Digital ID Australia 2025–2026: what it actually means for your privacy.
A plain-English Digital ID Australia explainer covering the Digital ID Act 2024, what changed in 2025, what is and isn't mandatory in 2026, and what privacy-focused Australians can do to keep control of their identity data. The "is Digital ID Australia mandatory" question keeps coming up — short answer below, full detail throughout.
The short answer to "is Digital ID mandatory"
No. The Digital ID Act 2024 explicitly establishes Digital ID as voluntary. Section 76 prohibits a participating service from refusing you service solely because you decline to use Digital ID. There is currently no proposal to make it mandatory.
The "Digital ID is mandatory now" framing that's been circulating online conflates two different things: the federated identity system (voluntary) and specific verification requirements (sometimes mandatory) that the system can satisfy among other methods. The social media age-verification rules that came into force from 10 December 2025 require some method of age verification — Digital ID is one option, but not the only one.
The longer answer below covers the system itself, the legislation, what changed when, and what you can do.
What the Australian Digital ID System actually is
Australia's federated identity framework — the Australian Government Digital ID System, formerly known as the Trusted Digital Identity Framework (TDIF) — is a way for accredited identity providers to verify your identity once and then issue cryptographic assertions to participating services on your behalf. The intent is that you don't have to email a passport scan to every service that needs identity verification; instead, the participating service trusts the identity provider's already-verified assertion.
The accredited identity providers as of 2026 include:
- myID (renamed from myGovID in late 2024) — the federal government's identity credential, issued by the ATO.
- Australia Post Digital iD — Australia Post's identity verification service.
- OCR Labs IDVerse — a private-sector identity provider used by banks and fintech.
- Mastercard ID — Mastercard's identity verification service, used by gambling and adult-content services.
- Several smaller accredited providers operating in specific sectors.
The framework is overseen by the Australian Competition and Consumer Commission as the Digital ID Regulator, with privacy oversight from the Office of the Australian Information Commissioner.
What changed in 2025
Digital ID Act 2024 came into full effect
The Act establishes the legal framework for the federated system, sets accreditation criteria for identity providers, mandates information-handling and breach-disclosure rules, and — critically — codifies the voluntariness principle.
Private-sector services became eligible
Before 2025 the system was largely government-to-citizen. From mid-2025, private-sector services (banks, telcos, online platforms) could integrate as participating relying parties. This is the change most likely to affect you in daily life: your bank may now offer "log in with Digital ID" as an option alongside username/password.
Social media age verification commenced 10 December 2025
The eSafety Commissioner's enforcement of the social media minimum age of 16 created a wave of online confusion that Digital ID had become mandatory. The age-verification requirement is real; the requirement to use Digital ID specifically is not. The platforms can satisfy the requirement with Digital ID, with credit-card age inference, with biometric age estimation, or with several other methods.
Adult-content age verification trial
A trial of mandatory age verification on adult-content sites began in late 2025. This is a context where verification of some kind is mandatory; the choice of which method (Digital ID, ID-document upload, credit card, age-estimation tech) is left to the platform.
What is "mandatory" in 2026 vs what isn't
Mandatory verification (multiple methods accepted)
- Social media account creation if you are under 16 (platforms verify age; Digital ID is one method, not the only one).
- Account opening at major Australian banks and gambling services (regulated under AML/CTF rules; Digital ID is convenient but ID document scans are still accepted).
- Specific government services where face-to-face was previously required (Centrelink high-trust transactions, ATO certain assessments).
Voluntary (Digital ID is one option among several)
- myGov access (you can still log in with username + 2FA).
- Most online retail purchases (no identity verification required at all in most cases).
- General web browsing, search, social media account use after creation.
- Telco SIM activation (regulated, but ID-document scans still accepted as an alternative).
What isn't mandatory and probably won't be soon
- Browsing the web.
- Using encrypted messaging apps (Threema, Signal, etc.).
- Using a VPN.
- Owning or operating a privacy-focused phone like a GrapheneOS Pixel.
- Paying with cash or cryptocurrency for goods that don't require identity verification.
What this means if your privacy threat model is real
A federated identity system genuinely reduces some risks: you stop emailing passport scans to fly-by-night services, the identity provider's security work is consolidated, and the assertions sent to relying parties are minimal (often just "this person is over 18", not the full identity record). Those are real privacy gains.
It also creates new risks. The identity provider sees a richer picture than any individual relying party — they know which services you use Digital ID with, when, and how often. If the identity provider is breached, the consequences are larger than any single-service breach. If your identity provider account is compromised, the attacker can authenticate as you to multiple services at once.
For most Australians, the privacy trade is favourable. For specific threat models — journalists protecting source identity, executives whose movements should not be aggregable, survivors of domestic violence whose identity should be unlinkable from prior identity — the trade tilts the other way. Those threat models warrant the operational separation we cover on the consultation page.
Practical steps if you want to keep control
- Use Digital ID where the alternative is uploading a passport scan to an unfamiliar service. The federated system is more privacy-respecting than the historical alternative.
- Decline Digital ID where the alternative method is acceptable. Username + 2FA on myGov works fine for most users.
- Compartmentalise. Keep your Digital ID linked to a profile that does not also hold sensitive personal correspondence. GrapheneOS multiple user profiles make this trivial — Digital ID lives in one profile, source meetings in another.
- Audit linked services twice a year. myID and other identity providers expose a "linked services" list. Remove services you no longer use.
- Use a hardware security key (YubiKey, Titan) where the identity provider supports it. Phishing-resistant authentication is the largest single security upgrade you can make.
- Don't migrate every workflow to Digital ID just because it's available. Some workflows are better served by separate, single-purpose authentication.
- Review the Privacy Code provisions. The Digital ID Act 2024 imposes specific information-handling obligations on accredited providers. Knowing what they are makes you a more effective user of the system.
Worried about identity-based tracking? Start with the device.
A hardened GrapheneOS phone with proper profile separation, network tunnel, and Phantom Protocol is the foundation any identity-management strategy depends on.
Browse Phones → Book a ConsultationFrequently asked
Is Digital ID mandatory in Australia?
No. The Digital ID Act 2024 explicitly establishes Digital ID as voluntary. Section 76 prohibits a participating service from refusing service solely because someone declines to use Digital ID.
What is the Australian Digital ID System?
A federated identity framework. Accredited providers (myID, Australia Post Digital iD, OCR Labs, Mastercard, others) verify your identity once and issue cryptographic assertions to participating services. Overseen by the ACCC and bound by the Digital ID Act 2024.
What changed in 2025?
Digital ID Act 2024 came into full effect. Private-sector services (banks, telcos) became eligible. Social media age-verification commenced 10 December 2025 — created public confusion that Digital ID itself had become mandatory; it had not.
Will Digital ID be mandatory in 2026?
No legislation has been introduced. The voluntariness principle is enshrined in the Act and would require a separate amendment to remove.
How does Digital ID affect my privacy?
Reduces some risks (you don't hand passport scans to dozens of services) and increases others (the identity provider sees a richer picture). Trust in the provider is the central question.
What can I do to keep control?
Use Digital ID where the alternative is worse. Decline where alternatives are acceptable. Compartmentalise across user profiles. Audit linked services twice a year. Use a hardware security key.
Is myGov the same as Digital ID?
No. myGov is the Australian Government online services portal. myID is one of several accredited Digital ID providers under the federated framework.