Regulation tracker
The laws and standards that govern how identity is verified, who they apply to, and where they stand.
| Regulation | Region | Status | Key date | Summary |
|---|---|---|---|---|
| BIPA | US | In force | Oct 2008 | Illinois’ Biometric Information Privacy Act, or BIPA, is a 2008 privacy law that requires notice and consent for many uses of biometric identifiers and allows affected people to sue. Its litigation history has made it a national compliance benchmark for facial biometrics. |
| GDPR | EU | In force | May 2018 | The GDPR has applied across the EU since 25 May 2018. It governs how identity verification providers and their customers collect, use, secure and delete personal data, with heightened rules for biometric identification data. |
| KYC/AML | Global | In force | — | KYC/AML is the global framework requiring regulated firms to identify customers, assess financial-crime risk, monitor activity and report suspicions. Its detailed legal duties are set by national and regional laws built around FATF standards. |
| NIST 800-63 | US | In force | — | NIST SP 800-63 is the United States government’s core framework for managing digital identity risk. It defines assurance levels for identity proofing, authentication and federation, and is widely used as a benchmark beyond federal agencies. |
| OSA | UK | Phasing in | Jan 2025 | The UK Online Safety Act requires services to assess and reduce children’s access to pornography and other harmful material. Ofcom oversees a phased regime that increasingly relies on highly effective age assurance while raising significant privacy questions. |
| eIDAS 2 | EU | Phasing in | Jan 2026 | eIDAS 2 updates the EU’s digital-identity and trust-services rules and creates the framework for the EU Digital Identity Wallet. It is in a phased implementation period, with wallet deployment and technical integration continuing through 2026 and beyond. |