References and Source Standards
This page identifies the principal sources used to prepare the public UbID documentation. It does not reproduce every deployment-specific legal, contractual, security, or implementation source.
UbID institutional research cut-off: 30 July 2026
Selected official-source recheck for Phase 3G: 6 August 2026
Laws, regulations, standards, regulator guidance, and certification schemes change. Always verify the current official publication and effective date before relying on a reference.
Source classes
- Normative standard — defines technical requirements or protocol behavior.
- Official law or regulation — authoritative legal text published by the responsible body.
- Authority guidance — official interpretation or implementation guidance; its legal effect depends on the jurisdiction.
- Controlled UbID source — approved institutional architecture, governance, or terminology baseline.
- Explanatory material — useful context that is not normative or legally authoritative.
Controlled UbID sources
- UbID Trust Fabric — Architecture Book, Enterprise Edition, version 2.0, July 2026.
- Identity in the Digital Society: The UbID Approach, 30 July 2026.
- Identity in the Digital Society: The UbID Approach — Global Privacy and Regulatory Alignment, version 3.1, 30 July 2026.
- Diccionario Técnico Institucional de Estándares, Criptografía e Interoperabilidad — UbID Trust Fabric, version 1.0, July 2026.
These controlled sources distinguish current implementation evidence, durable reference architecture, transitions, targets, and future concepts. A source description is not automatically a public availability commitment.
Digital identity and credential standards
- W3C Decentralized Identifiers (DID) Core 1.0
- W3C Verifiable Credentials Data Model 2.0
- IETF RFC 9901 — Selective Disclosure for JSON Web Tokens
- OpenID for Verifiable Credential Issuance 1.0
- OpenID for Verifiable Presentations 1.0
- W3C Web Authentication Level 3
- IETF RFC 9700 — OAuth 2.0 Security Best Current Practice
- Decentralized Identity Foundation — DIDComm Messaging v2.1
- Model Context Protocol specification
An implementation must declare the exact version and profile it supports, especially where a credential profile or extension remains under active development.
Cryptography and security
- NIST FIPS 203 — ML-KEM
- NIST FIPS 204 — ML-DSA
- NIST Privacy Framework
- NISTIR 8202 — Blockchain Technology Overview
- OpenBao Transit secrets engine
- OP-TEE overview
- GlobalPlatform TEE Protection Profile
Public documentation uses these sources to explain architecture and governance. It does not publish production key configuration, trust measurements, recovery parameters, or privileged procedures.
European Union
- General Data Protection Regulation — Regulation (EU) 2016/679
- European Digital Identity Framework — Regulation (EU) 2024/1183
- European Data Protection Board guidance
United Kingdom
- Data Protection Act 2018
- Data (Use and Access) Act 2025
- ICO guidance on the Data (Use and Access) Act 2025
- UK Digital Verification Services Trust Framework 1.0
Chile
- Law No. 19.628 on personal-data protection
- Law No. 21.719 regulating personal-data protection and creating the Personal Data Protection Agency
- Law No. 21.663 — Cybersecurity Framework Law
- Law No. 19.799 on electronic documents and electronic signatures
Americas
Canada
- Office of the Privacy Commissioner of Canada — PIPEDA
- Canada Privacy Act
- Government of Canada — digital credentials
United States
- Federal Trade Commission privacy and security guidance
- California Consumer Privacy Act
- California Privacy Protection Agency regulations
- New York SHIELD Act
- New York Department of Financial Services cybersecurity guidance
- Illinois Biometric Information Privacy Act
Latin America
- Colombia Law 1581 of 2012
- Peru personal-data protection legislation and guidance
- Brazil General Data Protection Law — LGPD
- Argentina Law No. 25.326
- Paraguay information on Law No. 7593/2025
- Mexico private-sector personal-data law resources
- El Salvador legislative sources
Asia-Pacific
- Hong Kong Personal Data (Privacy) Ordinance and Data Protection Principles
- Republic of Korea Personal Information Protection Commission
- Japan Personal Information Protection Commission legal resources
- Japan Digital Agency — My Number and related digital identity information
Use of regulatory sources
A public regulatory page should:
- cite the current official source;
- identify the publication or effective date where material;
- distinguish legal text from guidance;
- state the UbID contribution separately from residual institutional obligations;
- avoid asserting certification, registration, or legal recognition without current evidence;
- maintain a research cut-off and next review trigger;
- route unresolved legal questions to qualified local review.