EU Digital Identity Wallet

EU Digital Identity Wallet: Latest News and Privacy Concerns

The EU’s digital ID wallet is supposed to land in every member state by 24 December 2026, but the Commission itself doubts everyone will make it, and readiness already varies wildly by country. 

Privacy groups aren’t waiting for launch day to raise the alarm either: EDRi and epicenter.works spent March 2026 telling Brussels that the draft implementing rules water down the wallet’s own untraceability promises and add mandatory facial biometrics nobody asked for. 

Here’s where the rollout actually stands and what the privacy fight is really about. 

Key Takeaways

EU member states must offer at least one EUDI Wallet to citizens by 24 December 2026, but the European Commission itself has doubted every country will be ready in time.

France, Italy, and Austria already have live or advanced pilot wallets running; Bulgaria, the Netherlands, and Malta are among the countries reporting delays or partial functionality.

Privacy groups, led by EDRi and epicenter.works, say the draft implementing rules weaken the untraceability and pseudonym protections the original law promised, and add mandatory facial biometric checks that weren’t in the regulation to begin with.

What Is the EU Digital Identity Wallet?

The EU Digital Identity Wallet (EUDI Wallet, sometimes called the eID Wallet) is a mobile app that lets people prove who they are online and share specific pieces of verified information, such as their age or a qualification, without handing over a full identity document.

It comes from Regulation (EU) 2024/1183, known as eIDAS 2.0, which entered into force on 20 May 2024 and updates the original 2014 eIDAS framework for electronic identification. The regulation sets the legal basis; the technical detail, including data formats, security certification, and how wallets from different countries talk to each other, came later through a set of implementing acts the Commission adopted on 28 November 2024.

Each EU country must build and roll out its own wallet, but every national wallet must meet the same common technical standard so a wallet issued in one member state works in another.

When Do EU Countries Have to Launch Their Wallets?

Member states have 24 months from the implementing acts entering into force to offer citizens at least one EUDI Wallet. That puts the legal deadline at 24 December 2026.

A year after that, regulated organisations, including banks, insurers, telecoms providers, energy suppliers, and large online platforms, will have to accept the wallet as a valid means of identification, with that obligation landing around November 2027.

Which Countries Are Ahead?

France, Italy, and Austria are the furthest along. France Identité is already running as a live production service and is being expanded into an official EUDI Wallet rather than launched from scratch.

Which Countries Are Behind?

Readiness varies a lot by country. Bulgaria has reportedly not started serious work on a state-provided wallet because the national legislation isn’t in place yet. The Netherlands and Malta have both signalled they’ll launch with delays or limited functionality rather than the full feature set.

The European Commission has said it doubts every member state will hit the deadline, and industry analysts predict a staggered rollout: some countries will launch with a mature wallet on day one, while others will start with a bare-minimum version built out over the following months.

How Is the EUDI Wallet Supposed to Protect Privacy?

The regulation builds several privacy protections into the wallet’s design rather than leaving them to individual providers.

Selective disclosure lets a user share only what a service actually needs. A bar checking someone is over 18 gets a simple yes or no instead of a full date of birth or home address.

Unlinkability means that if the same credential is shown to two different services, those services can’t compare notes and work out it was the same person, even if they collude. That’s meant to stop the kind of cross-service profiling that’s common with today’s account-login systems.

The regulation also stops the body that issued a credential from finding out where or when it gets used afterwards. A government issuing a national ID credential isn’t supposed to learn that someone used it to enter a bar on a Tuesday night. Pseudonyms are built in too, so a person can get a certified attribute confirmed without revealing their full legal identity where the law doesn’t require it.

What Privacy Concerns Have Been Raised About the EUDI Wallet?

Despite that design, privacy groups say the rules being written to implement the regulation don’t live up to it.

In March 2026, European Digital Rights (EDRi), working with epicenter.works and eight other civil society organisations, told the European Commission the eID Wallet still isn’t fit for purpose. Their submission to the Commission’s public consultation on the draft implementing acts raised four specific problems:

The draft rules weaken the untraceability and unlinkability safeguards that were meant to stop people being tracked across services.

