Skip to main content

Jurisdiction Profiles

Review status: This foundation page requires specialist review before public approval. Its claims must remain within the scope stated here.

A single global identity technology does not create one global legal configuration. UbID uses jurisdiction profiles to apply local policy without redesigning the underlying credential and trust architecture for every deployment.

The profiles described here are implementation baselines, not legal opinions. Current official sources, local counsel, sector rules, regulator guidance, and deployment-specific facts remain authoritative.

Profile composition

A versioned profile should identify:

FieldPurpose
Jurisdiction and sectorCountry, state, province, region, public or private sector, and regulated domain
Participants and legal rolesController, joint controller, processor, issuer, verifier, holder service, custodian, orchestration provider, or trust-service role
Lawful purpose and basisPermitted processing purpose, legal basis, special-category condition, and prohibited secondary use
Claim minimisationAllowed claims, derived facts, prohibited combinations, and verifier retention
Notice and authorizationRequired notice version, consent or authorization evidence, withdrawal, and renewal conditions
Authentication and assuranceApproved methods, step-up, device, proofing, and human-review conditions
BiometricsNecessity, alternatives, capture, template protection, vendor role, retention, deletion, and review
Rights and complaintsAccess, correction, deletion, restriction, objection, portability, appeal, and regulator routing
Retention and recordsCredential, evidence, security, fraud, legal hold, and public-record schedules
Transfers and residencyProcessing location, recipient, subprocessor, transfer mechanism, and onward-use constraints
Incident obligationsAssessment, notification, evidence preservation, and communication timelines
Regulated statusRegistration, certification, conformity assessment, notification, or prohibited claims
Version controlOfficial sources, effective date, approvers, test evidence, supersession, and review date

Comparative public baseline

The following table identifies the principal baseline used in the UbID institutional regulatory study. It is intentionally concise and must not be treated as a complete statement of local law.

JurisdictionPrincipal baselineDeployment focus
European UnionGDPR and the European Digital Identity FrameworkLawful basis, minimisation, rights, DPIA, transfers, and regulated wallet or trust-service roles
United KingdomUK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025, and DVS Trust FrameworkPrivacy by design, complaints, assurance, conformity assessment, certification, and service registration
CanadaPIPEDA, Privacy Act, provincial regimes, and public-sector digital identity guidanceAppropriate purposes, consent, safeguards, access, breach records, federal/provincial scope, and assurance interoperability
United States — federalFTC and sector-specific frameworks such as health, finance, and children's privacyUnfair or deceptive practices, reasonable security, sector applicability, contracts, and incident procedures
New York StateSHIELD Act and NYDFS cybersecurity rules where applicableSafeguards, breach governance, MFA, cybersecurity program, testing, and reporting
CaliforniaCCPA/CPRA and implementing regulationsConsumer rights, sensitive information, assessments, cybersecurity audits, automated decision controls, and opt-out mechanisms
MexicoFederal and general personal-data protection frameworksLegality, purpose, proportionality, ARCO rights, sensitive data, security, notices, and transfers
El SalvadorPersonal-data protection and cybersecurity legislationEmerging authority and procedures, consent, rights, security, transfers, and incident controls
ColombiaLaw 1581, Decree 1074, and electronic-commerce frameworkAuthorization, purpose, restricted circulation, habeas data, policies, registration where applicable, and regulator procedures
PeruLaw 29733 and its current regulationConsent, ARCO rights, data-bank governance, sensitive data, security, incidents, and international processing
BrazilLGPD and ANPD regulationsLegal bases, rights, sensitive and children's data, accountability, impact reporting, incidents, and transfers
ChileLaw 19.628 as amended by Law 21.719, cybersecurity law, and electronic-signature frameworkTransition to the modernized privacy regime, rights, oversight, security, biometrics, transfers, and institutional readiness
ParaguayLaw 7593/2025 and implementing transitionNew comprehensive baseline, authority and procedure confirmation, rights, transfers, and versioned implementation
ArgentinaLaw 25.326 and implementing rulesConsent, habeas data, security, database obligations, rights timelines, and transfer safeguards
Hong KongPersonal Data (Privacy) Ordinance and six Data Protection PrinciplesCollection, purpose, retention, security, openness, access, correction, processors, and direct marketing
South KoreaPIPA and PIPC guidanceGranular consent, sensitive and unique identifiers, biometrics, transfers, security, foreign-operator duties, and sector certification
JapanAPPI plus the separate My Number and JPKI ecosystemPurpose, security, transfers, rights, authorized JPKI use, and strict separation of the Individual Number

Important transition examples

  • Chile: Law No. 21.719 has a deferred effective date of 1 December 2026. A Chilean deployment should treat 2026 as an implementation transition and maintain evidence of readiness, not assume that a technical profile alone satisfies the new regime.
  • United Kingdom: the DVS Trust Framework 1.0 is final, but its statutory commencement depends on accreditation of the first conformity-assessment body and is no earlier than 1 September 2026. Technical compatibility is not equivalent to certification or registration.
  • European Union: use of verifiable-credential standards does not by itself make a product a notified European Digital Identity Wallet or a qualified trust service under the European Digital Identity Framework.

These examples illustrate why effective dates, transition conditions, certifications, and regulator procedures belong in versioned profiles.

Profile evaluation

The selected profile should be evaluated before and during:

  1. collection or proofing;
  2. credential creation;
  3. biometric processing;
  4. presentation and disclosure;
  5. verifier retention;
  6. automated or assisted decision-making;
  7. device registration or recovery;
  8. cross-border transfer;
  9. rights or complaint handling;
  10. incident, revocation, deletion, or legal hold.

Combining overlays

A deployment may require multiple overlays at once:

Global baseline
+ country or regional profile
+ state or provincial profile
+ sector profile
+ institutional role profile
+ credential or transaction profile

The result should be deterministic and versioned. Conflicts must be resolved by the accountable institution; the platform must not silently choose the least restrictive rule.

Change and historical evidence

When a source changes, the institution should:

  • assess the legal and operational impact;
  • update the profile under change control;
  • test affected issuance, presentation, recovery, rights, and retention flows;
  • define migration for existing credentials and evidence;
  • preserve the previous version for historical explanation;
  • review public claims, contracts, notices, and partner documentation.

See Privacy and Regulatory Alignment and Assurance, Assessment, and Certification.