Garrigues

ELIGE TU PAÍS / ESCOLHA O SEU PAÍS / CHOOSE YOUR COUNTRY / WYBIERZ SWÓJ KRAJ / 选择您的国家

The European Digital Identity Wallet now has a timetable: tasks to be completed by December 2027

Moisés Menéndez and Belén Aguayo

The European Digital Identity Wallet now has a timetable: tasks to be completed by December 2027

The roll-out of the EUDI Wallet will require a review of identification, contracting and electronic signature processes across a wide range of organisations, with implications that go far beyond the technological sphere. In this article, we analyse the most relevant aspects to bear in mind.

Two dates set the agenda. By 24 December 2026, each Member State must offer its citizens at least one free European Digital Identity Wallet (EUDI Wallet). By 24 December 2027, businesses in the designated sectors – banking, energy, transport, healthcare and telecommunications, amongst others – and major platforms must accept it as a means of authentication. This is set out in Regulation (EU) 2024/1183 (eIDAS 2), in force since 20 May 2024 (OJEU 30-04-2024). The question is no longer whether the wallet will be introduced, but which identification, contracting and signing processes will need to be adapted, and in what order. This article sets out the picture: what the digital wallet is, who it applies to, from when, and what the implications are.

What is the European Digital Identity Wallet?

EUDI Wallets are mobile applications, provided by Member States, which enable users to identify themselves electronically, store and manage identity data and official documents in digital format, and sign using a qualified electronic signature. Each Member State will offer at least one; public solutions may coexist, whether mandated by the state or provided by recognised independent bodies. All of them, whether public or private, are regulated technologies, subject to the same compliance and certification framework. 

According to Article 5a of Regulation (EU) 2024/1183, the free wallet must be available within 24 months of the entry into force of the implementing acts. The first five were published in the Official Journal of the European Union on 4 December 2024 and entered into force on 24 December 2024: hence 24 December 2026, the date around which the registration of relying parties under Implementing Regulation (EU) 2025/848 (OJEU 7 May 2025, as amended) also revolves. The technical framework was finalised in 2026: Implementing Regulation (EU) 2026/798 (April) established remote onboarding of users, whilst Regulations (EU) 2026/1730, 2026/1731 and 2026/1735 (July, in force from 11 August 2026) revised the previous acts without altering the deadlines. Use of the digital wallet will always be voluntary for citizens. 

What citizens will be able to do with the digital wallet

The digital wallet is not merely a means of logging in. The regulation provides it with functionalities that organisations must be able to manage: 

  • Identification and authentication with public and private relying parties, both online and, where applicable, offline, with selective disclosure: providing only the necessary information (‘over 18 years of age’) without showing the full identity document. 
  • Storage of credentials: identity data, electronic attestations of attributes (academic qualifications, driving licence, health data) and qualified and non-qualified certificates. 
  • Integrated qualified electronic signature, free of charge for individuals for non-professional purposes. 
  • Transaction dashboard: the user will be able to see which relying parties they have shared data with, request its erasure (Article 17 of the GDPR) and report allegedly unlawful requests to the data protection authority. 

The traceability dashboard represents a qualitative shift from current models: citizens can see who has accessed their data and when; for the relying party, every excessive request is documented.

A technological solution designed with rights in mind

The wallet is not merely a compliance formality: it is a decision about who controls identity data in Europe. Its architecture – public technical specifications and profiles, open reference implementations, auditable certification – is not an engineering detail, but a guarantee that anyone can verify what the tool they use to identify themselves actually does. Selective disclosure, the protection of communication between the wallet and the relying party, and the prohibition on the wallet issuer profiling its use all point towards the same objective: to prove an attribute without revealing a full identity and without leaving an exploitable trail in the hands of an intermediary.

