Regulation tracker

The laws and standards that govern how identity is verified, who they apply to, and where they stand.

RegulationRegionStatusKey dateSummary
BIPAUSIn forceOct 2008Illinois’ Biometric Information Privacy Act, or BIPA, is a 2008 privacy law that requires notice and consent for many uses of biometric identifiers and allows affected people to sue. Its litigation history has made it a national compliance benchmark for facial biometrics.
GDPREUIn forceMay 2018The GDPR has applied across the EU since 25 May 2018. It governs how identity verification providers and their customers collect, use, secure and delete personal data, with heightened rules for biometric identification data.
KYC/AMLGlobalIn forceKYC/AML is the global framework requiring regulated firms to identify customers, assess financial-crime risk, monitor activity and report suspicions. Its detailed legal duties are set by national and regional laws built around FATF standards.
NIST 800-63USIn forceNIST SP 800-63 is the United States government’s core framework for managing digital identity risk. It defines assurance levels for identity proofing, authentication and federation, and is widely used as a benchmark beyond federal agencies.
OSAUKPhasing inJan 2025The UK Online Safety Act requires services to assess and reduce children’s access to pornography and other harmful material. Ofcom oversees a phased regime that increasingly relies on highly effective age assurance while raising significant privacy questions.
eIDAS 2EUPhasing inJan 2026eIDAS 2 updates the EU’s digital-identity and trust-services rules and creates the framework for the EU Digital Identity Wallet. It is in a phased implementation period, with wallet deployment and technical integration continuing through 2026 and beyond.