Supplementary code for digital right to work checks (1.1)
Published 1 September 2026
0. Version and certification validity notes
0.a. This 1.1 publication of the supplementary code for digital right to work checks (‘the RtW supplementary code’) will come into force under section 29 of the Data (Use and Access) Act 2025 on the date the first conformity assessment body (‘CAB’) is accredited to certify against it, which will be no earlier than 1 September 2026. It replaces the 1.0 publication of the RtW supplementary code, which was published on 9 June. The 1.0 publication was due to come into force when the first CAB was accredited to certify against it and no earlier than 1 September 2026. However, the 1.0 publication will not come into force as no CAB has ever been accredited to certify against it and none will ever be accredited as such given this new version of the code has been published. This 1.1 publication reflects Home Office regulations, which, amongst other things, enable the use of expired passports during digital right to work checks and the use of holder services for the purposes of checks to confirm that an individual carrying out work or services is the same individual as the worker on whom a right to work check has been conducted.
0.b. The RtW supplementary code is published by the Office for Digital Identities and Attributes (‘OfDIA’), part of Department for Digital, Culture, Media and Sport (‘DCMS’). It sets out rules for digital verification services (‘DVS’) conducting right to work checks on holders of British and Irish passports or passport cards. OfDIA is responsible for the maintenance of this supplementary code.
0.c. To be certified against the RtW supplementary code, services will need to also be certified against a current publication of the UK digital verification services trust framework (formerly known as the ‘UK digital identity and attributes trust framework’).
0.d. The non-statutory gamma (0.4) version of the RtW supplementary code, published on 26 June 2025 and the statutory gamma (0.4) published on 1 December 2025 will remain valid for a limited period of time for the purposes of:
- certification, such that certificates issued against those versions will remain valid and any audit and surveillance in respect of those certificates are conducted against those versions as relevant, subject to 0.e below; and
- Part 2 of the Act (where relevant and where there exist certificates which are valid against them) such that references to supplementary code are to be read as references to the non-statutory gamma (0.4) and the statutory gamma (0.4) versions.
0.e. The statutory gamma (0.4) version of the RtW supplementary code is only to remain valid for new certifications following the coming into force date of this 1.1 RtW supplementary code in the circumstances below:
- The DVS applied for certification against the statutory gamma (0.4) RtW supplementary code before the day on which this 1.1 RtW supplementary code comes into force but the certification process had not been completed by that date, such that a certificate was issued by an accredited CAB after that date; or
- The DVS applying for certification, at the point at which they apply for new certification, holds a certificate confirming they comply with the requirements under the non-statutory gamma (0.4) or the statutory gamma (0.4) versions of the RtW supplementary code and the application is made by that DVS before the certificate expires and within 15 months of the day on which this 1.1 RtW supplementary code comes into force.
0.f. The non-statutory gamma (0.4) and the statutory gamma (0.4) versions of the RtW supplementary code referred to in 0.c will no longer apply for the purposes of certification and Part 2 of the Act, and certificates issued against them will expire and should be ignored for those purposes if any of the following apply:
- 27 months have elapsed since the day on which this 1.1 RtW supplementary code comes into force (including that day);
- a service uplifts to the 1.1 publication and has a certificate issued to confirm that;
- the service’s non-statutory gamma (0.4) or statutory gamma (0.4) certification against the RtW supplementary code expires; or
- the service’s non-statutory gamma (0.4) or statutory gamma (0.4) certification against the UK digital verification services trust framework expires.
Part 1 - Background and context
1. Introduction
1.a. This is the 1.1 publication of the RtW supplementary code for digital right to work checks. It sets out rules DVS must follow, and the recommendations they can follow, in order to be certified against the RtW supplementary code.
1.b. A DVS’s certification against the RtW supplementary code assures employers who choose to conduct digital right to work checks that they can use the service to help meet Home Office requirements and recommendations (for example, regarding the level of confidence or authenticator quality) for digital right to work checks for holders of British and Irish passports, or Irish passport cards.
1.c. Employers will also need to comply with requirements for digital right to work checks, set out in Home Office regulations and guidance to obtain and retain certain data from the DVS and to check that the individual whose identity was verified is the same person who presents themself for work.
1.d. This RtW supplementary code builds on the rules set out in the 1.0 version of the UK digital verification services trust framework the ‘trust framework’). DVS can only certify against this RtW supplementary code if they are certified against the trust framework.
1.e. Terms in this document are defined as set out in the trust framework’s definitions and glossary. In this document, ‘you’ and ‘your service’ are used to direct a provider to the specific rules their organisation and service(s) must follow, and the recommendations they can follow, to be certified. As such, ‘you’ is directed to DVS rather than to employers throughout this document.
1.f. The RtW supplementary code does not set any new requirements on, or recommendations for, employers for conducting compliant right to work checks. These are set by the Home Office, not OfDIA. The RtW supplementary code helps DVS show they can be used by employers to fulfil their obligations.
Part 2 - Rules of the RtW supplementary code
2. Applicable roles
2.a. You must perform at least the role of identity service provider as described in the trust framework to be certified against the RtW supplementary code. You must additionally perform the role of holder service provider to be certified against the rules in section 5.
