Say you want to sign up for a new mobile phone plan online in Australia. Today, the telephone company has to run its own identity check. You upload a photo of your driver’s license, maybe your passport, perhaps a utility bill, until you hit the 100-point identity threshold. You hand over copies of sensitive documents to a private company, which then stores them. You repeat this whole process again next week when you apply for a rental property, and again when you open a new bank account.
For years, Australia’s national digital identity system was a government-only affair. That’s about to change. In December 2026, the Australian Government Digital ID System opens to the private sector for the first time, with significant implications for identity verification providers, banks, fintechs, and any business that onboards customers online.
Here is what phases 3 and 4 actually mean, what opens up, and how identity verification providers can prepare.
Key Takeaways
- The private sector gains access in December 2026. Phases 3 and 4 of the Australia digital ID rollout open the government system to private businesses, both as users and as accredited providers.
- Accreditation is the gateway. To provide digital ID services within the system, providers must be accredited by the regulator and earn a trust mark demonstrating compliance with privacy, security, and fraud-control standards.
- Participation is voluntary, for everyone. Businesses cannot force customers to create a Digital ID and must always offer an alternative verification path.
- The opportunity is real but limited. The government expects only five to ten private-sector providers to participate initially, making early accreditation a genuine competitive advantage.
- Preparation should start now. The accreditation process is rigorous, and providers that begin readiness reviews early will be best positioned when applications open.
Book a Demo
Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience.
What Is the Australian Digital ID Act 2024?
The Australia Digital ID Act is the legislation that formalized and expanded Australia’s national approach to digital identity. It took effect on December 1, 2024, replacing the previous unlegislated Trusted Digital Identity Framework (TDIF) with a legally binding accreditation scheme and a governing structure for the Australian Government Digital ID System, known as AGDIS.
At its core, the Act does three things:
- It establishes AGDIS as the national system that lets individuals verify their identity online with government and, eventually, private businesses.
- It creates a legislated accreditation scheme that any provider of digital ID services must pass to participate.
- It sets up an independent regulator, the Australian Competition and Consumer Commission (ACCC), to oversee accreditation, compliance, and enforcement, with the Office of the Australian Information Commissioner handling privacy obligations.
Importantly, the Act doesn’t create a new identification document or a single national ID number. As the government has repeatedly stressed, a Digital ID is not a card, a number, or a new form of ID. It is a secure electronic method of proving who you are online without handing over unnecessary personal information. Instead of providing physical copies of multiple documents to reach the traditional 100-point identity check, an individual can verify once and reuse that verified identity across services.
The framework for digital identity Australia is being rolled out in four phases, deliberately staged so the system can scale safely. Phases 1 and 2 expanded the system across Commonwealth, state, and territory government services. Phases 3 and 4 are where the private sector finally enters the picture.
If you are new to the fundamentals, our guide to what identity verification is provides useful background before diving into the accreditation detail below.
What Opens Up in December 2026
December 2026 is the pivotal date. Both remaining phases are scheduled to commence then, and together they complete the transition from a government-only system to an economy-wide one.
Phase 3 opens applications to private-sector relying parties. This means businesses such as banks, telcos, insurers, and online platforms will be able to apply to use government-accredited Digital ID providers to verify their customers. A customer could, in principle, use their government-backed Digital ID to open a bank account or sign up for a mobile plan without repeatedly submitting identity documents.
Phase 4 goes a step further. It allows accredited private-sector Digital ID providers, attribute providers, and identity exchange providers to apply to join AGDIS. This is the phase that lets private identity businesses operate inside the national system, and potentially facilitate access to certain government services.
One critical principle runs through both phases: voluntariness. Even when a business participates in AGDIS, it cannot require a customer to create or use a Digital ID as a condition of service. An alternative, non-AGDIS method of verification must always be available. This is a non-negotiable feature of digital ID Australia, and it shapes how businesses must design their onboarding flows.
It is worth noting that accreditation itself has been open throughout all phases. Several private entities are already accredited, including Australia Post, IDVerse, Mastercard, and ConnectID operated by Australian Payments Plus. What December 2026 changes is their ability to actually participate within the government system.
The Accreditation Framework for IDV Providers
Accreditation is the mechanism that determines who can provide digital identity services within AGDIS. It is voluntary in the sense that no one is forced to seek it, but it is mandatory for any provider wanting to operate inside the government system. The scheme recognizes three main categories of accredited entity:
- Identity Service Providers (ISPs): Entities that verify and manage an individual’s identity, generating the Digital ID itself.
- Attribute Service Providers (ASPs): Entities that verify specific attributes about a person, such as age, qualifications, or professional status, rather than full identity.
