Digital identity services in Bermuda

Published: 5 Dec 2024
Type: Insight

There is steep demand for the ability to authenticate a person’s identity through the use of a trusted repository of their digital information.


In response to that growing demand, the Bermuda Monetary Authority has taken a first and vital step towards the regulation of digital identity service provider businesses in Bermuda.

On November 22, the island’s financial services regulator published proposals and a request for feedback on this topic titled Consultation Paper: Regulation of Digital Identity Service Provider Business.

The DISP consultation provides an extremely conscientious and thoughtful proposal for a DISP licensing regime and discussion of many of the issues that other regulators of DISP businesses must grapple with.

These include qualifying technical service standards, cybersecurity risk management, compliance with privacy law, the complications for DISP outsourcing and related authority for continuing oversight and enforcement.

In a concerted effort to seek the guidance and advice of all potential stakeholders and the public the BMA seeks to protect, the DISP consultation asks 18 specific and probative questions that focus on some of the more challenging aspects of its regulatory proposals.

Some of those questions assume a detailed knowledge of how digital ID systems work across multiple participants.

For example, question 11: “Do you think (regulated financial institutions) should adapt their online services to accept digital ID logins to access their proprietary systems, thus unlocking the convenience of ‘single sign-on’ for digital ID users?”

The more feedback and advice that the BMA can receive on this much needed initiative, the better and faster the solution will arrive to cure the present quagmire of incessant and time-consuming demand for “know your customer” personal information and related manual identity verification materials.

Moves in the direction of digital identity verification by governments, inter-governmental bodies and the private sector have been going on for about 35 years.

In 1989, the G-7 created the Financial Action Task Force as an independent inter-governmental body to promote countermeasures and policies necessary to address the growing global concern about money laundering, terrorist financing and the proliferation of weapons of mass destruction.

In the decades that followed, many governments around the world ventured into the realm of identity verification, including early attempts in Canada to merge driving licences and health ID cards into “smart cards” that would allow biometric access to a consolidated database for ease of online access and identity verification.

In March 2020, as a reflection of IT advances in data management, FATF published its Guidance on Digital Identity to promote the creation, adoption and regulation of digital ID systems that can be used and relied upon to securely, quickly and efficiently identify persons who are low-risk participants in global finance, investment and corporate management.

One of the most important recommendations of the GDI was for governments to create a “digital ID assurance framework” for the assessment, certification and continuing regulatory oversight of reliable digital identification service providers.

Certainly, the demand for one-stop identity verification services is rapidly increasing because regulators, regulated entities, individuals and corporations must constantly spend huge amounts of management time and expense verifying either their own identity to others or verifying the identity of those with whom they wish to do business or regulate.

The GDI was generally agnostic about how any combination of digital identity services might be configured to achieve those ends, and many jurisdictions around the world have (before and after the GDI) launched a wide range of digital ID systems.

Some are governmental, some are offered as public-private sector partnerships, and other jurisdictions have created regulatory regimes for the certification of trusted, private sector DISPs.

In 2022, Britain launched its own GDI initiative called the UK Digital Identity & Attributes Trust Framework, which seeks to encourage the launch of private sector digital identity solutions to meet those market demands.

Under the supervision of an Office for Digital Identities and Attributes, the UK DIATF defines the rules, standards and governance oversight for all DISPs.

The UK DIATF includes a certification regime to provide the public with assurance that the digital identity services they subscribe to will be secure, reliable and will be administered under the watchful eye of the Office for Digital Identities.

Kudos to the BMA for this recent initiative, and I hope that all other public policy and regulatory reform in Bermuda will follow the BMA’s thoughtful consultative lead.

First Published in The Royal Gazette, Legally Speaking column, December 2024

Share
More publications
Appleby-Website-Private-Client-and-Trusts-Practice-1905px-x-1400px
13 Mar 2026

A will trust can keep a home in the family

In Bermuda, a family homestead represents more than financial value; it embodies ancestral heritage and housing security.

