Back to blog
EU & UK

eIDAS and the EU Digital Identity Wallet: what it means for relying parties

A European framework for digital identity and trust services, moving toward a wallet citizens control. What changes for organisations that verify identity or accept electronic signatures.
GRC Copilot Team
eIDAS and the EU Digital Identity Wallet: what it means for relying parties

eIDAS governs electronic identification and trust services across the EU, and its next phase moves toward a digital identity wallet that individuals control. For most organisations the practical question is narrow: what must you accept, and what can you rely on.

Trust services, briefly

The framework covers electronic signatures, seals, timestamps, registered delivery and website authentication certificates. The important distinction throughout is between ordinary and qualified services - qualified ones are provided by supervised providers on national trusted lists and carry stronger legal effect.

The signature levels that matter commercially

  • Simple electronic signature - broad definition, admissible but weak evidentially.
  • Advanced electronic signature - uniquely linked to the signatory, capable of identifying them, under their sole control, and detecting subsequent changes.
  • Qualified electronic signature - an advanced signature created by a qualified device with a qualified certificate. It carries legal effect equivalent to a handwritten signature and shifts the evidential burden.
The practical consequence: for most commercial contracts an advanced signature is sufficient and proportionate. Insisting on qualified signatures everywhere adds cost and friction; using simple signatures for high-value or disputed agreements leaves you with weak evidence.

The wallet, and what changes for you

The direction of travel is toward a wallet held by the individual, containing verified attributes they can present selectively - proving they are over 18 without disclosing a birth date, or proving a professional qualification without handing over a full document.

For organisations that verify identity, the shift is from collecting documents to accepting verified assertions. That is a genuine improvement for data minimisation: you stop holding copies of passports you never wanted and cannot securely retain.

Track identity and privacy obligations together

GRC Copilot maps identity, privacy and security controls across the regimes that apply to you, with evidence per requirement.

Obligations for relying parties

Organisations accepting wallet credentials are expected to register as relying parties, state what attributes they request and why, and request only what is necessary. That last point has teeth: over-requesting attributes is both a wallet-framework issue and a data minimisation issue under GDPR.

Certain sectors face expectations to accept the wallet where they already require strong identification - financial services and public services in particular.

What to do now

  1. Inventory where you verify identity today and what documents you collect and store.
  2. Review your signature levels. Match the level to the value and disputability of the agreement rather than applying one level everywhere.
  3. Check your providers - if you rely on qualified services, confirm the provider appears on a national trusted list.
  4. Reduce document retention where verified attributes could replace stored copies; identity documents are a breach liability.
  5. Track the timeline. Implementation is staged and technical specifications continue to develop - confirm current status before committing in contracts.

Frequently asked questions

Do we have to accept the wallet?

Obligations fall on defined sectors and grow over time. Verify your position rather than assuming you are out of scope.

Is a qualified signature always needed?

No. Advanced is proportionate for most commercial agreements; qualified matters where legal equivalence to handwriting is required.

Does this replace KYC?

It can supply verified attributes to support it, but sector KYC obligations remain and are not discharged by the wallet.

Does it apply outside the EU?

The framework is EU, but organisations serving EU customers may be expected to accept wallet credentials in scoped sectors.

Key takeaways

  • Match signature level to value and disputability, not a blanket policy.
  • The wallet shifts you from collecting documents to accepting assertions.
  • Request only necessary attributes - over-requesting is a privacy issue too.
  • Verify qualified providers appear on a national trusted list.
#eidas #digital-identity #eudi-wallet #trust-services #qualified-signature #verification