eIDAS 2.0
European Digital Identity Framework (Regulation (EU) 2024/1183)
Overview
Regulation (EU) 2024/1183 amends the eIDAS Regulation (EU) No 910/2014 to establish the European Digital Identity Framework. It entered into force on 20 May 2024. Each Member State must provide at least one European Digital Identity Wallet within 24 months of the entry into force of the implementing acts, which the European Commission states as the end of 2026. Use of the wallet is voluntary and free of charge for natural persons. Public sector bodies, and private relying parties that are required to use strong user authentication, must accept the wallet, so identity teams need to plan for wallet-based login and attribute verification.
IAM Requirements
European Digital Identity Wallet (Article 5a)
- Each Member State provides at least one wallet within 24 months of the entry into force of the implementing acts
- Wallets are provided under an electronic identification scheme with assurance level high
- Issuance, use and revocation are free of charge to natural persons, and use of the wallet is voluntary
- Wallets must support selective disclosure of data and user-generated pseudonyms
- Users can see a log of all transactions through a common dashboard
Relying Party Obligations (Article 5b)
- A relying party that intends to rely on wallets registers in the Member State where it is established
- Registration states the intended use and the data the relying party will request from users
- Relying parties must not request data other than what they indicated at registration
- Relying parties are responsible for authenticating and validating person identification data and attestations of attributes received from wallets
- Relying parties must not refuse pseudonyms where identification of the user is not required by Union or national law
Mandatory Acceptance (Article 5f)
- Public sector bodies that require electronic identification and authentication for an online service must also accept the wallet
- Private relying parties required by law or contract to use strong user authentication (for example in banking, financial services, health, energy, transport and telecommunications) must accept the wallet no later than 36 months after the implementing acts enter into force; micro and small enterprises are excluded
- Very large online platforms that require user authentication must accept the wallet
- Acceptance applies only at the voluntary request of the user and for the minimum data necessary
Attributes and Privacy
- Wallets let users request, store, combine and present person identification data and electronic attestations of attributes, online and offline
- Member States must make it possible to verify listed attributes against public-sector authentic sources within 24 months of the implementing acts
- Attestation providers must not obtain data that lets transactions or user behaviour be tracked, linked or correlated unless the user explicitly authorises it
- Access to services must remain possible by other identification and authentication means
Compliance Checklist
Penalties for Non-Compliance
Member States set the penalties. For qualified and non-qualified trust service providers, administrative fines of a maximum of at least €5 million for natural persons and, for legal persons, €5 million or 1% of total worldwide annual turnover, whichever is higher (Article 16).
Quick Facts
- Region
- European Union
- Effective Date
- May 20, 2024
- Enforcing Body
- National supervisory bodies in each EU Member State; the European Commission adopts the implementing acts