---
title: "Approval to participate in the AGDIS form"
source: "https://www.digitalidsystem.gov.au/sites/default/files/2024-11/digital_id_-_forms_-_approvals_form.pdf"
collection: "digital-id-accreditation"
guidance_commit: "db3111cd9d11643ac08b34b4d75b0d0d983ca388"
---

         Approval to participate in AGDIS form
            Warning: It is a serious criminal offence under the Commonwealth Criminal Code to
            provide false or misleading information. False or misleading information in an
            application (including a material omission) may also be grounds to revoke any approval
            granted based on that information.


         Personal information

         Some of the information you provide in your application for approval to participate in the
         Australian Government Digital ID System (AGDIS) may constitute personal information for the
         purposes of the Privacy Act 1988 and the Digital ID Act 2024. This notice is intended to inform
         you of matters related to our collection of personal information contained in your application
         and should be read in conjunction with the ACCC’s Privacy Policy.

         Why we are collecting personal information

         Information, including any personal information, contained in your application is being
         collected by the ACCC as the Digital ID Regulator for the purposes of:
            •   assessing your application for approval to participate in the AGDIS in accordance with
                the Digital ID Act 2024; and
            •   administering, and otherwise facilitating the proper functioning of the Digital ID Act
                2024.

         What happens if you do not provide requested personal information.

         If you do not provide personal information relevant to your application for approval to
         participate in the AGDIS, that may impact our ability to assess your application.

         Whom we may disclose personal information to

         Information contained within AGDIS approval applications, including personal information,
         may be disclosed to:
            •   other Commonwealth agencies (for example, the Office of the Australian Information
                Commissioner and Services Australia in their capacity as the System Administrator);
            •   State and Territory police forces;
            •   international regulators and law enforcement bodies;
            •   external consultants engaged by us

         to assist our assessment of AGDIS approval applications.

         The information, including any personal information, contained in AGDIS approval applications
         is collected, and stored on servers, in Australia, in a secure environment. As above, personal
         information contained in AGDIS approval applications may be disclosed overseas to relevant


Page 1
         international regulators and law enforcement bodies to assist our assessment of AGDIS
         approval applications.

         Information about how to access your personal information, how to correct your personal
         information and how to complain about our handling of your personal information (and how
         we’ll deal with such a complaint) is set out in the ACCC’s Privacy Policy.

         By ticking the box below, you confirm that you have obtained the consent of any individual to
         whom personal information contained in your AGDIS approval application relates to disclose
         their personal information to the ACCC (as the Digital ID Regulator) to be collected, used and
         disclosed for the purposes set out above.

         ☐ Yes


         Screening check
         ☐ If your organisation is applying to become an Accredited Entity in the AGDIS, it must
           receive accreditation before approval can be granted.

         ☐ Your organisation must be an eligible entity type to participate.

         ☐ I acknowledge that my organisation must comply with all Digital ID legislation including the
           Digital ID Act 2024, Digital ID Rules, the Accreditation Rules, the Digital ID Data Standards
           and the service levels relevant to your organisation's approval to participate.

         ☐ Your organisation must commence participating in the AGDIS on its participation start
           date.

         Before applying, your organisation must have plans and procedures in place relating to its
         participation in the AGDIS for the following:

             ☐ Effective written procedures to notify the System Administrator promptly of planned or
               unplanned outages or downtime affecting your organisation's IT system where these
               will or could be reasonably expected to have a material effect on the operation of the
               AGDIS.

             ☐ Effective written procedures to notify the System Administrator promptly of planned or
               unplanned outages which may have material effects on the operation of the AGDIS.

             ☐ Cyber security plan (includes conducting a risk assessment)

             ☐ Digital ID fraud management plan (includes conducting a risk assessment)

             ☐ Disaster recovery and business continuity plan

         ☐ I acknowledge my organisation is responsible for the operation of the service(s) in the
           AGDIS, including providing contact information and responding to any event.


