Better Identity Coalition Floats 'Rules of the Road' for Verifiable Credential Data Requests

Silhouettes of multiple human figures overlaid with green digital data points and connecting lines, representing concepts like biometric identification, data privacy, or mass surveillance through technology.

The Better Identity Coalition has circulated a draft voluntary code of conduct—framed as “rules of the road”—meant to influence how organizations request and use data from verifiable digital credentials. The proposal is positioned as an early attempt to discourage overly broad or invasive information requests as verifiable credentials move closer to everyday use.

On the Center for Cybersecurity Policy and Law’s account, the document is presented as a “straw man” for the ecosystem to react to, with expectations aimed at credential issuers, wallet providers, and relying parties. The underlying idea is familiar: even when selective disclosure is technically possible, real-world implementations can drift toward data maximalism unless there are shared norms about what should and should not be requested.

That matters for mobile identity because verifiable credentials are often sold as a way to present a narrow claim—for example, an age threshold—without exposing a full identity record. The model is central to many digital wallet strategies and is reflected in rollouts such as Telefonica Tech’s self-sovereign identity launch.

In the United States, credential-request norms also intersect with state-issued identity as agencies explore digital versions of driver’s licenses and other government credentials. The coalition has previously pushed for state motor vehicle agencies to serve as key trust anchors, including in the coalition’s Blueprint for State Policymakers.

The timing also overlaps with broader work on wallet trust and interoperability. Industry efforts such as FIDO Alliance’s Digital Credentials Initiative are pushing into credential policy and certification questions, while investment continues in decentralized identity infrastructure, including NEC X’s investment in Indicio.

For mobile wallet builders, a voluntary “rules of the road” document is less about legal enforceability than about product defaults and procurement expectations. If buyers start treating “responsible request behavior” as a requirement, it can influence verifier UX, what data fields are requested by default, how requests are explained to users, what is logged, and what recourse exists when a credential holder believes a request is inappropriate.

Sources: Center for Cybersecurity Policy and Law

By the Mobile ID World Editorial Team