Bhutan NDI
— Governance

The Governance Framework

Bhutan NDI Governance Framework is a family of legislative documents. The National Digital Identity Act of Bhutan 2023 is the mother of legislation for the framework.

In force 2023-07-2413 chapters · 160 sections
01

Bhutan NDI Act

Bhutan NDI Governance Framework is a family of legislative documents. The National Digital Identity Act of Bhutan 2023 (NDI Act 2023) is the mother of legislation for the NDI Governance Framework. NDI Act 2023 is a historic act passed by the parliament of Bhutan and subsequently granted Royal Assent by His Majesty The King. The Act empowers and also details the roles and functions of entities utilising the NDI ecosystem. Granular roles and functions are detailed in the NDI Governance Framework documents as empowered to do so by the Act.

— The full Act
National Digital Identity Act of Bhutan 2023

Dzongkha and English in one PDF. Each text is equally authoritative; where the two differ in meaning the courts reconcile them.§160

Download PDF
02

Purpose & application

The Act came into force on 24 July 2023. Its stated purposes:§2, §4

Provide for a National Digital Identity Infrastructure that is innovative
Encourage the use of digital credentials or data
Support digital trust between Issuers, Holders and Verifiers
Achieve environmental, social, governance and sustainability objectives
Enhance privacy and security of digital credentials and data

It applies to the Governing Body and Administrative Body, Issuers, Holders and Verifiers, Trust Service Providers, and all digital credentials and data recognised under it — extending beyond Bhutan's territorial jurisdiction.§3

03

Institutional framework

The Act separates approval from operation across two bodies.Chapter 2

Governing Body
Five members — approval and oversight

The head of the Government Technology Agency, two civil servants nominated by the Lhengye Zhungtshog, and two independent members nominated by GovTech. The Chairperson is elected from among the members; a term runs four years and is renewable.

Approves the Governance Framework and the Infrastructure, monitors the Administrative Body's compliance, approves on-boarding and registration regulations, and recognises foreign electronic identification schemes.

§5–§10
Administrative Body
The National Digital Identity Company

Develops and implements the Governance Framework and the operational infrastructure, registers and regulates Trust Service Providers, operates or directs Trust Registries, guides entities on credentials and data, and monitors compliance. Its head serves as non-voting Member Secretary of the Governing Body.

§11–§13
04

What the framework specifies

The Administrative Body submits the Governance Framework to the Governing Body for approval, which ensures it is aligned with national needs and consistent with recognised international standards.§14–§16

Standards & procedures

What public and private entities follow when providing or availing services.

Rights & obligations

Of every entity operating under the Act.

Credential schemes

The foundational credential, its use, and formats for digital credentials.

Collection & disclosure

Requirements governing the use and disclosure of credentials and data.

Trust services

The services to be provided by Trust Service Providers.

Conformance audit

Requirements for audit; the Governing Body appoints Auditors.§152

05

Interoperability & standards

The Infrastructure is technology-neutral: any implementation that meets the requirements of the Act qualifies. The Governing Body directs the use of open public specifications from globally accepted standards bodies, and publishes its own specification only where no open standard exists.§19–§24

A decentralised public key infrastructure removes dependency on a central authority, supports decentralised identifier methods with cryptographic agility, and produces certificates with the same legal effect as those from a qualified Certificate Authority.§30–§38

06

Privacy, residency & security

Globally accepted information security and privacy assurance standards apply to all credentials and data under the Act.§61–62
Every party handling data — including Verifiers, Trust Service Providers, Guardians and Controllers — is accountable for its secrecy.§63
The Infrastructure is designed so credentials and data can reside within the jurisdiction of Bhutan.§115
Identity fraud and cyber-security incidents must be notified to the Administrative Body within the period set by the Governance Framework.§118
Credentials and data are portable between Digital Wallets and their associated Agents.§66
07

Offences & penalties

Chapter 12 grades offences against the Infrastructure.§131–§146

Damaging the National Digital Identity InfrastructureFelony · 3rd degree
Tampering with Trust RegistriesFelony · 3rd degree
Unauthorised interception of digital credentialsFelony · 4th degree
Unlawful disclosure of credentialsFelony · 4th degree
Identity theftFelony · 4th degree
Deliberate interferenceMisdemeanour
Non-conformance to the on-boarding processPetty misdemeanour
08

Chapters of the Act

01Preliminary
02Institutional Framework
03Governance Framework, Interoperability & Policies
04Decentralised Public Key Infrastructure
05Digital Credentials
06Digital Wallets & Digital Agents
07Trust Service Providers
08Certification & Revocation
09Digital Guardianship & Controllership
10Data Residency & Information Security
11Cross-Border Recognition
12Offences & Penalties
13Miscellaneous

Questions about the framework? Contact the Bhutan NDI team.