1. What the Act actually establishes
  2. Who holds your data
  3. The privacy safeguards in the Act
  4. Does it stop data breaches?
  5. Where the gaps remain
  6. What to do before you sign up to a digital ID
  7. The safeguard you should not rely on

Australia now has a national digital ID system. The Digital ID Act 2024 (Cth) (the Act) received royal assent on 30 May 2024 and the Australian Government Digital ID System went live for consumers in late 2024, when the first accreditation and participation rules took effect (Digital ID Rules 2024, Digital ID (Accreditation) Rules 2024). If you have used myGov or a government service online recently, you may already have been offered a digital ID without thinking much about what sits behind it.

That is exactly the moment it is worth pausing. The system holds identity information about millions of Australians, it is operated partly by private companies, and it was sold largely on the promise that it will make fraud harder after the Optus and Medibank breaches. This article sets out what the Act actually does with your information, what safeguards it contains, and where the real risks still sit.

What the Act actually establishes

The Act does three main things. First, it creates an accreditation scheme for businesses that provide digital ID services, such as verifying your identity or holding identity credentials. Second, it establishes the Australian Government Digital ID System, which lets accredited providers and approved government and business "relying parties" connect to a common way of verifying who you are. Third, it sets up a regulator with enforcement powers.

The regulator is the Australian Competition and Consumer Commission (ACCC), which acts as the Digital ID Regulator under s 90 of the Act. The Information Commissioner (the OAIC) has a separate oversight role for privacy compliance. That split matters: the ACCC polices the scheme, while the OAIC handles complaints about how your personal information is handled.

Who holds your data

A common fear raised when the bill was first introduced was that the system would centralise every Australian's identity documents in one government database, creating a single "honeypot" for hackers. That is not quite how the legislation works, and the distinction is worth understanding.

The system is federated rather than centralised. Your identity is verified by an accredited identity service provider, such as a bank or a government agency, and the exchange of attributes happens between accredited providers rather than through one giant repository. The Act deliberately prohibits accredited entities from using biometric information for "one-to-many matching" of individuals or to determine whether someone holds multiple digital IDs (s 48(3)). Identity exchange providers are also barred from retaining attributes such as your name, address or date of birth once the transaction is complete (s 56).

That design reduces the "single database" risk, but it does not eliminate concentration risk. A handful of large accredited providers will still hold identity credentials and biometric data for very large numbers of Australians, and each is itself a target. The Medibank litigation shows how valuable that data is to attackers: the OAIC is pursuing Medibank in the Federal Court over the 2022 breach in which the personal and health information of about 9.7 million customers was exposed (Medibank Private Limited v Australian Information Commissioner [2024] FCA 117). A digital ID does not change the economics of that kind of attack.

The privacy safeguards in the Act

The Act contains a dedicated privacy chapter (Chapter 3) that goes further than the Privacy Act 1988 (Cth) in several ways.

  • Restricted attributes: accredited entities cannot collect information about your racial or ethnic origin, political opinions, religious beliefs, sexual orientation or similar sensitive attributes (s 44).
  • Express consent: before an accredited entity can disclose your name, address, date of birth, phone number or email to a relying party, it needs your express consent (s 45).
  • Biometric data: collection, use and disclosure of biometric information is allowed only for verifying your identity or authenticating your digital ID, and generally requires express consent (ss 48-49). Biometric information collected to verify identity must be destroyed as soon as verification is complete unless you have consented to its retention (s 51).
  • No tracking: accredited entities are prohibited from data profiling to track your online behaviour, even with your consent (s 53).
  • No marketing: personal information held by accredited entities cannot be used for marketing, advertising or market research (s 55).
  • No enforcement fishing: personal information cannot be used or disclosed for enforcement-related activities unless proceedings have started or a warrant exists, and biometric information can be disclosed to a law enforcement agency only in limited circumstances such as under a warrant (ss 49, 54).
  • Voluntary by law: a participating relying party must not require you to create or use a digital ID as a condition of accessing a service, and must provide another reasonably accessible means (s 74).

