63A-20-301. State-endorsed digital identity requirements.
(1) A state-endorsed digital identity shall: incorporate state-of-the-art safeguards for protecting an individual's identity, including compromise detection, recovery mechanisms, and cross-context correlation protections; include methods to establish authenticity and integrity; be compatible with a wide variety of technological systems while maintaining strong privacy and security; support online and offline presentation; enable a holder to: selectively disclose an individual's identity attributes; or demonstrate that the individual meets a specified minimum age without disclosing the individual's age or birth date; allow a holder to choose a digital wallet that conforms with the requirements established by the department; and be easy for a holder to adopt and use.
(2) The department shall: validate verification of an individual's identity provided by an identity proofing entity; comply with the requirements of this chapter through technological means where possible; ensure any technical infrastructure used to control the issuance or revocation of a state-endorsed digital identity is maintained within a state-controlled data center located within the state; ensure that a state-controlled data center located within the state shall use best practices in collection, processing, storage, and disclosure of all individual identity and identity attributes; select open technological standards for the creation, issuance, use, and acceptance of a state-endorsed digital identity that are: publicly available; and free from: licensing fees; and patent restrictions; verify and endorse a specific set of identity attributes including an individual's: name; birth date; image; and Utah residence address; and create a process for: a holder to: obtain, maintain, and control an individual's state-endorsed digital identity; use an individual's state-endorsed digital identity; limit access to an individual's state-endorsed digital identity and identity attributes; obtain a new state-endorsed digital identity if the individual's state-endorsed digital identity is compromised; and migrate a state-endorsed digital identity to another digital wallet compliant with this chapter; a holder to request that an individual's identity attributes be amended or corrected; and appointment of a digital guardian to obtain or use a state-endorsed digital identity on an individual's behalf.
(3) A state-endorsed digital identity may not include a mechanism that allows the department to monitor, surveil, or track the presentation of a state-endorsed digital identity to another entity.
(4) Information provided by an individual to the state to obtain a state-endorsed digital identity may only be: used for the purpose of issuing and managing a state-endorsed digital identity; used as authorized by the individual; retained as long as necessary to issue and manage a state-endorsed digital identity; maintained within a state-controlled data center located within the state; or disclosed to: the subject of the record or the subject's digital guardian; or a person with a warrant or court order.
(5) The department may only revoke an individual's state-endorsed digital identity if: the state-endorsed digital identity has been compromised; the department's endorsement was: issued in error; or based on fraudulent information; or the holder requests that the department revoke the individual's state-endorsed digital identity.
(6) The department shall report a data breach regarding individual identity or identity attributes in accordance with Section. 63A-19-405