They add mandatory processing of sensitive biometric facial data, something the group says was never part of the original eIDAS Regulation.

They interpret the regulation’s pseudonym provisions narrowly, making full identification the default and pseudonyms largely unusable in practice.

They make registration certificates for relying parties optional, which shifts the burden onto users to check, every time, whether a service is asking for more data than it needs.

EDRi also flagged a scope concern: some national and EU lawmakers now want to make wallet use mandatory for age verification, including for accessing social media, even though the wallet was originally meant to be a voluntary tool for accessing public services online. The group is asking the Commission to keep it voluntary and fix the safeguards before attaching any mandatory use case to it.

Separate reporting has picked up a related complaint: parts of the wallet app reportedly require hardware-bound attestation to function, tying the wallet to specific device hardware and, in some implementations, to US technology providers for age-verification checks. Critics say that it locks users into particular device ecosystems and sits awkwardly next to an EU project meant to reduce dependence on non-EU tech platforms.

What Does This Mean for Businesses?

For most businesses, nothing changes immediately. The obligation to accept the wallet applies to a specific list of regulated sectors, and even then not until around a year after member states start issuing wallets.

What’s worth tracking now is the gap between the wallet’s legal privacy requirements and what the implementing rules currently allow. If your business will eventually need to accept EUDI credentials for identity checks, KYC, or age verification, the safest approach is to design that integration around the regulation’s actual privacy requirements (selective disclosure, unlinkability, data minimisation) rather than around whatever a specific national wallet happens to support at launch, since that’s likely to keep changing over the next year.

GDPRLocal can help you work out what data protection processes you’ll need once identity verification through the wallet becomes part of your compliance obligations.

Conclusion

The EUDI Wallet’s legal deadline hasn’t moved: at least one wallet per member state by 24 December 2026, business acceptance in regulated sectors about a year after that. What has moved is confidence in a smooth rollout. Some countries are close to ready; others aren’t, and the Commission has said so publicly. On privacy, the regulation’s promises (selective disclosure, unlinkability, no issuer tracking) are solid on paper, but civil society groups are actively fighting to stop the implementing rules from watering them down before the wallet reaches anyone’s phone.

Frequently Asked Questions

When does the EU Digital Identity Wallet launch?

Member states must offer citizens at least one EUDI Wallet by 24 December 2026, though the European Commission has said not every country is likely to meet that date with a fully featured wallet.

Will businesses have to accept the EUDI Wallet?

Regulated organisations, including banks, insurers, telecoms and energy providers, and large online platforms, will have to accept the wallet as a means of identification roughly a year after member states begin issuing it, around November 2027.

Is the EU Digital Identity Wallet safe from tracking?

The regulation requires selective disclosure and unlinkability so services can’t combine data to track users, and issuers aren’t supposed to see where credentials get used. Privacy groups including EDRi argue the current draft implementing rules water down these protections and should be fixed before rollout.

Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It is not a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.

About the Author

Zlatko Delev

Head of Commercial & Country Manager

Zlatko Delev is Head of Commercial and Country Manager at GDPRLocal, where he leads the company’s commercial strategy and market presence. He brings international experience across sales, marketing, and customer success, along with a legal background from his studies at Iustinianus Primus Law School in Skopje, Macedonia.

Zlatko sits at the front line of GDPRLocal’s client relationships, guiding organisations through the first stages of their compliance journey and helping them understand where they stand and where they need to go on GDPR, information security, and the emerging landscape of AI regulation. His role bridges commercial strategy with practical data protection knowledge, ensuring clients get clear, actionable direction from their very first conversation with GDPRLocal.

Alongside his commercial focus, Zlatko has trained extensively in project management and organisational leadership, including risk management, stakeholder communication, agile methodology, and digital marketing, a broad skill set that supports his structured, delivery-focused approach to growing GDPRLocal’s business internationally.