identity.org.au

identity.org.au is not an Australian Government service. It is an open-source community service stewarded by the not-for-profit DETIO Foundation, currently in the process of applying for accreditation under the Digital ID Act 2024. How this service is different

Policies

Privacy

This page tells you what exists, where it lives, who can read it, and how long it is kept — with the actual figures, not adjectives.

The binding documents — the VirtEngine Privacy Policy, Biometric Data Addendum and Consent Framework — are versioned in the open-source repository. This page summarises them faithfully; where they differ, the repository documents govern.

This website collects nothing

identity.org.au is a static informational site. It has no accounts, no login, no forms, no analytics trackers and no advertising. The privacy questions that matter concern the wallet and the VEID network — which is what the rest of this page covers.

The life of your data, in five stages

Captured on your phone, encrypted before it moves, processed only inside hardware-sealed trusted processing units, destroyed when scoring ends — leaving only the result.

  1. Stage 1 Captured On your phone: document scan, selfie, liveness.
  2. Stage 2 Encrypted on your device Sealed before anything moves. Keys stay in your phone.
  3. Stage 3 Processed in a sealed enclave Hardware-attested. No operator can look inside.
  4. Stage 4 Raw data destroyed The enclave keeps nothing after scoring ends.
  5. Stage 5 Only the result remains A score and tier — never documents or biometrics.
Trusted processing — how the vault works, and why no one can open it

What exists, where it lives, who can read it

Each category of identity data, its storage location, readability and retention
Data Where it lives Who can read it Kept for
Document scans (licence, passport) Encrypted on your device; encrypted payloads in the network vault You. Processing happens only inside sealed, attested enclaves — no operator can look in; results, not images, are recorded 7 years (know-your-customer law), then destroyed
Biometric templates (face, fingerprint, iris) Encrypted on-device before transmission (X25519-XSalsa20-Poly1305); never unencrypted on-chain Never shared with services; never sold — prohibited regardless of consent Active account + 3 years after closure; absolute maximum 7 years from last use
OCR-extracted details (name, date of birth) Encrypted identity scopes on the network You; services only per explicitly consented claim With your account, subject to the document retention rule
Verification results (level, pass/fail) On the network — tamper-proof records Services you consent to, per request Permanent (results, not evidence)
Consent records Auditable history, timestamped You in full; services see their own grants Permanent audit trail
Verification session metadata (device fingerprint, IP during verification) Off-chain verification systems Fraud-prevention processing only Security logs 12 months; error logs 90 days
Wallet address and transactions The public blockchain Public — but not linked to your personal details Permanent (blockchain immutability)

The biometric commitments

Biometric data is special-category data, and the published Biometric Data Addendum binds the system to commitments stronger than general privacy law requires:

  • Never sold, leased or traded — an absolute prohibition that applies regardless of consent. Biometric data is never monetised.
  • Never disclosed raw. Services receive verification results, not biometric data. Sub-processors are contractually prohibited from retaining or using it.
  • Separate, informed consent — biometric consent is unbundled from terms acceptance, logged with a timestamp, and withdrawable at any time.
  • Deletion on request: 30 days from request or account closure, plus backup rotation (typically 90 days). Encryption keys are destroyed, rendering encrypted copies permanently unreadable.
  • Breach notification within 72 hours of discovery, with plain-language disclosure and identity-theft protection support where biometric data is involved.
  • Access rights: request a copy of your biometric data at any time ([email protected], subject “Biometric Data Access Request”); responses within 30 days.

Retention, in one table

Retention periods per data type and their rationale
Data type Retention period Why
Blockchain recordsPermanentImmutability — but never readable personal data
Biometric templatesActive account + 3 yearsFraud and re-registration prevention, KYC/AML
Identity documents7 yearsRegulatory (KYC/AML) requirements
Usage metrics3 yearsBilling and audit
Support communications3 yearsCustomer service
Security logs12 monthsIncident investigation
Error logs90 daysDebugging

At the end of retention

Destruction is automatic: deletion from active systems, removal from backups within the rotation schedule, and destruction of encryption keys — which makes any on-chain encrypted material permanently unreadable.

Your rights

  • Access — a copy of your data, within 30 days of request.
  • Correction — re-verify with corrected evidence; you review every extracted field before submission.
  • Withdrawal of consent — per scope, per service, any time. See revoking consent.
  • Deletion — see deleting your identity for the full process and its honest limits.
  • Portability — export your data in a structured format.

Contact for all privacy matters: [email protected]. The system is designed to comply with the Australian Privacy Principles, GDPR (including Article 9 explicit consent for biometric data), and biometric-specific laws such as Illinois BIPA.

Read the governing documents

The full Privacy Policy, Biometric Data Addendum, Consent Framework and GDPR compliance documentation are versioned alongside the code in the open-source repository — you can read the exact text this page summarises.