eIDAS 2.0 Changes Europe’s Identity Architecture

The European Digital Identity Framework is not simply a government login application. It creates a cross-border trust architecture for wallets, credentials and the organisations that request them.

Regulation (EU) 2024/1183—the updated eIDAS framework—applied from 20 May 2024. It requires Member States to provide European Digital Identity Wallets built to common specifications, with rollout targeted by the end of 2026.

The wallet is intended to let citizens, residents and businesses identify themselves and present verified attributes across borders. Examples include qualifications, licences, age, payment information and health-related documents.

For technical teams, the important word is not “wallet”. It is “ecosystem”.

The user should disclose only what is necessary

The framework requires support for selective disclosure. A service asking whether a person is over a threshold should not automatically receive the person’s full date of birth, address and legal identity.

That data-minimisation objective has architectural consequences. Relying parties must define which attributes they need and why. Wallets must present and protect attributes, authenticate the requesting party and create a record visible to the user.

Good implementation reverses a familiar identity pattern. Instead of the service collecting a broad identity profile “in case it is useful”, it requests a verified claim that is proportionate to the transaction.

Relying parties become part of the trust model

An organisation that intends to rely on an EUDI Wallet for a digital service must register in its Member State. The registration includes its identity, contact details, intended use and the data it plans to request.

The relying party must identify itself to the user and cannot request data beyond the registered purpose. It is also responsible for validating the identity data or electronic attestations it receives.

This means wallet support is not a generic “Sign in with Europe” button. Each service needs a registered purpose, authorised attribute requests, certificate handling and privacy controls.

The wallet itself is high-assurance infrastructure

Wallets must operate at a high assurance level, follow security-by-design principles and undergo certification. The regulation calls for strong encryption, explicit user confirmation, protected cryptographic material and secure communication with wallets and relying parties.

Providers must logically separate wallet data from unrelated services and avoid collecting unnecessary information about wallet use. The wallet should not become a new central tracking mechanism.

Common protocols and implementing standards are therefore as important as the legal framework. Interoperability has to work across Member States without weakening authentication or privacy.

Identity teams should prepare for coexistence

Wallet use is voluntary, and alternative access methods must remain available. Organisations will therefore operate mixed identity journeys for some time: national eID, EUDI Wallet, organisational credentials and conventional account recovery.

Preparation should include:

  1. Identifying services that could accept wallet credentials.
  2. Reducing each identity journey to the minimum required attributes.
  3. Registering relying-party purposes and maintaining them as services change.
  4. Validating credentials, issuer trust and revocation status.
  5. Separating wallet transaction logs from unnecessary behavioural analytics.
  6. Designing accessible alternatives and recovery routes.
  7. Threat-modelling device theft, malicious relying parties, correlation and social engineering.

Identity becomes a verifiable exchange

Traditional online identity systems ask every service to collect, verify and store similar information. The EUDI model attempts to let trusted issuers provide verifiable attributes under the user’s control.

If it works, the result is not merely more convenient authentication. It is less repeated identity collection, more explicit purpose and stronger cross-border verification. Those benefits depend on disciplined relying parties as much as secure wallets.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *