Close

New Workspace Modernization Research from CDW

See how IT leaders are tackling workspace modernization opportunities and challenges.

Feb 09 2026
Data Analytics

Utah Advances Policy-First Digital Identity Framework Centered On Individual Control

The state moves to authorize a digital identity framework emphasizing open standards, privacy and durable public policy nationwide.

Utah is moving toward full legislative authorization of a state-endorsed digital identity framework that prioritizes individual control, privacy and long-term verifiability, Utah Chief Privacy Officer Christopher Bramwell said recently at the Identity Policy Forum.

The initiative, known as State-Endorsed Digital Identity, or SEDI, is designed to separate identity from government-issued privileges, rely on open standards and create a durable foundation for digital services across state and local government.

Speaking at a forum presented by the Better Identity Coalition, the FIDO Alliance and the Identity Theft Resource Center, Bramwell said Utah plans to introduce comprehensive SEDI legislation this year. The bill would establish rules for digital identity verifiers, wallet providers and enforcement, while defining the role of government as an endorser — not owner — of identity.

Bramwell said multiple states are already in discussions with Utah about adopting similar approaches, and a multistate SEI consortium is forming to accelerate coordination. The effort, he said, aims to move digital identity policy out of administrative silos and into open, elected policymaking processes.

Click the banner below to consider approaches to data center optimization.

 

Identity Belongs to the Individual, Not the State

At the core of Utah’s approach is a clear position on control: Identity exists independent of government, and individuals — not agencies — must ultimately control it, Bramwell said.

“Whoever controls the key controls the identity,” he told attendees, arguing that digital identity systems must be designed so individuals retain control of cryptographic keys while the state provides endorsement and protection.

Bramwell cautioned against identity models that allow governments or third parties to revoke identity outright, particularly when identity is tightly coupled to licenses or privileges. Even individuals who lose certain rights, he said, still retain identity — a distinction he described as fundamental to American values and constitutional norms.

He also warned against centralized national identity systems, citing both political resistance and cybersecurity risk. A single point of failure, Bramwell said, could undermine public trust if compromised at scale, particularly during sensitive events such as elections. States, he argued, are better positioned to anchor identity systems while coordinating through shared frameworks.

The Utah model also preserves anonymity and pseudonymity, which Bramwell described as essential to free expression and civic discourse. He criticized proposals that would require full identity disclosure to access online platforms, calling them incompatible with historical American principles.

READ MORE: States must appoint data privacy officers.

Data Governance as the Foundation for Digital Identity

Bramwell placed digital identity within a broader effort to modernize government data practices, arguing that identity cannot function properly without strong data governance. He said most government entities lack clear rules for data disposal, defined purposes for data use and consistent processes for notifying individuals when those purposes change.

Those gaps, he said, stem from decades of technology modernization that failed to translate traditional records management laws into technical requirements. The result is mounting public distrust and growing operational risk as governments move toward automation and artificial intelligence-driven decision-making.

Utah’s strategy addresses those challenges through three pillars: comprehensive data governance, verifiability and automation. The first pillar establishes a clear legal basis for data use, retention limits and modern data schemas capable of supporting immutable public records and verifiable credentials. Utah is currently the only state with a comprehensive government data privacy law that applies to every public entity statewide, Bramwell said.

The second pillar focuses on verifiable, accurate data and reliable identity proofing; prerequisites, Bramwell said, for responsible automation. Only after those foundations are in place can governments safely deploy AI systems with appropriate human oversight, appeal mechanisms and bias protections.

DIVE DEEPER: Here’s a guide to AI governance for state and local agencies.

Open Standards, Right to Paper and a Multistate Path Forward

SEDI is being designed to support multiple credential formats, including both long-lived credentials for life events such as property ownership and education, and more ephemeral credentials for short-term interactions. Bramwell emphasized that open standards and open protocols are central to the framework, allowing any individual to understand how their identity functions.

He also stressed the importance of preserving a “right to paper,” warning that citizens should not be forced into a fully digital existence. Physical documents, he said, must remain available and strengthened alongside digital systems to maintain public trust and accessibility.

By grounding digital identity in law, transparency and shared values rather than technology alone, Bramwell said Utah hopes to provide a replicable model for other states.

Sean Pavone/Getty Images