23 July 2026

Privacy Law should be seen as the enabler of digital identity – not the barrier

There appears to be a persistent narrative in the digital identity space that privacy law stands in the way of progress. Compliance with the Privacy Act 2020 (Privacy Act) is often framed as a hurdle to be cleared, a cost to be managed, or worse, an excuse to delay adoption of digital identity solutions altogether. In our view, this narrative is not only unhelpful, but unfounded.

The reality is that well-designed digital identity tools are inherently more privacy-protective than the manual, paper-based processes they replace. Traditional identity verification often requires individuals to hand over far more personal information than is strictly necessary (e.g. photocopies of passports, utility bills, birth certificates), documents that are then stored, sometimes insecurely, by the requesting party. The risk of data breach, misuse, or simple human error in these processes is well established.

Digital identity products, by contrast, are built around the principle of data minimisation. A digital credential can confirm that you are over 18 without revealing your date of birth. It can verify your address without handing over a utility bill containing your account number. It can confirm your right to work without disclosing your immigration history.

This directly supports compliance with Information Privacy Principle (IPP) 1 of the Privacy Act which requires that organisations must collect only the personal information they genuinely need for a lawful purpose connected to their functions. Digital identity credentials operationalise this principle in a way that paper-based processes never could. When a verifier needs to confirm a single attribute, a digital credential can disclose precisely that attribute and nothing more – meaning that no surplus data changes hands and no unnecessary copies are made. Clear disclosures about the collection and use of digital credentials for a defined purpose, as required by IPP3, also give individuals greater control over, and understanding of, how their data is used.

Further, the obligation to protect and ensure the security of personal information under IPP5 is also better managed through digital identity products that are purpose built to satisfy these requirements using privacy by design approaches. A well-constructed digital credential collects less information, stores it more securely, and gives individuals greater control over what is shared and with whom.

Where digital identity services are provided by accredited providers under the Digital Identity Services Trust Framework Act 2023 (DISTF), the public also has heightened assurance that the tool they are using is safe and secure. Accreditation requires providers to meet defined standards around information security, privacy protections, and operational integrity. It subjects them to ongoing obligations and regulatory oversight. It provides a basis for reliance that no paper-based process has ever offered.

The DISTF was designed precisely to address the trust deficit that has historically slowed digital identity adoption. It creates a regulated environment in which providers must demonstrate and maintain compliance with standards that go well beyond the baseline requirements of general privacy law. For the public, accreditation is a signal that a provider has been independently assessed, and there is a system of accountability behind the service.

It is time to move past the notion that privacy law and digital identity are in tension. Many of the tools available today represent a better means of protecting privacy than the traditional measures they replace. They collect less, store less, share less, and (if accredited services under the DISTF) do so within a framework of regulated accountability.

The law is not the barrier. The sooner we recognise that privacy-first digital identity tools are the fulfilment of our privacy principles, not a threat to them, the sooner we can move toward the secure, trusted digital identity ecosystem that benefits everyone.

At MinterEllisonRuddWatts, we work closely with providers and relying parties to ensure that the adoption and implementation of digital identity tools is consistent with privacy law, documented through appropriate privacy notices and supported by privacy impact assessments.

If you are exploring digital identity solutions and want to get the privacy settings right from the outset, we are here to help.


Author: Suzy McMillan, Special Counsel, MinterEllisonRuddWatts

21 July 2026

Designing trust into the digital economy
06Jul

Designing trust into the digital economy

At Cuscal Paymark, we’ve seen how trust evolves - from the early days of card…

Bridging the trust gap in digital identity
06Jul

Bridging the trust gap in digital identity

At Cuscal Paymark, we’ve spent decades helping shape how New Zealanders pay.

Super Saver tickets now live: Digital Trust Hui Taumata 2026 – Towards Universal Trust
23Apr

Super Saver tickets now live: Digital Trust Hui Taumata 2026 – Towards Universal Trust

Join us at the Digital Trust Hui Taumata 2026 - Towards Universal Trust, Aotearoa New…

Tākina Convention & Exhibition Centre