---
title: "Conditions on accreditation or AGDIS approval form"
source: "https://www.digitalidsystem.gov.au/sites/default/files/2024-11/digital_id_-_forms_-_conditions_on_accreditation_and_approval.pdf"
collection: "digital-id-accreditation"
guidance_commit: "db3111cd9d11643ac08b34b4d75b0d0d983ca388"
---

         Conditions on Accreditation and AGDIS
         Approval Form
         This application form is for use by organisations that hold accreditation under the
         Accreditation Scheme or approval to participate in the Australian Government Digital ID
         System under the Digital ID Act 2024. This application form allows organisations to apply to
         the Digital ID Regulator for a condition to be imposed, varied or revoked. A separate form
         needs to be completed for each condition.


         Declaration
         I understand my organisation must comply with all relevant Digital ID legislation (such as the
         Digital ID Act 2024, the Digital ID Rules 2024, and the Digital ID (Accreditation) Rules 2024)
         and the conditions imposed by such legislation. I understand that it is for the Digital ID
         Regulator to decide on any application to the Digital ID Regulator to impose, vary or revoke a
         condition. I understand that my organisation must receive notice of a decision relating to a
         change, variation or revocation of a condition before being able to operate with that condition,
         or its variation or revocation.

              Yes


         Personal information collection notice
         Some of the information you provide in your application for a condition to be imposed, varied
         or revoked may constitute personal information for the purposes of the Privacy Act 1988 and
         the Digital ID Act 2024. This notice is intended to inform you of matters related to our
         collection of personal information contained in your application and should be read in
         conjunction with the ACCC’s Privacy Policy.

         Why we are collecting personal information

         The information, including any personal information, contained in your application is being
         collected by the ACCC as the Digital ID Regulator for the purposes of assessing your
         application to impose, vary or revoke a condition on your organisation’s accreditation under
         the Accreditation Scheme or approval to participate in the Australian Government Digital ID
         System.

         What happens if you do not provide requested personal information.

         If you do not provide personal information relevant to your application for a condition to be
         imposed, varied or revoked, that may impact our ability to assess your application.

         Whom we may disclose personal information to

         The information contained within condition applications, including personal information,
         may be disclosed to:


Page 1
         •    other Commonwealth agencies (for example, the Office of the Australian Information
              Commissioner and the Australian Security Intelligence Organisation);
         •    State and Territory police forces;
         •    international regulators and law enforcement bodies;
         •    external consultants engaged by us;

         to assist our assessment of accreditation applications.

     How your personal information is collected and stored

     The information, including any personal information, contained in applications for conditions
     to be imposed, varied or revoked is collected and stored on servers in Australia in a secure
     environment.

     Information about how to access your personal information, how to correct your personal
     information and how to complain about our handling of your personal information (and how
     we’ll deal with such a complaint) is set out in the ACCC’s Privacy Policy.

     By ticking the box below, you confirm that you have obtained the consent of any individual to
     whom personal information contained in your application relates to disclose their personal
     information to the ACCC (as the Digital ID Regulator) to be collected, used and disclosed for
     the purposes set out above.
             Yes


Page 2
  All items marked with an asterisk * are mandatory.

    1. Is your organisation seeking a condition to be imposed, varied or revoked?*

            Impose a condition                Vary a condition          Revoke a condition

  Imposing a condition
    2. Does the condition relate to your organisation's accreditation or AGDIS approval?*

             Accreditation                    AGDIS approval

   3. Select whether the condition relates to your service type or a service.*

             Service type                     Service


                             If the condition relates to service type, go to question 4.
                               If the condition relates to a service, go to question 5.


   4. Select the service type the condition relates to.*

         Select one

   5. Advise which service the condition relates to.*


   6. Select the condition sought to be imposed.*

         Select one

  Vary or Revoke a Condition
    7. Select the condition category to be varied or revoked?*
         Select one


    8. Select the condition sought to be varied or revoked.*


                   If the condition relates to Restricted Attributes, go to question 9 on
                                                   page 4.

                              All other Conditions, go to question 24 on page 8.

                  If the conditions relate to Services the entity is approved to provide, or
                     provide access to, within the AGDIS, go to question 28 on page 9.


Page 3
  Restricted Attributes

    9. Select the kind of restricted attribute your organisation is seeking to collect and/or
       disclose.*

            Health information (within the meaning of the Privacy Act 1988) about an individual.
            An identifier of an individual that has been issued or assigned by or on behalf of the
            Commonwealth, a State or Territory, an authority or agency of the Commonwealth, a
            State or Territory, or a government of a foreign country.

           Information or an opinion about an individual's criminal record.

            Information or an opinion about an individual's membership of a professional or
            trade association.
            Information or an opinion about an individual's membership of a trade union.
            Other information or opinion that is associated with an individual and is prescribed
            by the Accreditation Rules.