These are real constraints, backed by civil penalties of up to 1,500 penalty units for breaches such as unlawful collection of biometric information or prohibited tracking (ss 48, 53).

Does it stop data breaches?

No, and it was never designed to. The Act protects how identity information flows within the accredited system, but a data breach is a failure of security somewhere along that chain. If an accredited provider is hacked, the same consequences follow as with Optus or Medibank: personal information can be exposed regardless of how carefully the legislation is drafted.

The more relevant question is whether the system shrinks the attack surface overall. The government's argument is that it does, because it reduces how often you hand documents such as passports and driver licences to different businesses, each holding their own copy. If a business verifies your identity through the digital ID system rather than storing your passport scans, less of your data sits in that business's systems to be stolen. That logic is sound in theory, but it depends entirely on how well accredited providers and relying parties secure the data they do hold. The Act does not guarantee that outcome; it only creates the framework.

Where the gaps remain

The most significant gap is that the wider reform of the Privacy Act 1988 (Cth) is still unfinished. When the Digital ID bill was introduced, Australia's privacy law was widely criticised as outdated, and the government's own review had recommended a major overhaul. Only part of that reform has been delivered. The Privacy and Other Legislation Amendment Act 2024 (Cth) enacted the first tranche in December 2024, including a statutory tort for serious invasions of privacy and new criminal offences for "doxxing". Bigger items from the review, such as a direct right of action for privacy breaches and tougher rules on how personal information is collected and used, remain outstanding. That means the digital ID system is being built on a privacy foundation that is still being renovated.

There is also a question of scale. The Act's accreditation scheme was designed to expand over time from government services into the private sector, so the number of businesses holding identity-related data will grow. Each expansion increases the number of entry points that a hacker could target, and the practical security of the system will depend on how the ACCC supervises accreditation.

What to do before you sign up to a digital ID

For most people the decision is straightforward: a digital ID is voluntary, and the Act says businesses and agencies cannot force you to use one. Before you enrol, it is worth asking a few questions of the provider and of yourself.

  • Do you need a digital ID at all, or is the alternative channel acceptable? A service that offers a digital ID option must still give you another way in.
  • What identity documents does the provider ask you to upload, and how long does it keep them?
  • Where is your biometric information stored, and what happens to it if you close the account? You are entitled to have your digital ID deactivated on request (s 29).
  • If you run a business, check whether your business is or could become a relying party. Participating businesses take on obligations, including the prohibition on requiring customers to use a digital ID, and they need to understand how their own systems will handle identity data they receive.

If your business is considering becoming an accredited provider or a relying party under the scheme, the accreditation conditions and participation rules are detailed and carry real consequences for getting them wrong. An Artificer Legal adviser can review the accreditation or participation terms, check that your data handling complies with both the Act and the Privacy Act, and help you respond if the OAIC or the ACCC comes knocking with a complaint or a direction.

The safeguard you should not rely on

The sharpest point from the Act is this: the legislation can constrain what accredited entities do with your information, but it cannot stop an attacker who gets in anyway. The privacy chapter tells you who is allowed to use your data and for what; it says almost nothing about whether the systems holding it are secure enough. That is the difference between the two big questions in this debate. Whether the digital ID system is a privacy problem is answered in part by the Act, with safeguards that are genuinely stronger than the general law. Whether it is a security risk depends on the operators, and that is something legislation alone cannot fix.

In short, the Digital ID Act 2024 created a voluntary, regulated system with meaningful privacy protections, from the ban on collecting sensitive attributes to the restrictions on biometric data and enforcement access. It did not create a single central database, but it did concentrate identity data in a smaller number of hands, it does not prevent breaches at accredited providers, and it sits on a Privacy Act that is only partially reformed. For individuals, the practical answer is to treat a digital ID as an option to be assessed, not an obligation. For businesses, the system is a new compliance surface that deserves the same care as any other area where you hold customer data.