Skip to main content
EUDI Wallet

The EUDI Wallet is set to fundamentally change how digital identity is handled in Europe. In the future, citizens should be able to identify themselves, present electronic credentials, and sign documents via their smartphones – both with government agencies and in private sector applications.

The wallet is more than just a digital version of a physical wallet for ID cards or driver’s licenses. A key function is the ability to securely identify oneself digitally. It is part of a pan-European trust infrastructure where various providers collaborate. Credentials must come from reliable sources, be technically verifiable, and have specific legal effects depending on the use case.

This is precisely where Trust Service Providers, also known as Trust Service Providers, play an important role. They enable, among other things, qualified electronic signatures (QES), seals, timestamps, and qualified electronic attribute attestations.

EUDI stands for European Digital Identity. The EUDI Wallet is a digital identity solution that allows users to securely manage their identity data on their smartphones and share it selectively.

The legal basis is Regulation (EU) 2024/1183, often referred to as eIDAS 2.0. It expands the original eIDAS Regulation to include a European framework for digital identities. The European Commission has thus created the foundation for a common digital identity infrastructure in Europe.

Each EU member state must provide at least one recognized EUDI Wallet. This can be offered directly by the member state, operated under government contract, or developed by a private provider and state-approved.

Use of the wallet remains voluntary for citizens. They decide for themselves which data they share with whom.

The comparison with a wallet is helpful for understanding but falls short. The EUDI Wallet does not contain simple scans or PDF files. The stored credentials are structured, machine-readable, cryptographically secured, and linked to the issuing authority. Companies and authorities can thus automatically verify who issued a credential, whether it is still valid, and whether its data has been altered.

Significance and Benefits of the EUDI Wallet

Many digital processes currently fail due to identification or the exchange of reliable credentials. Documents are scanned, sent via email, and then manually checked. In some cases, citizens must appear in person to identify themselves or submit documents by mail.

The EUDI Wallet aims to reduce such media disruptions. Users can receive credentials directly from an authorized source and reuse them in various applications and functions. Depending on the function, they can use it to identify themselves digitally, present authorizations, or electronically sign documents.

They should be able to:

– Identify online and partially offline,
– Receive and present digital credentials,
– Share specific information selectively,
– Access public and private services,
– Electronically sign or seal documents,
– Prove authorizations for work, study, or travel.

Common technical specifications should ensure that the wallet can be used in all member states.

Data-Minimizing Credentials

An important advantage is selective disclosure. Users do not always need to transmit a complete document. For age verification, for example, it may be sufficient to provide the information that a person is of legal age. The exact date of birth, name, or address do not necessarily need to be disclosed. Which attributes an application may request depends on the purpose and legal requirements. The wallet should display the request transparently and allow conscious approval.

What Data Can I Present with the EUDI Wallet?

The EUDI Wallet can contain both identity data and additional electronic credentials.

Possible use cases include:

Identity: Name, date of birth, place of birth, nationality

Mobility: Mobile driver’s license, vehicle data

Education: Enrollment certificates, diplomas, degrees

Administration: Residence, marital status, official certificates

Profession: Professional qualifications, powers of attorney, representation authorizations

Health: Prescriptions or insurance certificates

Contracts: Electronic signatures and seals

The European Commission is testing corresponding use cases in areas such as education, mobility, health, travel, payments, and contract signing. Which credentials will actually be available at launch depends on which authorities, companies, and other issuers make their data available digitally and integrate it into the wallet ecosystem.

What is the Core Identity or PID?

The Person Identification Data, or PID, forms the core identity of a natural person within the EUDI Wallet. The basic information includes surname, first name, date of birth, place of birth, and nationality.

Additional attributes can be added by member states. The technical criteria are specified by corresponding implementing acts.

The PID should not be understood as a photo or digital copy of an ID card. It is a structured and cryptographically secured data record that enables identification in digital workflows. An ID card or other government-issued document can serve as the basis for the initial issuance of the PID. A driver’s license, university degree, or professional qualification, on the other hand, is included in the wallet as a separate credential.

How Secure is the EUDI Wallet?

The EUDI Wallet must meet the requirements of the eIDAS trust level “high.” This applies particularly to identity verification, onboarding, authentication, and management. Registration cannot be done solely with a name or email address. Identity must be confirmed using a correspondingly secure procedure.

Importantly: A secure and certified wallet does not automatically make every credential stored in it a qualified credential. Even a signature triggered via the wallet is not automatically a qualified electronic signature. Additional eIDAS requirements for security must be met for this.

Who Does What in the EUDI Wallet Ecosystem?

The EUDI Wallet does not perform all tasks itself. In the ecosystem, various roles work together:

Wallet Providers provide the wallet application and are responsible for its secure technical environment.

PID Providers issue and update or revoke the core identity data as needed.

Issuers issue additional credentials. These can be administrations, universities, employers, banks, or Trust Service Providers.

Users or Holders manage the wallet and decide which data to release.

Relying Parties request and verify credentials. These include, for example, authorities, companies, or educational institutions.

An organization can assume multiple roles simultaneously.

Architektur EUDI Wallet

What Role Does the Trust Service Provider Play in the EUDI Wallet?

They become relevant when digital information needs to be linked with verifiable origin, integrity, or special legal effect.

A distinction must be made between non-qualified and qualified trust service providers. A qualified trust service provider, or qTSP, must meet the requirements of the eIDAS Regulation, be audited by the competent supervisory authority, and be listed in a national Trusted List.

For example, a university can issue a digital diploma itself. An authority can provide attributes from an official register. Not every credential therefore requires a qualified trust service.