    10. Specify which restricted attribute your organisation is seeking to collect and/or disclose.*


    11. Is your organisation seeking to collect and/or disclose a restricted attribute.*
        Select one only.

            Collect          Disclose          Collect and disclose


                  Question 12 - 23 are applicable for conditions on accreditation.

          Question 16 - 20 are only applicable for participating relying parties seeking to
                      disclose or collect and disclose a restricted attribute.


Page 4
    12. List the relying party or relying parties your organisation is seeking to disclose a
        restricted attribute to.*


    13. Outline the arrangements in place between your organisation and each relying party
        (not including participating relying parties) to ensure the protection of the restricted
        attribute(s) from further disclosure.*


    14. Is your organisation seeking to disclose a restricted attribute to an entity outside
        the Australian Government Digital ID System?*

                 Yes             No


    15. Specify which entity or entities you seek to disclose a restricted attribute to.*


Page 5
    16. Provide justification as to why your organisation is seeking to collect and/or disclose
        the restricted attribute.*


    17. Explain why a similar outcome cannot be achieved without collecting and/or disclosing the
        restricted attribute.*


    18. Is the collection or disclosure of the restricted attribute regulated by other legislative or
        regulatory requirements?*

              Yes               No

  18a. If yes, what specific legislation or regulatory requirements apply?*


    19. How would your organisation comply with the legislative or regulatory requirement(s) if
        the condition is imposed?*


Page 6
     20. When considering whether to impose a condition relating to restricted attributes,
         the Digital ID Regulator must consider the potential harm that could result if the
         restricted attributes were disclosed to an entity that was not authorised to collect
         them and the community expectations as to whether the restricted attributes must
         be handled more securely than other kinds of attributes. Your organisation may
         provide any information it considers relevant to the Digital ID Regulator’s
         consideration of these matters.


     21. Provide your organisation's risk assessment plan as it relates to the restricted
         attribute.*

     22. Provide your organisation's privacy impact assessment as it relates to the restricted
         attribute.*

     23. Provide your organisation's protective security (including security governance,
         information security, personnel security and physical security), privacy arrangements
         and fraud control arrangements as it relates to the restricted attribute.*
     Upload any other documents relevant to this application.


                                  Go to page 11 to sign the declaration.


Page 7
   All other conditions

     24. Describe the detail of the condition sought to be imposed, varied or revoked.*


     25. Why is the condition being sought? *


     26. Select the desired day of effect for the condition to be imposed, varied or revoked, if
         any.


     27. Select the desired day when the condition will cease to be imposed or varied, if any.


         Upload any other documents relevant to this application.


                                 The Digital ID Regulator may request further
                               information and evidence during the application
                                                 assessment.


Page 8
    Services the entity is approved to provide, or provide access to, within the
    AGDIS
         28. Is your organisation seeking to add, vary or remove a service?*

                              Add               Remove            Vary

         29. Specify the service


                                           If Add, go to question 30.
                                    If Remove, go to question 38, on page 10.


    Add a Service

         30. Who owns and administers the service?*


         31. Are other organisations responsible for the delivery of the service?*

                  Yes               No


         31a. If yes, who are the other organisations?*


         31b. If yes, what are their roles?*


         32. Will the service access the AGDIS directly or via another service?*

                   Directly           Via another service

         32a. If via another service, which service?*


Page 9
      33. Is the service only accessible using digital ID?

                 Yes                No

      34. If yes, does the service meet an exception to the voluntariness requirements?* Please
          provide details.


      35. If no, provide the details of the other access methods (other than digital ID).*


      36. Has your organisation engaged with the Office of the System Administrator to conduct
          testing?*

                Yes            No

      37. If yes, what is the Key Identifier provided by the System Administrator for this service?*


                                         Go to page 11 to sign the declaration.


    Remove a service

          38. Explain the reason for removing the service from accessing the AGDIS.*


          39. Outline any risks identified by your organisation with the removal of the service.*


          40. Has your organisation notified the Office of the System Administrator?*

                 Yes           No

          Upload any other documents relevant to this application.


Page 10
          Declaration

          I First name Last name        , Position                   of Organisation

          hereby declare that:
             •      I am authorised by my organisation to make the declarations contained in this
                    application;
             •      all information provided in this application form is true and complete; and
             •      I, and other authorised contacts, will continue to provide true and complete
                    information in relation to this application and any approval of this application, if
                    granted.
          I acknowledge that if I, or other authorised contacts, provide or have provided false or
          misleading information, including omission, that this may result in this application being
          denied or suspended until further notice, any approval being revoked, or in enforcement action
          being taken.


          Signed:                                                               Date:


Page 11