- Identity Exchange Providers: Entities that securely route identity information between providers and relying parties without creating a central store of data.
To become accredited, providers must satisfy requirements set out in the Accreditation Rules and Accreditation Data Standards. These cover several core areas:
- Identity verification levels: Meeting defined proofing standards for how rigorously identity is established.
- Privacy protections: Strict handling of personal information, including prohibitions on collecting certain sensitive data and restrictions on using identity data for unrelated purposes.
- Security: Robust controls against cyber threats and mandatory reporting of security and fraud incidents.
- Fraud control: Active systems to detect and prevent identity fraud within the service.
- Accessibility and usability: Ensuring the service works for people who face barriers, with testing across diverse user groups.
- Biometrics: Where used, biometric systems must be continuously improved to avoid discriminating against any group.
Providers that meet these standards receive a trust mark they can display. Using the trust mark without authorization, or failing to use it when required, can attract civil penalties of $330,000.
What It Means for Private-Sector IDV Providers
For identity verification providers, phases 3 and 4 create a mix of opportunity and challenge.
The opportunity is substantial. Being accredited and active within AGDIS positions a provider at the center of Australia’s national identity infrastructure. Because the government anticipates only five to ten private-sector providers participating initially, early movers stand to capture a meaningful share of a market that touches banking, payments, telecommunications, and beyond. Accreditation also functions as a powerful trust signal, telling relying parties and consumers that a provider has met rigorous, legally enforced standards.
The challenges are equally real. Accreditation is demanding, and the privacy, security, and fraud-control obligations are ongoing rather than one-time hurdles. Providers must build systems that detect increasingly sophisticated fraud, including AI-generated documents and deepfakes, while remaining fully compliant with data-handling restrictions. The voluntariness principle also means businesses cannot rely solely on Digital ID, so providers that support both system-based and traditional document-based verification will be best positioned to serve the full market.
For providers already navigating existing obligations, it helps to understand how this fits alongside broader compliance duties. Our overview of KYC regulations explains the wider identity and anti-money-laundering context that AGDIS participation sits within.
How to Prepare for AGDIS Accreditation
Providers that want to participate when applications open should not wait until December 2026 to begin. Here are practical steps to build readiness:
- Review the Accreditation Rules and Data Standards. Map your current capabilities against the published requirements for identity proofing levels, privacy, security, and fraud control to identify gaps early.
- Assess your privacy posture. Confirm your data-handling practices align with the Act’s strict limits on collecting and using identity information, and that you can demonstrate compliance.
- Strengthen fraud detection. Ensure your systems can detect modern threats including synthetic identities, injection attacks, and deepfakes, since fraud control is a core accreditation criterion.
- Build incident-reporting processes. Establish the notification and management procedures required for cyber security and identity fraud incidents within AGDIS.
- Validate accessibility and usability. Test your service with diverse users to meet the accessibility standards embedded in the framework.
- Decide on your category. Determine whether you are seeking accreditation as an identity service provider, attribute provider, or exchange provider, as each carries distinct requirements.
- Engage early with the process. Monitor ACCC guidance and prepare documentation ahead of time so you are ready to apply as soon as the window opens.
Book a Demo
Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience.
FAQs
What is myID and how does it differ from myGovID?
myID is the current name for the Australian Government's Digital ID app, operated by the Australian Taxation Office. It was previously called myGovID and was rebranded to reduce confusion with the separate myGov services portal. The underlying function remains the same: verifying identity to access government services online.
Is participation in AGDIS mandatory for Australian businesses?
No. Participation is entirely voluntary for businesses, and accreditation is voluntary for providers. Critically, businesses that do participate cannot require customers to create or use a Digital ID and must always offer an alternative verification method that does not rely on AGDIS.
What is the TDIF and who must comply with it?
The Trusted Digital Identity Framework was Australia's earlier, unlegislated accreditation scheme for digital identity providers. It has been replaced by the legislated accreditation scheme under the Digital ID Act 2024. Providers seeking to operate within AGDIS now comply with the new Accreditation Rules rather than the former TDIF.
How does Australia's Digital ID Act compare to eIDAS 2.0 in the EU?
Both create frameworks for trusted digital identity across public and private sectors, but they differ in approach. The EU model centers on a Digital Identity Wallet issued to citizens. You can explore the European framework in our guide to eIDAS 2.0 and the EU Digital Identity Wallet.
Can overseas IDV providers apply for AGDIS accreditation?
The accreditation scheme is designed to operate economy-wide, and accreditation focuses on meeting the required privacy, security, and technical standards rather than nationality alone. Overseas providers should review the Accreditation Rules closely and seek guidance from the ACCC, as operating within AGDIS involves meeting Australian data and technical requirements.