Page 2
         Address for notices

         Does the organisation consent to notices and other documents under the Digital ID framework
         being given by email?
               Yes                 No

         What is the email address which may be used to give the organisation any notice or other
         document under the Digital ID framework by email?


         What is the physical address which may be used to give the organisation any notice or other
         document under the Digital ID framework?


         What is the postal address which may be used to give the organisation any notice or other
         document under the Digital ID framework?


Page 3
All items marked with an asterisk * are mandatory.


           Application information

           1. What type of provider is your organisation applying for approval to participate in the AGDIS?*
              Select one only:

                 Attribute provider (ASP)

                 Exchange provider (IXP)

                 Identity provider (ISP)

                 Participating Relying Party (PRP)


           2. What type of entity is your organisation?*
              Select one only:

                 Non- corporate Commonwealth entity

                 Commonwealth company

                 State or Territory Government entity

                 None of the above


                       Participation in the AGDIS is being phased. Please refer to the Digital ID
                              legislation to check if your organisation is eligible to apply.

           3. What service(s) is your organisation seeking to be approved?*


                             If applying to participate in the AGDIS as an Accredited Entity
                             (Attribute provider, Exchange provider or an Identity provider),
                                               go to question 4 on page 5.

                                If applying to become a Participating Relying Party, go to
                                                  question 15 on page 7.


  Page 4
         Accredited Entities - Service details

         4. Does your organisation intend to offer this accredited service outside the AGDIS?*
                Yes              No


         5. Has your organisation engaged with the Office of the System Administrator to conduct
         testing for this service?*

                Yes              No

         6. If yes, what is the Key Identifier provided by the Office of the System Administrator for this
         service?*


         Accredited Entities - Conditions
               Your organisation's application for approval will include any conditions applied to
                                                its accreditation.

         7. Does your organisation wish to make changes to your organisation's accreditation
         conditions?*
                Yes              No

                      To change your organisation’s accreditation conditions, please
                       complete the Conditions on Accreditation and Approval Form.

         8. Does your organisation wish to apply for an approval condition?*
                Yes              No


         9. Select whether the condition request relates to your service type or a service.*

                Service          Service Type

         10. If service, advise which service.*


         11. Describe the detail of the condition sought to be imposed.*


Page 5
         12. Why is the condition being sought?*


         13. Select the desired day of effect for the condition to be imposed, if any.


         14. Select the desired day when the condition will cease to be imposed, if any.


         Upload any other documents relevant to your application for this condition.


         Accredited Entities - Plans and procedures

         Sign and upload the Plans and procedure declaration for accredited entities seeking
         approval to participate in the AGDIS.*

         Upload any other documents relevant to your organisation's application.


               The Plans and procedures declaration for accredited entities seeking approval to
              participate in the AGDIS form to be downloaded from the Digital ID System website
                                  and must be attached with your application.


                                    Go to All entities - Declarations on page 12.


Page 6
     Participating Relying Party - Service details

                                 Repeat questions 15 - 19a for each service
                                your organisation is seeking to be approved.


     15. Who owns the service?*


     16. Are other organisations responsible for the delivery of the service?*
             Yes              No

     16a. If yes, who are the other organisations?*


     16b. If yes, what are their roles?*


     17. Will the service access the AGDIS directly or via another service?*
             Directly           Via another service

     17a. If via another service, which service?*


     18. Is the service only accessible using digital ID?*
              Yes             No

     18a. If yes, does the service meet an exception to the voluntariness requirements?
     Please provide details.*


Page 7
     18b. If no, provide the details of the other access methods (other than digital ID).*


         19. Has your organisation engaged with the Office of the System Administrator to conduct
         testing?*

                 Yes            No


     19a. If yes, what is the Key Identifier provided by the Office of the System Administrator for
     this service?*


     Participating Relying Party - Conditions

     20. Does your organisation wish to apply for a condition?*

                Yes             No


                                   If yes, repeat the following questions for each
                               condition your organisation is seeking to be approved.

                                         If no, go to question 40 on page 12.


