Join our mission
Be part of the future of digital democracy with quality data shared as a raw material.
About ID Exchange
ID Exchange is an Australian digital trust infrastructure company founded in 2015 to deliver the missing consent layer for the global digital economy. Through its Human Data Agency model, proprietary IP portfolio centred on the Opt In® and Opt Out® trademark instruments, and its ConsentPort™ verified consent gateway, the company enables trusted, standards-based consent to be securely issued, verified and managed across digital identity, AI and data-sharing ecosystems.
Positioned as neutral trust infrastructure rather than another identity provider, ID Exchange enables governments, enterprises and digital platforms to exchange data with confidence by automating compliant, machine-readable consent between individuals and data holders. This critical protocol fills the trust gap required to accelerate Digital Public Infrastructure, Smart Data and AI-driven data markets while giving individuals control over what data is shared, with whom, for what purpose and for how long.
Leadership
Joanne Cooper — Founder & Chief Executive Officer
Joanne Cooper founded ID Exchange in 2015 to lead in the field of privacy and consent technologies. Across four decades she has worked at the leading edge of emerging technology — including roles with Getronics, Optus, and Allianz — and has provided regulatory consultation to the UK, US, and Australian governments. She has attended several UK trade delegations since 2017 and is an active ambassador for digital democracy solutions.
Joanne is the daughter of Australian captain of industry Tom Cooper, who launched the first luggable computer and personal computer into the Australian market in the early 1980s — a heritage of technology pioneering she carries into her work on individual data sovereignty.
Her work has been widely recognised. She was named an OWI Top 100 Influencer in Identity, received the Women in Security Recognition Award as Australia's Most Outstanding Female in ICT in 2024, and was honoured with the AB+F Innovation Award. In 2026, ConsentPort was shortlisted by the UK Department of Trade Smart Data Forum.
Purpose
The MyID Consent proof of concept was established to help explore practical, standards-based approaches to digital identity and consent management within the Government sector for civic or sectoral use cases. Government discovery and pilots have focused on a range of core requirements including eSafety, Digital Assurance, Smart Data Ecosystems and Data Portability compliance in regions such as Australia, Europe and the MENA region.
Primary Objective
Demonstrate that individuals can control their own identity data — deciding what to share, with whom, and for how long — using open, interoperable standards rather than proprietary centralised systems.
Regulatory Context
All PoC's are designed to align with evolving digital identity regulatory frameworks. In Australia this includes the Digital Identity Act 2024, Privacy Act 1988, and the Consumer Data Right (CDR). We observe international laws such as the GDPR, CCPA and many others and PoC's are fully qualified to ensure pilots navigate and automate relevant laws in respect to the data owner and data controllers throughout the data access journey.
Vendor Evaluation
A structured shortlist of two leading vendors — Affinidi and Inrupt — has been developed to assess which platform best meets the technical, regulatory, and commercial requirements of a production deployment.
Stakeholder Engagement
This site serves as a secure briefing resource for internal stakeholders, executive sponsors, and invited external reviewers — providing a structured overview of the initiative and its findings.
The Problem We Are Solving
Today's identity and data sharing landscape creates systemic risk for individuals and institutions alike.
Fragmented Identity
Australians maintain dozens of separate digital identities across government, banking, health, and commercial services — each with its own credentials, data stores, and consent mechanisms. There is no unified, user-controlled identity layer.
Opaque Data Sharing
When individuals share data with financial institutions or government agencies, they typically have no visibility into how that data is used, stored, or shared onward. Consent is often buried in lengthy terms and conditions.
Excessive Data Collection
Organisations routinely collect more data than is necessary for the transaction at hand — creating unnecessary privacy risk and regulatory exposure under Australia's Privacy Act and the forthcoming Privacy Act reform.
No Audit Trail for Individuals
Individuals have no practical way to audit who has accessed their data, when, and under what authority. This makes it impossible to detect unauthorised access or enforce data deletion rights.
Vendor Lock-In
Proprietary identity platforms create dependency on single vendors — making it difficult for organisations to switch providers or for individuals to move their data between services.
Regulatory Compliance Complexity
Financial institutions must navigate overlapping regulatory requirements — AML/KYC, Privacy Act, CDR, Digital Identity Act — often with siloed, manual processes that create compliance risk and operational cost.
First look - Proof of Concept (PoC) programs
The MyID Consent solution was curated for a specific PoC and was built working with our elite local and Canberra based Software Engineering partner Hide and Seek Digital in association with Nexrupta to design a range of high-quality applications that maintains and reflects our four core design principles.
Open Standards First
All technical components are built on open, ratified standards — W3C Verifiable Credentials, Solid Protocol, DID (Decentralised Identifiers), and OpenID Connect. No proprietary lock-in at the protocol layer.
User Sovereignty
The individual is the authoritative source of their own identity data. Organisations request access; they do not hold copies. Consent can be granted, modified, or revoked at any time by the user.
Minimum Necessary Disclosure
Selective disclosure and zero-knowledge proof techniques ensure that only the specific data required for a transaction is shared — not entire identity profiles.
Regulatory Alignment
Every design decision is evaluated against Australia's regulatory framework — Privacy Act 1988, Digital Identity Act 2024, CDR, and AML/CTF Act — to ensure a production deployment would meet compliance requirements.
Australian Regulatory Framework
PoC's can be designed to operate within Australia's existing and emerging regulatory landscape or that of the client's requirements. As an example, we have listed the frameworks that apply for the Australian marketplace that have been aligned for local PoC programs.
Scope & Limitations (Pilot engagements)
✅ In Scope
- Technical architecture design and documentation
- Vendor evaluation — Affinidi and Inrupt
- Five-stage PoC workflow demonstration
- Regulatory alignment assessment
- Stakeholder briefing materials
- Open standards compliance review
⛔ Out of Scope
- Live production deployment
- Real customer data or PII
- Legal or compliance sign-off
- Procurement or vendor contracting
- Integration with existing core banking systems
- Security penetration testing
⚠️ Important: This proof of concept is for evaluation and discussion purposes only. It does not constitute legal, compliance, or procurement advice. All regulatory assessments should be independently verified by qualified legal and compliance professionals before any production deployment is undertaken.
Proposed Next Steps
Subject to stakeholder review and approval, the following phases are proposed following PoC evaluation.
PoC Evaluation — Current
Stakeholder review of this briefing site. Vendor demonstrations from Affinidi and Inrupt. Technical architecture review. Regulatory alignment assessment.
In ProgressVendor Selection & Pilot Design
Select preferred vendor based on PoC evaluation. Design pilot scope with real (but limited) user cohort. Engage legal and compliance for regulatory sign-off. Establish data governance framework.
PlannedControlled Pilot
Deploy pilot with selected vendor. Onboard limited user cohort. Measure against defined success criteria. Engage AUSTRAC and OAIC as appropriate for regulatory guidance.
PlannedProduction Readiness Assessment
Security penetration testing. Full regulatory compliance review. Integration architecture with core systems. Business case development for board approval.
PlannedExplore the Full PoC
Review the five-stage proof of concept walkthrough or dive into the vendor briefs.