"Digital ID after August 2026: the protection strategy, and what's still expanding"
Australia's digital identity system now has two parallel storylines, and they pull in opposite directions. On the last day of August 2026 the Attorney-General released a broad identity protection strategy — draft privacy legislation covering AI data practices and smart glasses, a right to erasure aimed at social media and search platforms, and a new service called IDLock that will let people block their own driver licence and passport in the Document Verification Service. In the same month, NSW formally agreed to feed driver licence photos into the national face matching network, and the government announced a biometric liveness capability to harden the Digital ID itself against spoofing. Protection and expansion are running on the same track, in the same direction, and it's worth being precise about which is which.
We covered the earlier phase in Australia's Digital ID in 2026: voluntary on paper, expanding everywhere — the system went live under the Digital ID Act 2024, and the question was always what would happen once onboarding pressure arrived. August 2026 answered part of that.
What the strategy adds on paper
The strategy, reported in detail by Biometric Update on 31 August, has three concrete pieces. First, a right to erasure: individuals can demand that large digital platforms — social media and search engines specifically — destroy personal information they hold, with journalism carved out. Second, stronger consent standards for data collection and "measures to stop businesses from trading in personal information without clear permission," which targets the data-broker economy that has grown up around breached and scraped Australian records. Third, the AI angle: the draft law names AI systems trained on people's data without consent, and ambient-collection devices — smart glasses in particular — as enforcement targets. The government explicitly cites connected vehicles that continuously collect and process personal information as an amplifier of breach and surveillance risk.
The framing from Attorney-General Michelle Rowland leans on public distrust: almost four in five Australians report having very little or no control over how their personal information is collected or used. That's the strategy's own diagnosis, and it's a fair one — the Privacy Act has been under reform since 2023 and only the first tranche (a statutory tort for serious invasions of privacy, doxxing offences) has passed.
The centrepiece for identity specifically is IDLock. Announced on 31 August 2026, it's a myGov service letting Australians "block, unblock and monitor the use of eligible identity documents through the Document Verification Service at any time." A small early-access cohort gets it later this year; national rollout is 2027. It's described as a new way to reach the protections of the Credential Protection Register, which has existed since 2022.
What actually changed versus 2024-25
Here's the position we'll take and defend: almost nothing in the August strategy is new law yet, and the parts that feel new mostly aren't.
The Attorney-General's own release is a delivery announcement, not legislation — no bill, no schedule, no commencement date beyond the 2026 trial and 2027 rollout. IDLock operates inside powers that already existed: the Credential Protection Register has been running under the Identity Verification Services Act 2023 since late 2022, and the government says it has blocked over 830,000 fraudulent identity verification attempts — roughly 18,000 a month. IDLock is a user-facing toggle on an existing blocklist. That's genuinely useful, but "new identity protection framework" and "new way to access an existing register" are different sentences, and the government used the first.
The right to erasure and the consent reforms are draft legislation released for consultation, with introduction to parliament planned by the end of 2026. Nothing has survived committee, amendment, or a vote. Australians are reading press releases about protections they cannot invoke today.
Contrast that with the 2024 baseline. The Digital ID Act 2024 already contains safeguards the strategy gets credit for gesturing toward: accredited entities can't use biometric information for one-to-many matching, must destroy biometric data collected for verification as soon as verification completes, are banned from profiling to track users even with consent, and face civil penalties for breaches. The OAIC keeps a Digital ID page describing those safeguards, and its Digital ID Regulatory Strategy (published February 2025) set out how the regulator intended to police the accredited system. So when the August strategy announces "protections for digital ID," the honest reading is: the ID system itself was already regulated harder than the general economy around it. The new strategy is mostly about the surrounding economy — platforms, brokers, wearables — where the Privacy Act remains weak.
One limitation to concede: we're working from the government release, the draft-law reporting, and the Biometric Update coverage, not from the full exposure draft text. The final scope of the erasure right — which platforms qualify, what counts as "personal information shared," how enforcement works — depends entirely on what survives consultation. ThreatVectr's reporting notes the bill is subject to amendment and nothing has been tabled yet. Anyone treating the announced scope as settled is ahead of the evidence.
The expansion pressure nobody paused
While the protection side drafted bills, the system kept growing. On 8 August 2026, NSW moved to join the National Driver Licence Facial Recognition Solution, sharing driver licence and photo card images with the national face matching service to fight identity fraud and organised crime. WA and SA were already connected; the NDLFRS launched in October 2025 after close to a decade of state-by-state negotiation dating back to 2019, when Victoria and Queensland first signalled they'd contribute licence images.
Two things about the NSW move deserve scrutiny. It arrived inside a broader organised-crime bill that also lets police compel people to hand over device access information and gives police access to unredacted toll-camera images. The face matching expansion isn't happening in a privacy-neutral package; it's bundled with coercive powers. And in April 2026 the government announced plans to contract biometric liveness detection for the national Digital ID, meaning the system is actively adding biometric capabilities — spoofing defence, yes, but biometric capability is biometric capability, and each addition is another surface that can be repurposed or breached.
This is the structural tension in Australian digital identity policy. The Digital ID Act deliberately prohibits one-to-many biometric matching inside the accredited system — that's a hard line the 2024 law drew for good reason. Meanwhile, a separate national face matching service built on state licence databases is expanding jurisdiction by jurisdiction, and its core function is precisely matching faces against a stored gallery. Legally these are different systems with different rules. Practically, from the citizen's side, Australia is accumulating two biometric identity infrastructures, one restricted and one growing.
Practical takeaways for Australians
When is a Digital ID required? Under the current law, never by individuals. Government services offer it, private-sector relying parties are phasing in, but you retain the documentary alternative for every use case we can find — the AML/CTF framework, for instance, requires organisations to maintain an alternative verification method, and section 35A-style electronic checks only proceed with your express agreement and an available alternative. If someone tells you a Digital ID is mandatory for a service, ask them to point to the requirement; we have not found one, though we concede a future expansion could create de facto pressure in specific sectors even without a legal mandate.
What about IDLock when it lands? Our view: use it. If your licence or passport details were exposed in the Optus or Medibank breaches — and 9.7 million Medibank customers' were — a block on electronic verification is a real, if narrow, control. It's also weaker than advertised: a block list stops a stolen credential from verifying, but the underlying data is already loose. The Zyphe analysis puts it correctly — strong recovery mechanism after a breach, weak preventive one before it. And a locked passport still works at the border; only the verification pathway closes.
If offered a Digital ID for a service, the decision rule we'd use: does the service otherwise demand document scans it will store? If yes, the Digital ID may genuinely reduce the copies of your documents floating around — that's the system's legitimate argument. If the service would only do a simple name-and-DOB check anyway, the Digital ID adds nothing for your privacy and one more account to your attack surface. Whatever account set you keep, a hardware FIDO2 key makes the phishable-password half of that surface disappear, and keeping document scans off the phone entirely — or off a faraday-pouched phone when you're not using it — does more than any ID lock.
On the strategy's other promises — erasure, consent reform, wearable rules — the practical takeaway is that nothing is actionable until the bill passes. If the erasure right matters to you, it will matter in 2027, not now.