     21. Select whether the condition request relates to your service type or a service.*
                Service        Service Type

     22. If service, which service?


     23. Select the condition your organisation is seeking to be imposed.*
             Other         Restricted attributes


                          If the condition relates to Restricted attributes, go to question 24
                                                       on page 9.

                          If the condition relates to Other, go to question 35 on page 11.


Page 8
         Applying for restricted attributes

         24. Select the kind of restricted attribute your organisation is seeking to collect and/or
         disclose.* Select one or more:

                Health information (within the meaning of the Privacy Act 1988) about an individual.
                An identifier of an individual that has been issued or assigned by or on behalf of the
                Commonwealth, a State or Territory, an authority or agency of the Commonwealth, a State or
                Territory, or a government of a foreign country.

                Information or an opinion about an individual's criminal record.

                Information or an opinion about an individual's membership of a professional or trade association.
                Information or an opinion about an individual's membership of a trade union.

                Other information or opinion that is associated with an individual and is prescribed by the
                Accreditation Rules.

         25. Specify which restricted attribute your organisation is seeking to collect and/or disclose.*


         26.Is your organisation is seeking to collect and/or disclose a restricted attribute?*
         Select one only.
                 Collect          Disclose         Collect and disclose

         27. Provide justification as to why your organisation is seeking to collect and/or disclose
         the restricted attribute.*


Page 9
          28. Explain why a similar outcome cannot be achieved without collecting and/or disclosing the
          restricted attribute.*


          29. Is the collection or disclosure of the restricted attribute regulated by other legislative or
          regulatory requirements?*

                   Yes               No


          30. If yes, what specific legislation or regulatory requirements apply?*


          31. How would your organisation comply with those regulatory requirements if the condition to
          collect and disclose the restricted attribute is granted?*


          32. When considering whether to impose a condition relating to restricted attributes, the Digital
          ID Regulator must consider the potential harm that could result if the restricted attributes were
          disclosed to an entity that was not authorised to collect them and the community expectations
          as to whether the restricted attributes must be handled more securely than other kinds of
          attributes. Your organisation may provide any information it considers relevant to the Digital ID
          Regulator’s consideration of these matters.


Page 10
          33. If granted, will your organisation disclose the restricted attribute outside the AGDIS?*
                   Yes                No


          34. If yes, provide further information including the circumstances the restricted attribute will
          be provided and to whom.*


          Applying for other conditions

          35. Describe the detail of the condition sought to be imposed.*


          36. Why is the condition being sought?*


          37. Select the desired day of effect for the condition to be approved, if any.


          38. Select the desired day when the condition will cease to be imposed, if any


          Upload any other documents relevant to your application for this condition.


Page 11
      Participating Relying Party - Exemption forecasting

      39. If approved to participate in the AGDIS, will your organisation be seeking an exemption from the
      voluntariness requirements?*

              Yes                 No                Unsure


      40. If yes, please provide details of why your organisation intends to seek an exemption, which
      service would be seeking the exemption, details of the service(s) that would be impacted and why
      your organisation considers an exemption to be appropriate in the circumstances.*


      Participating Relying Party - Appropriateness

      Please upload the relevant forms and associated evidence to help us assess whether, in light of the
      objectives of the Digital ID Act, it is appropriate to approve the organisation. Please refer to the
      Digital ID Regulator's guidance for the template forms and more information.*


      Participating Relying Party - Plans and procedures

      Sign and upload the Plans and procedures declaration for relying parties applying to participate in the
      AGDIS.*
             The Plans and procedure declarations for relying parties applying to participate in the
            AGDIS from to be downloaded from the Digital ID System website and must be attached
                                           with your application.

      Upload any other documents relevant to your application.


      Review and submit application (all entities)
      Sign and upload the Declaration for compliance for all entities applying to participate in the AGDIS.*

      Sign and upload the Final declaration for all AGDIS applications.*


             Please attach signed declaration. All declarations can be downloaded from the Digital ID
                                         System website and uploaded.


Page 12
