
"Australia's Digital ID in 2026: voluntary on paper, expanding everywhere"
Australia's Digital ID in 2026: voluntary on paper, expanding everywhere
Every few weeks a fresh round of claims circulates about Australia's Digital ID system — that it's about to become compulsory, that it unlocks your social media, that police can read your messages through it. None of that is currently true, but the system is growing fast, and the direction of travel is worth understanding. Here is where Digital ID actually stands as of October 2026.
The legal status: voluntary, with a legal floor
The Digital ID Act 2024 established a legislated, accreditation-based system, and it explicitly establishes Digital ID as voluntary. The ACCC, which acts as the Digital ID Regulator, describes its own mission as building "a trusted, secure, voluntary and inclusive regulated system" in its Digital ID Regulator annual report. Section 76 of the Act goes further: a participating service cannot refuse to deal with you because you don't want to use a Digital ID. (Digital ID Act 2024, ACCC Digital ID regulation)
Recent fact-checking backs the voluntary point against viral claims. Reuters' fact-check of 29 September 2026 confirmed that Digital ID is not required to access social media and does not give police access to private messages — two of the more persistent myths. (Reuters Fact Check)
What changed in 2026
Two things happened this year that matter:
- Scale. In the twelve months from 1 May 2025 to 30 April 2026 there were more than 113 million authenticated transactions through the Australian Government Digital ID System, up from 36.5 million in the previous corresponding period. That is a system moving from pilot to plumbing. (Minister for Finance media release, 26 June 2026)
- Private sector expansion. From 1 December 2026, accredited private Digital ID providers can join the government system and charge commercially for their services, and businesses that use myID for their own services begin contributing to its costs from 1 January 2027. Government services keep using myID for free, and individuals never pay. Higher-risk services will still require the government-issued myID rather than a private provider. (Minister for Finance media release, 26 June 2026)
The ACCC's role as regulator covers accrediting identity providers, approving participants, and enforcing the accreditation rules and data standards. The OAIC sits over the privacy safeguards, which build on the Privacy Act 1988. (OAIC on Digital ID)
What civil-society critics say
Civil liberties groups have supported the idea of digital identity in principle but pressed hard on safeguards. The Queensland Council for Civil Liberties, in its submission on the Digital ID Rules and Accreditation Data Standards, argued the scheme must proceed only with "clear and enforceable safeguards" and alongside an enforceable federal human rights framework and completed Privacy Act reform — not as a standalone expansion. (QCCL submission, June 2024)
That critique hasn't lost force in 2026. The worry is not the Act as written but the accumulation: a voluntary system used by tens of millions, opened to commercial providers, becomes the default path for everyday transactions, and "voluntary" starts meaning "you can technically opt out, but you'll queue for an hour to prove who you are the old way."
What you can actually do
- Use it where it's convenient; refuse it where it isn't. If a service tells you a Digital ID is mandatory, that's a breach of the scheme's rules — and worth reporting to the Digital ID Regulator.
- Know what's shared. The design principle is selective disclosure: a service gets confirmation you're over 18, not your full date of birth and document numbers, when that's all it needs. Check the details when you connect myID to a service.
- Keep your real documents out of app screenshots. Most digital-ID leakage is ordinary phishing and sloppy storage, not the system itself.
Why we're watching it
Digital ID is an authentication layer, and authentication done well reduces the amount of raw identity data businesses hoard — which is a privacy win when the safeguards hold. Our interest at StealthOz is the device layer underneath: if your phone runs a hardened OS like GrapheneOS, your identity applets sit on a device with a much smaller attack surface. That matters more, not less, as identity transactions move onto phones.
This post is general information, not legal advice.