DTA baking privacy into design of Govpass
The Digital Transformation Agency adopted privacy by design principles for the Govpass unified identity verification system, considering privacy from the inception of development, according to the agency's privacy advisor Jacob Suidgeest.
As part of the agency's involvement in Privacy Awareness Week, Suidgeest has penned a blog post detailing the steps the agency is taking to ensure the privacy of Govpass users is maintained.
These include using a double-blind architecture for the identification process itself, which handles the process through an exchange process, he said.
A service seeking to verify a user will not have access to the user's identity documents, while identity providers will not be aware of which service is requesting the verification.
The data collection process itself has been designed based on privacy principles focusing on limiting the collection, use, disclosure and retention of personal information, as well as giving users both a choice of how to verify their identity and control over how their data is shared.
Govpass will likewise be provided on an opt-in rather than opt-out basis, and users will be able to revoke their account at any time. It will also provide users clear information on how their personal data will be used prior to gaining consent from a user.
The project will also be subject to a series of independent privacy impact assessments aimed at identifying and mitigating privacy risks.
Half of government agencies falling short on email security measures: report
Lack of consistency across Australian Government bodies leaves critical vulnerabilities in the...
CISA and Microsoft warn of “active attacks” on SharePoint
Alerts have been published active attacks exploiting a remote code execution vulnerability in...
NSW Government agencies have ineffective cybersecurity controls: report
The Audit Office of New South Wales has found that NSW Government agencies still have minimal...