3. Identity verification
3.a. You must follow the rules for identity service providers set out in the trust framework.
3.1. Acceptable documents
3.1.a. For the purposes of digital right to work checks, the identity must be created using one of the following documents:
- A British passport, or
- An Irish passport, or
- An Irish passport card.
3.1.b. If an expired passport or passport card is used to create the identity, it must have expired no more than six months before the date of the check.
3.1.c. The passport or passport card, whether expired or not, must be valid according to GPG 45 and not be visibly clipped.
3.2 Acceptable GPG 45 Profiles
3.2.a. For the purposes of digital right to work checks, the identity check must meet a medium level of confidence or above according to GPG 45.
3.2.b. If an expired passport or passport card is used to create the identity, you must confirm its cryptographic security features are genuine as part of the validity check following the rules in 6.3.2 of GPG 45.
4. Data to share with employers
4.a. If the check is successful, you must provide all the information in the table below to the employer relying on your service in a clear, legible format which cannot be altered. Each data field must either be labelled precisely as it is in the table below, or clearly identifiable as matching a data field specified in the table below. For example:
- ‘DVS-registered service’ in the place of ‘Confirmation that the DVS provider has a registered service’; or
- Code-compliant check’ in the place of ‘Confirmation that the check is provided in accordance with the RtW supplementary code’.
| Data field | Note |
|---|---|
| Given name(s) | |
| Middle name(s) | Only required if the user has a middle name(s). |
| Surname(s) | |
| Date of birth | |
| Image of the passport or passport card | This must be an image of the full biometric page of the passport or, in the case of an Irish passport card, an image of the front of the document in full. The holder’s name, date of birth and nationality must be clearly visible in the image, as must their photo and the date of expiry of the document. |
| Photograph of the user | You must verify that the photograph matches the image of the passport or passport card. |
| Date of identity check | |
| Evidence checked by | The name of your service, as it appears on your certificate |
| Confirmation that the DVS provider has a registered service | Confirmation that you have a service certified against a valid version of the trust framework and the RtW supplementary code and that the service is registered as such in the DVS register at the time the check is conducted. See 4.b. for the format this response must take. |
| Confirmation that the check is provided in accordance with the RtW supplementary code | Confirmation that the two following conditions are true: 1) the service that conducted the right to work check to which the output relates was certified and registered as per the field above at the time the check was conducted; and 2) the check is provided in accordance with the RtW supplementary code. See 4.b. for the format this response must take. |
| Link to DVS register entry | You must provide the link to the entry for your service on the digital verification services register. You could also provide your trust mark details. |
| Identity verified | See 4.b. for the format this response must take. |
4.b. The response for the indicated fields must be ‘yes’ (or a clear equivalent, such as ‘Y’ or ‘true’) or ‘no’ (or a clear equivalent, such as ‘N’ or ‘false’).
4.c. You could retain your own record that you conducted the check. Retention of information listed in 4.a is the employer’s responsibility, as set out in Home Office regulations and guidance. Your service does not need to retain this information.
4.d. You could use the trust framework data schema to support a standardised approach to sharing data with employers.
5. Using a holder service to conduct a right to work check
5.a. Passports and passport cards can be withdrawn or cancelled, and right to work checks are not transferrable from one employer to another. As such, if you want to use a pre-existing identity stored in a holder service to conduct a right to work check, you must be able to assure the employer that the user holds a British passport, Irish passport or Irish passport card at the time the check is conducted, and that the passport or passport card is not visibly clipped or expired by more than 6 months by conducting a GPG 45 validity check on it. If an expired passport or passport card is used, it must be validated according to 3.2.b.
5.b. While right to work checks are not transferrable from one employer to another, an employer, individual or other organisation (‘relying party’) may need to check whether a worker has already had a right to work check conducted. If you want to use a pre-existing identity stored in a holder service to check that an individual carrying out work or services has had their right to work checked and confirmed, you must:
- know whether the user of the holder service account (‘user’) is the same person as the worker on whom the right to work check was conducted (‘worker’)
- know that this right to work check was successful and remains valid
- confirm to the relying party whether the user is the same person as the worker.
5.c. If you conduct a check as described in 5.a or 5.b, you must follow the rules for holder service providers set out in the trust framework and the holder service must have medium protection using medium quality authenticators as a minimum according to GPG 44.
5.d. To conduct a right to work check as described in 5.a, you must know the pre-existing identity was created in line with 3.2, and you must share the data in 4.a with the employer.
5.e. If you have conducted a check as described in 5.b., and you have successfully matched the user with the worker on whom the right to work check was conducted, you must be able to share the following information upon request from a relying party:
- an image of the user captured during the check if such an image is available; and
- the image from the right to work check that you matched them against.
You must only share this information if you have agreed to supply it to the relying party and if you have confirmation that the user understands that this information will be shared. You must agree with the relying party how long you will retain this information for if you have agreed to supply it.
The relying party is not obliged to request this information, but may do so, for example, for compliance purposes.