{
  "d": "EA5O9z0TB932sm8kJIVdAIpwLpEWRWC5--VNS5r69frn",
  "purposeLimitation": "A verifier or relying party MUST process disclosed attributes only for the specific, relying-party-defined purpose disclosed to the holder at the time of presentation, and MUST NOT retain them longer than necessary for that purpose (Utah Code 63A-20-501, 63A-20-702).",
  "chainLinkConfidentiality": "A verifier or relying party MUST NOT assimilate, aggregate, correlate, sell, or otherwise combine disclosed attributes -- including with information collected by independent means before, during, or after the presentation -- for any purpose beyond the disclosed purpose. This binds each downstream recipient reached through the edge section of a presentation.",
  "dataMinimization": "A verifier MUST request and process only the minimum attributes necessary for the disclosed purpose, and MUST honor the holder's selective disclosure -- including proof of a minimum age without the birth date -- rather than requiring fuller disclosure (63A-20-301(1)(e), 63A-20-501).",
  "dutyOfLoyalty": "The department, wallet providers, verifiers, relying parties, and digital guardians MUST refrain from any processing that conflicts with the best interests of the individual, exploits them, imposes a disproportionate risk, operates to their detriment, or causes harm (63A-20-701).",
  "noSurveillance": "No party may use a SEDI presentation, or any artifact derived from it, to enable monitoring, surveillance, profiling, tracking, or persistent correlation of the holder's assertions of identity (63A-20-101(10), 63A-20-301(3)).",
  "acceptGuardianPresentation": "A verifier or relying party MUST accept a presentation made by an authorized digital guardian on a holder's behalf on the same terms as one made by the holder directly (63A-20-401, 63A-20-501, 63A-20-601).",
  "noDeviceSurrender": "No party may require the holder to surrender the secure device holding the SEDI credential in order to present it (63A-20-101(11), 63A-20-501, 63A-20-601).",
  "consentAndNotice": "A verifier or relying party may process attributes only with the holder's authorization and conspicuous, contemporaneous notice of the purpose (63A-20-401, 63A-20-501, 63A-20-702).",
  "respectRevocation": "A verifier MUST check credential status and MUST NOT rely on a SEDI credential the issuer has revoked; the department may revoke only on the statutory grounds -- compromise, issuance in error or by fraud, or holder request (63A-20-301(5)).",
  "safeHarbor": "By accepting a presentation governed by this framework -- a signed IPEX agree referencing the presentation's SAID -- a verifier elects the safe harbor of Utah Code 63A-20-701, conditioned on compliance with the purposeLimitation and chainLinkConfidentiality clauses. Breach forfeits the safe harbor and constitutes evidence under 63A-20-801.",
  "noOverAssertion": "A holder MUST NOT present a SEDI credential to assert a fact it does not endorse; the state endorses only name, birth date, image, and Utah residence address (63A-20-301(2)(f)), and derived credentials assert only their stated claim."
}
