63A-20-303. Identity proofing.
(1) The department shall establish and maintain identity proofing requirements for the issuance of a state-endorsed digital identity that: follow a generally accepted identity proofing standard; are commensurate with the risks of impersonation, fraud, and misuse associated with the credential; and are consistent with the privacy, civil liberties, and security requirements of this chapter. The identity proofing process shall be designed to establish, at a minimum, that: the applicant is a real individual; the applicant is the individual the applicant claims to be; the applicant's birth date is the date the applicant claims it to be; and the applicant meets the eligibility requirements of Section. 63A-20-302 The department shall ensure that the identity proofing process results in a credential that provides a level of confidence in the individual's identity that is: sufficiently robust to support reliance by governmental entities and private-sector relying parties where required by law or policy for online age assurance; and appropriate for use in both online and offline presentations. Identity proofing processes shall be designed so that the state's endorsement: reflects verification at a point in time; and does not require: continuous monitoring; or tracking.
(2) An applicant shall provide true and accurate information as required under this part. Knowingly providing materially false information for the purpose of obtaining a state-endorsed digital identity constitutes fraud and may result in denial, revocation, and other remedies provided by law.
(3) Obtaining or holding a state-endorsed digital identity does not affect an individual's physical identity documents. An individual is not required to surrender, cancel, or replace any physical identity document as a condition of applying for or holding a state-endorsed digital identity.
(4) The department shall define by rule, in accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act, the identity proofing standards and processes required for issuance of a state-endorsed digital identity. The rules shall, at a minimum: specify the objectives the identity proofing process is intended to achieve; describe the acceptable methods of identity proofing, including: in-person, remote, or hybrid methods, and the conditions under which each may be used; and minimum evidence requirements and validation methods; align with generally accepted identity proofing practices; and establish requirements and a process to become an identity proofing entity.