Appleby-Website-Employment-and-Immigration
12 Mar 2026

Privacy at Work: What PIPA Means for Bermuda Employers

The Personal Information Protection Act 2016 (PIPA), which came into force on 1 January 2025, represents Bermuda’s first comprehensive date protection regime. The legislation regulates the collection, use, disclosure and storage of personal information with the objective of protecting individuals’ privacy while allowing organisations to use data in a responsible and transparent manner. PIPA applies broadly to organisations operating in Bermuda, including employers. As a result, the employment relationship is one of the contexts in which the practical impact of PIPA is the most significant. Employers routinely process large volumes of personal information relating to employees and job applicants, and PIPA imposes obligations that affect recruitment, workplace monitoring, record-keeping, and disciplinary processes.

IWD website preview
9 Mar 2026

International Women’s Day 2026 Roundtable: Rights. Justice. Action. For all women and girls.

As we recognise International Women’s Day 2025, we are reminded that gender equality is not just a vision – it’s a call to action.

Dispute Resolution
4 Mar 2026

Bermuda: An Overview of Insurance: Contentious

There has been a recent increase in policyholder disputes involving coverage challenges by (re)insurers in the context of Bermuda high-value, excess-of-loss policies. This is, in part, due to Bermuda’s commercial (re)insurers facing a marked and sustained rise in the volume of claims, incurring claims costs globally of BMD1.1 trillion from 2016 through 2024. The massive volume and quantum of claims can be attributed in part to the significance of the Bermuda (re)insurance market in the global economy, as well as Bermuda’s exposure to catastrophic losses caused by natural disasters over this period. Bermuda’s increased exposure to global (re)insurance risks has naturally resulted in an increase in complex claims and coverage disputes.

Employment-and-Immigration
27 Feb 2026

Pay transparency heading Bermuda’s way?

The culture of secrecy with respect to pay traditionally found in workplaces may soon experience a shift, as global lawmakers and governments have enacted or moved toward enacting legislation to mandate greater pay transparency.

Appleby-Website-Insurance-and-Reinsurance
27 Feb 2026

Bermuda Monetary Authority: Modern, Thoughtful and Competitive

The Bermuda Monetary Authority (BMA) has signaled a clear direction for the future of insurance supervision in Bermuda by the release of its latest Notice on Regulatory Burden Reduction for Better Policyholder Outcomes (Notice).

Appleby-Website-Banking-and-Asset-Finance-1905px-x-1400px
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Banking

Bermuda is not considered an international banking center and only banks licensed by the Bermuda Monetary Authority (BMA) under the Banks and Deposit Companies Act 1999 (BDCA) are entitled to undertake banking businesses in or from Bermuda. As banking is defined as deposit taking (as opposed to lending), international banks are generally able to lend to Bermuda-based borrowers subject to applicable restrictions relating to carrying on business in Bermuda.

Appleby-Website-Insurance-and-Reinsurance
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Insurance (Captives)

Bermuda is one of the leading captive insurance markets in the world with over 600 registered captive insurers writing an impressive ~$30 billion of annual gross written premiums.

Appleby-Website-Corporate-Practice
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – General Corporate

The Bermuda Monetary Authority (BMA), an independent body that has been in existence since 1969, is an integrated regulator and supervisor responsible for the licensing, supervision and regulation of financial institutions in Bermuda. The BMA’s mandate includes entities conducting insurance, deposit taking, investment and trust business. The BMA conducts risk-based supervision and enforcement, including enforcing anti-money laundering and counter-terrorist financing standards. The BMA sets prudential rules, issues codes of conduct and devises industry guidance to ensure the jurisdiction adheres to international standards.

Appleby-Website-Insurance-and-Reinsurance
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Insurance (Commercial)

The Bermuda Monetary Authority’s (BMA) 2026 Business Plan (Plan) outlines continued strengthening of Bermuda’s position as a leading global insurance and reinsurance jurisdiction.