Consultation Paper
Consultation Paper - Regulation of Digital Identity Service Provider Business (2024-11-22)
DraftView on BMA's website Source document
Summary
This is a Bermuda Monetary Authority consultation paper proposing a new licensing and supervisory regime for Digital Identity Service Providers (DISPs) that would issue and manage non-governmental digital identities for individuals. It sets out the rationale, proposed scope, and draft requirements that would be enacted through a new Digital Identity Service Provider Act (DISPA), and invites industry feedback before the framework is finalised.
Proposed regulatory elements
- Licensing: DISPs operating in or from Bermuda would need to be licensed by the BMA and meet minimum licensing criteria, including fitness of controllers, shareholder controllers, directors and officers.
- Senior representative and principal office: Licensed DISPs would be required to maintain a senior representative and a principal office in Bermuda.
- Risk and cyber risk management: DISPs would need robust risk management frameworks, with specific cyber risk management requirements given the sensitivity of identity data.
- Insurance: DISPs would be required to hold insurance or similar arrangements to cover operational risks.
- Consent and privacy: DISPs would need to implement consent and privacy safeguards for users' personal and identity data.
- Outsourcing and conduct of business: Proposed rules would govern outsourcing arrangements and general conduct of business standards for DISPs.
- Prudential returns and supervision: DISPs would be subject to ongoing prudential reporting and BMA supervisory review, including on-site and off-site inspections.
- BMA powers: The Authority would gain powers to obtain information, issue directions, impose conditions or restrictions, and revoke licences, plus enforcement powers including civil penalties up to $2,500,000 per breach, public censure, prohibition orders and injunctions.
- Consequential amendments: The Bermuda Monetary Authority Act 1969 and AML/ATF Guidance Notes would need amendment to incorporate DISP business and support use of Digital IDs by regulated financial institutions.
As a consultation paper, none of these proposals are yet binding law; they represent the BMA's proposed approach pending industry feedback and subsequent legislative enactment of the DISPA. Stakeholders are invited to submit comments and suggestions to the Authority.
Key obligations
- Interested stakeholders must submit comments and feedback on the proposed DISP regulatory regime to policy@bma.bm by 10 January 2025.
- Once enacted, entities wishing to provide digital identity services in or from Bermuda would be required to obtain a licence from the BMA and satisfy minimum licensing criteria.
- Licensed DISPs would be required to maintain a senior representative and principal office in Bermuda.
- Licensed DISPs would be required to implement risk management, cyber risk management, consent and privacy, and outsourcing controls, and to submit prudential returns to the BMA.
- Licensed DISPs would be required to hold insurance or similar arrangements against operational risk.
- Licensed DISPs would be required to comply with BMA directions, conditions, and restrictions, and to report accurately to the Authority, with false or misleading statements constituting a criminal offence under the proposed DISPA.
Applies to
Digital Identity Service Providers (DISPs), AML/ATF Regulated Financial Institutions (RFIs), Digital Asset Business (DAB) sector participants
Deadlines
- 10 January 2025: Deadline for submitting comments and suggestions on the Consultation Paper to the BMA at policy@bma.bm.