Introduction
On May 6, 2026, Utah's SB 275 will establish the first state-endorsed digital identity program in the U.S., incorporating explicit privacy protections. This groundbreaking law allows Utah residents to share only the necessary information for each transaction. For example, when verifying age at a bar, the system confirms "over 21" without revealing your birthdate or address. This approach marks a significant shift from traditional ID systems.
Key Provisions of SB 275
The law applies to businesses that choose to participate in Utah's program. If you're a digital wallet provider, an identity verification vendor, or a business accepting the state credential, you'll need to comply with new consent, purpose-limitation, and loyalty obligations.
Timeline
- March 2025: Utah legislature passes SB 275 unanimously.
- Expected April 2025: Governor Cox signs the bill into law.
- May 6, 2026: Compliance deadline for participating businesses.
- 2028: Audits begin to evaluate compliance and effectiveness.
Gaps in Current Practices
SB 275 highlights deficiencies in existing identity verification methods:
- Consent Issues: Traditional ID checks often lack explicit consent for each attribute collected. SB 275 requires consent for each attribute.
- Data Minimisation: Physical IDs expose more information than necessary. SB 275 enforces Data Minimisation.
- Loyalty Obligations: Current systems lack loyalty obligations. SB 275 introduces this requirement to protect user data.
- Technical Safeguards: Physical IDs are easy to forge. SB 275 mandates cryptographic protections to secure digital credentials.
Alignment with Existing Standards
SB 275 aligns with established privacy and security frameworks:
- GDPR Article 5(1)(c): Requires Data Minimisation. SB 275 operationalizes this at the identity verification level.
- GDPR Article 6: Requires a lawful basis for processing. SB 275 mirrors this with its consent requirement.
- ISO/IEC 27002 Control 5.34: Addresses privacy and PII protection. SB 275 establishes a regulatory framework for compliance.
- NIST Cybersecurity Framework (CSF) 2.0 2.0 PR.DS-01 and PR.DS-02: Supports SB 275's cryptographic safeguard requirements.
Action Items for Your Team
- Audit Identity Verification Vendors: Confirm if your vendors will participate in Utah's program and their compliance plans.
- Map Data Needs: Identify what attributes you need versus what you currently collect to reduce privacy risks.
- Implement Consent Mechanisms: Develop systems to manage consent at the attribute level.
- Define Loyalty Boundaries: Establish what "loyalty to the user" means for your processes and document these boundaries.
- Evaluate Cryptographic Controls: Ensure your digital identity technology includes robust cryptographic protections.
- Prepare for Audits: Build audit trails demonstrating compliance with consent, purpose limitation, and technical safeguards.
- Monitor Legislation: Track state-level digital identity bills to stay ahead of emerging regulations.
Conclusion
Early compliance with digital identity regulations like Utah's SB 275 offers a strategic advantage. The shift towards privacy-respecting verification is inevitable. By adapting now, your business can lead the way in secure and efficient identity verification practices.





