{
  "node_id": "au-digital-id-act-2024-agdis-trust-framework",
  "title": "Australia Digital ID Act 2024 (Cth) and Australian Government Digital ID System Trust Framework",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2024-06-21",
  "bluf": "The Digital ID Act 2024 (Cth) is Australia's primary digital identity statute, replacing the prior administrative Trusted Digital Identity Framework (TDIF) with a binding legislative regime. The Act establishes the Australian Government Digital ID System (AGDIS) under the oversight of the Digital ID Regulator and applies a four-pillar trust framework covering accreditation of identity service providers, privacy safeguards, system governance, and enforcement. Accreditation is governed by Chapter 2 (Sections 13 to 31) and is required for entities seeking to operate as an Identity Service Provider, Credential Service Provider, Identity Exchange, or Attribute Service Provider within the AGDIS. Use of a digital ID by individuals is voluntary under Section 74, and the Crown is bound by the Act under Section 5.\n\nThe AGDIS framework is established by Chapter 4 (Sections 57 to 88) and requires the Digital ID Regulator under Section 58 to oversee and maintain the system. Privacy protections in Chapter 3 (Sections 32 to 56) include restrictions on biometric information handling, prohibitions on profiling using digital identity attributes, and specific consent requirements for restricted attributes such as biometric and health data. Enforcement is set out in Chapter 9, including civil penalty provisions, injunctions, and infringement notices. The Act commenced in phased tranches in 2024 to 2025 with full AGDIS operational scope expanding to private-sector relying parties under a staged onboarding model.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "us-nist-sp-800-63-4-2025-digital-identity-guidelines",
    "au-privacy-act-1988",
    "w3c-verifiable-credentials-data-model-2-0"
  ],
  "primary_citations_count": 7
}