Requirements for digital wallet providers.

Utah Code § 63A-20-401, under Part 63A-20-4: Digital Wallet Providers.

Utah Code § 63A-20-401

63A-20-401. Requirements for digital wallet providers.

(1) A digital wallet produced by a digital wallet provider shall: incorporate state-of-the-art safeguards for protecting an individual's identity; process an individual's identity attributes in a secure manner; comply with the requirements of this part through technological means where possible; be tamper resistant; support online and offline presentation of a state-endorsed digital identity; maintain a secure log: with sufficient information for the holder to know: what identity attributes were provided; and the verifier or relying party the identity attributes were provided to; accessible only to the holder; exportable only by the holder; and deletable only by the holder; enable a holder to: selectively disclose an individual's identity attributes; or demonstrate that the individual meets a specified minimum age without disclosing the individual's age or birth date; and allow a presentation of a state-endorsed digital identity by a digital guardian.

(2) A digital wallet provider may only process an individual's identity attributes from a state digital identity if: the processing is necessary for a presentation; the holder has received conspicuous notice of: what identity attributes are collected from the state digital identity; how the identity attributes are used; the purpose for which the identity attributes are processed; and how long the identity attributes are retained; and the holder consents to the processing of the individual's identity attributes.

(3) Information provided by a holder to a digital wallet provider for the purpose of creating or using a digital identity may only be: processed for the primary purpose for which the holder disclosed the information; and used, retained, sold, or shared: as expressly authorized by the holder; or if required by law.

(4) Nothing in this section relieves a digital wallet provider from complying with the requirements of Title 13, Chapter 44, Protection of Personal Information Act, or Title 13, Chapter 61, Utah Consumer Privacy Act.