A qTSP comes into play particularly when:

– A qualified electronic signature is created,
– A qualified electronic seal is needed,
– A qualified electronic attribute attestation is issued,
– A qualified timestamp is required,
– Qualified certificates are managed,
– Signatures or seals need to be validated and preserved for the long term.

The EUDI Wallet does not replace these services. It provides users with easy and secure access to them.

Qualified Signatures (QES) via the EUDI Wallet

An important use case is the qualified electronic signature (QES), or QES for short. The QES generally has the same legal effect as a handwritten signature throughout the EU.

The signature creation unit can be part of a certified wallet environment. Alternatively, a remote QSCD can be operated by a Trust Service Provider.

A possible process:

1. A document is prepared in a specialized application.
2. The EUDI Wallet displays the signature process.
3. The person confirms it with a PIN or biometric authentication.
4. The Trust Service Provider creates the QES.
5. The signature result is returned to the application.

Depending on the technical architecture, only a hash of the document – its digital fingerprint – is transmitted to the signature infrastructure.

Electronic Attribute Attestations and Other Trust Services in the EUDI Wallet Context

Attributes describe characteristics or authorizations of a person or organization. Examples include an academic degree, professional qualification, or power of attorney.

eIDAS distinguishes between non-qualified electronic attribute attestations, qualified electronic attribute attestations (QEAA), and attestations from public authorities based on authentic sources.

A QEAA is issued by a Trust Service Provider and offers particularly high legal and technical reliability.

For companies and administrations, this means: Not every use case requires a qualified attribute attestation. What matters is what statement a credential should make, from which source the data comes, and what legal consequences are associated with it.

In addition to signatures and attribute attestations, other trust services are also relevant:

– Electronic seals verify the origin of data or documents and protect their integrity.
– Electronic timestamps prove that certain data existed at a specific point in time.
– Validation services check whether signatures, seals, or certificates are valid.
– Preservation services maintain the verifiability of digital signatures and seals over the long term – even if certificates expire or technical procedures evolve.

Advantages of the EUDI Wallet for Businesses and Administrations

When properly integrated, the EUDI Wallet can significantly simplify digital processes. Structured credentials can be automatically verified for authenticity, reducing manual checks. At the same time, paper documents, scans, email attachments, and letters can increasingly be eliminated. Since the wallet operates according to common European specifications, processes can also be used across borders within the EU. Through selective disclosure, only the data that is actually needed for the specific use case is shared. Tampered documents can be more easily detected, and identification, credential presentation, and electronic signature can be connected in a seamless process. Thus, the EUDI Wallet helps reduce manual work and accelerate digital applications, registrations, or contract signings.

What Companies and Authorities Should Do Now

Organizations can already prepare before full implementation:

– Identify workflows: Where are identities, credentials, or authorizations and their authenticity verified today?
– Define attributes: Which data is actually needed?
– Clarify legal requirements: When is a simple credential sufficient, and when is a qualified trust service required?
– Determine own role: Should the organization verify credentials, provide them itself, or do both?
– Prepare specialized procedures: Systems must be able to request, receive, validate, and process authorizations.
– Incorporate data protection and governance: Data queries, storage, and responsibilities must be clearly regulated.
– Start with a pilot project: Suitable processes are those with high manual verification effort and clearly defined credentials.

Implementation in Germany

In Germany, a state EUDI Wallet is being developed on behalf of the Federal Ministry for Digital Affairs and Public Modernization (BMDV).

The Federal Agency for Leap Innovations (SPRIND) is working with project partners on the national wallet and the associated identity ecosystem. The project aims not only to digitally replicate existing processes but also to enable new, seamless identity processes as a leap innovation.

In addition to the state solution, private providers should also be able to develop and have their own wallets approved. The EUDI Wallet is thus not only an IT project of the BMDV and SPRIND but also an important building block for public modernization and digital administration in Germany.

Conclusion: The EUDI Wallet Needs a Trustworthy Ecosystem

The EUDI Wallet is a central building block for digital identity in Europe. It aims to enable citizens to securely identify themselves, share authorizations in a controlled manner, and complete digital processes without unnecessary media disruptions.

However, the identity solution only unfolds its full potential in interaction with wallet providers, issuers, verifying entities, and Trust Service Providers. Only this shared infrastructure ensures that users can identify themselves digitally, securely share credentials, and use qualified services such as QES.

For companies and authorities, EUDI Wallet readiness therefore means more than just connecting an app. Specialized procedures, attributes, data protection, compliance, validation, and the necessary trust infrastructure must also be considered.

As a qualified Trust Service Provider, SIGN8 supports companies and administrations with qualified signatures, seals, timestamps, digital credentials, and trustworthy identity processes and infrastructure. This allows regulatory requirements from eIDAS to be translated into concrete applications.

Frequently Asked Questions about the EUDI Wallet

Is the use of the EUDI Wallet mandatory?

No. Use is voluntary for citizens. However, each EU member state must offer at least one recognized wallet.

Can I identify myself digitally with the EUDI Wallet?

Yes. The EUDI Wallet is intended to enable secure identification with authorities and private services.

Can I create a QES with the wallet?

Yes. The EUDI Wallet must support the creation of qualified electronic signatures. The technical implementation can be done, among other things, via a remote QSCD of a qTSP.

Does every credential need a Trust Service Provider?

No. Credentials can also be issued by authorities, universities, or companies. A Trust Service Provider is needed when a qualified trust service is required.

When will the EUDI Wallet be available in Germany?

Germany must provide at least one EUDI Wallet by the end of 2026. Which credentials and use cases will be available at that time depends on further implementation.