Skip to content

Digital Identity

What is Digital Identity?

The collection of electronically captured and stored personal attributes, credentials, and identifiers that uniquely represent an individual in digital systems.

Privacy and Data Protection

Each of these is named in at least one of the same controls as digital identity. The number is how many controls name both.

What the standards actually require on digital identity

Requirements naming digital identity across 6 standards, quoted from the control text.

Requires Member States to designate supervisory bodies to supervise European Digital Identity Wallet providers, with powers to monitor compliance, require information and order corrective action, and to report to the Commission and the Cooperation Group.

EIDAS-Art.46a · Supervision of the European Digital Identity Wallet framework

Conduct a Digital Identity Risk Assessment per NIST SP 800-63-3 Section 5 and select appropriate assurance levels for each digital transaction or service.

NISTSP63-1 · Digital Identity Risk Assessment and Assurance Level Selection (IAL, AAL, FAL)

Conduct Digital Identity Risk Management per NIST SP 800-63-4 Section 5 (April 2025) using the updated risk management process introduced in Rev 4.

NISTSP63R4-1 · Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection

Recognising that interoperable digital identity regimes promote connectivity and growth in the digital economy, the Parties shall pursue mechanisms to promote compatibility and interoperability between their respective digital identity regimes, including throu...

DEPA-7.1 · Digital Identities

The FATF 40 Recommendations + Methodology are the global AML/CFT/CPF standard. Last comprehensive revision February 2012; subsequent TARGETED UPDATES: R.5 (Terrorist Financing) 2024; R.8 (NPO) 2023 narrowed scope to focused proportionate measures;

FATF-Status · FATF 40 Recommendations - corpus status, 5th + 6th Mutual Evaluation Rounds + targeted updates

Questions people ask about digital identity

What is Digital Identity?
The collection of electronically captured and stored personal attributes, credentials, and identifiers that uniquely represent an individual in digital systems.
Why is Digital Identity important for compliance?
Digital Identity is a key concept in Privacy and Data Protection. Understanding digital identity helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Digital Identity?
Digital Identity appears in the requirement text of eIDAS 2.0 - EU Digital Identity Regulation, NIST SP 800-63 Digital Identity Guidelines, NIST SP 800-63-4, ITU-T X.805 - Security Architecture for End-to-End Communications, Digital Economy Partnership Agreement (DEPA). Across these standards we have identified 14 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Digital Identity?
Explore our compliance framework pages to see how digital identity applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Digital Identity applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.