This is where it differs from the model that has prevailed until now. In practice, identifying oneself online has meant doing so via three or four global platforms that turn every authentication into business data. The wallet replaces that intermediary with a public, interoperable standard across the twenty-seven Member States: credentials reside on the citizen’s device, and the citizen decides, transaction by transaction, what to reveal and to whom. For organisations, the practical takeaway is: less reliance on third-party identity providers and greater reliance on a framework they can audit.

The criticism has been voiced and should be taken seriously: a state-backed identity infrastructure could be seen as a tool for control, particularly if it is linked in the future to age verification, access to social media or use cases not currently envisaged. The regulation seeks to mitigate this through voluntary use, pseudonyms, the prohibition on requiring the identity wallet when another means suffices, and the traceability dashboard itself. Whether these safeguards work will depend less on the text of the regulation than on its implementation: on the independence of the supervisory bodies, on the discipline with which relying parties limit what they request, and on the specifications remaining public and subject to review. Here too, companies have something to gain: those who request only what is necessary simultaneously reduce both their risk of penalties and user mistrust. 

Key obligations for organisations

Public sector

Public bodies requiring electronic identification for an online service must accept digital wallets in accordance with Article 5f(1). There is no specific deadline: the obligation applies from the moment the digital wallets become available in each Member State.

Companies in regulated sectors

Banking and financial services, transport, energy, social security, healthcare, drinking water, postal services, digital infrastructure, education and telecommunications form the core of the private sector entities subject to these obligations. The obligation applies to businesses in these sectors that are required, by law or by contract, to use strong user authentication (SCA), and takes effect 36 months after the entry into force of the implementing acts: 24 December 2027. 

Micro-enterprises and small enterprises are excluded in accordance with Recommendation 2003/361/EC. 

The main legislation currently requiring SCA is Directive (EU) 2015/2366 (PSD2) on payment services: it obliges providers to apply SCA when a payer accesses their account online, initiates an electronic payment transaction or carries out any action via a remote channel that may entail a risk. This places the financial sector amongst the first to be affected. The key, in any case, is the criterion rather than the list: a single organisation may have processes both within and outside the scope.

Very large online platforms (VLOPs)

Platforms with more than 45 million monthly active users in the EU, as defined by Regulation (EU) 2022/2065 (DSA), which require authentication must accept and facilitate the use of digital wallets. Furthermore, they may only request the minimum data necessary for the specific service – in line with the GDPR’s data minimisation principle – which will necessitate a review of a significant proportion of current processes. 

Free qualified electronic signature

Wallets will offer all natural persons the possibility to sign using a qualified electronic signature free of charge for non-professional purposes. For professional purposes, Member States may set a fee. By eliminating dedicated devices (chip cards, tokens, USB sticks), this may accelerate the adoption of the signature method with the highest evidential value. 

Expected economic impact

In its 2021 impact assessment, the European Commission estimated the annual savings resulting from simplified identification (KYC, onboarding) and reduced damage caused by cybercrime: 

Overall, the Commission forecasts net benefits of between €800 million and €6.5 billion.

From the regulation to the decision

The main practical issues will revolve around aspects such as determining whether a organisation falls within the actual scope of the obligation and from when; what needs to be in place by 24 December 2026, when the register of relying parties and the access certificate will serve as the gateway to the wallet; how data minimisation – which the Spanish Data Protection Agency already penalises today – turns selective disclosure into the management of an existing risk; what age verification requires of platforms; what a qualified electronic signature from the wallet contributes to the probative value of the contract; and when it makes sense to move from accepting credentials to issuing them. 

The financial sector illustrates the starting point: Article 12 of Law 10/2010 already recognises the qualified electronic signature as a form of remote identification, and Regulation (EU) 2024/1624 on the prevention of money laundering, applicable from 10 July 2027, will raise due diligence requirements that the digital wallet can meet. We are not starting from scratch: Garrigues has already analysed the use of the digital wallet for hotel check-in. 

The dates have been set; what remains to be decided is how to meet them, with processes already adapted to the regulatory framework applicable to each organisation.