) develop processes, guidance and tools to support implementation of this Recommendation; and
d) report to the Council on the implementation, dissemination and continued relevance of this Recommendation no later than 5 years following its adoption and at least every 10 years thereafter.
Background Information
The Recommendation on the Governance of Digital Identity was adopted by the OECD Council at Ministerial level on June 8, 2023, based on a proposal by the Public Governance Committee (PGC). The Recommendation aims to guide Adherents in successfully establishing user-centred, trusted and well-governed domestic approaches, and to create the conditions for full international interoperability of digital identity across geographies, technologies and sectors.
The Need for a Standard on Digital Identity
Identity verification is essential to the functioning and resilience of social, economic and political systems. Physical documents such as identity cards and passports have enabled individuals to access essential services and cross borders, but they are insufficient to meet the opportunities and challenges of the digital age. To ensure the long-term sustainability of digital identity, governments must establish robust foundations for governance and treat digital identity as essential digital public infrastructure.
Governments are working to ensure trusted access to digital identities for natural and legal persons that are portable across platforms, sectors and borders. However, challenges to domestic and international implementation remain, including public awareness, user experience and adoption, digital inclusion, data sharing, interoperability, liability, data privacy and security. These challenges are shaped by technology and grounded in fundamental issues of governance, including strategy, public-private collaboration, regulation and international co-operation. Creating trusted and robust digital identity systems requires a strategic and systematic approach that considers the emergence and management of new models and technologies. Achieving this requires balancing different objectives according to the domestic context. It calls for governance frameworks that are flexible, adaptable and promote cross-border interoperability.
The Recommendation builds on the work of the Working Party of Senior Digital Government Officials (the E-Leaders Working Party under the PGC) and complements efforts by the OECD Committee on Digital Economy Policy and other international organisations and forums. It provides a standard for the governance of digital identity aligned with OECD values, enabling accessible, user-friendly, highly trusted, secure and equitable approaches that simplify and accelerate interactions, enable more proactive and personalised services, and reduce opportunities for error, fraud and other misconduct.
Scope of the Recommendation
The Recommendation is structured around 3 pillars.
- The first pillar stresses the importance of developing user-centred and inclusive digital identity systems. This includes designing and implementing digital identity systems that are effective, easy to use and responsive to the needs of users and service providers. The pillar also emphasises the need for digital identity systems to prioritise inclusion and minimise barriers to access while maintaining non-digital means of proving identity.
- The 2 pillar focuses on strengthening the governance of digital identity. This requires taking a strategic approach to digital identity and defining roles and responsibilities throughout the digital identity ecosystem. It is also important to protect privacy, give security a high priority, and ensure trust in digital identity systems. The pillar further focuses on aligning legal and regulatory frameworks and providing resources to enable interoperability among different systems and services.
- The third pillar is dedicated to the cross-border use of digital identity. It requires identifying the evolving needs of users and service providers in different cross-border scenarios and co-operating internationally to establish a basis of trust in other jurisdictions’ digital identity systems and issued identities. Achieving portability of digital identity across jurisdictions is complex, but international co-operation and the development of international instruments can set expectations, build consensus and foster trust.
Overall, the Recommendation provides a framework to promote the development of trusted access to digital identities for natural and legal persons that are portable across platforms, sectors and borders. To realise this ambition, it addresses challenges at the domestic and international levels: public awareness, user experience and adoption, data sharing, interoperability, liability, data privacy and security, governance, and international co-operation. The Recommendation does not focus on technical aspects, nor does it imply changes to the nature of domestic identity systems.
Next Steps
Through the E-Leaders Working Party, the PGC will serve as a forum for information exchange and multistakeholder dialogue on user-centred and inclusive digital identity systems, governance, and cross-border use. Discussions are intended to support peer learning among Adherents and disseminate good implementation practices.
The PGC will monitor activities and emerging trends in digital identity, provide guidance and tools to support implementation, and report an evaluation of the Recommendation’s implementation, dissemination and continued relevance in 2028.
For further information, see: https://www.oecd.org/gov/digital-government/。連絡先情報:eleaders@oecd.org。
