EUDI Wallet (European Digital Identity Wallet)

Published on

04/09/2026

Updated on

04/09/2026

Reading time

4 min

Definition

The EUDI Wallet (European Digital Identity Wallet) is the digital wallet for proof of identity mandated by the European Union. It resides as an application on the user’s device, where it stores government-issued identity data and other electronic credentials, sharing them with third parties only upon request and with explicit consent.

The legal basis is Regulation (EU) 2024/1183, which fundamentally amended the eIDAS Regulation (910/2014) and is therefore commonly referred to as eIDAS 2.0.

It is relevant for payment transactions because, from the end of 2027, it must be accepted as a means of strong customer authentication and because it places identity verification during onboarding on a new footing.

The legal framework

Regulation (EU) 2024/1183 entered into force on 20 May 2024. It is fleshed out by a series of implementing acts—ranging from CIR 2024/2977 to CIR 2025/2162—that establish formats, protocols, certification, and the trust model.

The technical specifications are set out in the Architecture and Reference Framework (ARF), which the Commission updates in collaboration with the Member States; Version 2.7.3 is currently the authoritative version. The ARF is not a legal act, but it serves as the practical reference for any implementation.

The deadlines



 

No other deadlines are specified in the text of the regulation in this way: Article 5f(2) refers to “no later than 36 months after the date of entry into force of the implementing acts.” The date mentioned is a calculation derived from that, and it shifts if the acts themselves are delayed.

How it works

The ecosystem comprises four roles:

  • Wallet Provider – provides the certified wallet and is responsible for the “high” security level.
  • PID Provider – issues the Person Identification Data, the state identity core
  • Attestation Provider – issue additional attestations: QEAA (qualified, from a QTSP), PuB-EAA (from public bodies based on authentic sources), EAA (non-qualified)
  • Relying Party – the entity that requests and relies on a proof; a crucial role for banks.

From a technical standpoint, the ARF relies on established building blocks: credentials in ISO/IEC 18013-5 (mdoc) or SD-JWT VC format, issuance via OpenID4VCI, and presentation via OpenID4VP.

EUDI Wallet — one queryA relying party sends a presentation request to the wallet, naming the attributes it needs and the purpose. The wallet shows the user who is asking, for what purpose and which data is involved, and the user consents with a PIN or biometrics. Only the requested attributes leave the wallet. The wallet presents them signed with a device-bound key, and the relying party verifies the presentation. The example at the bottom shows the effect of selective disclosure: the question whether the holder is over eighteen is answered with yes, without the date of birth ever leaving the wallet.Userthe account holderEUDI Walleton the user’s deviceRelying Partyasks and verifies1 · the request2 · the user decides3 · the answerpresentation request · which attributes, for what purposeshown to the user · who asks, what for, what dataconsent · PIN or biometricspresentation · signed with a device-bound keyselective disclosure — only the requested attributesverified — proven, and nothing more disclosedan example of what actually leaves the walletthe relying party asksis the holder over 18?the wallet answersyesthe date of birth never leaves the walletOne query — that is the whole interaction1 · The relying party asks for specific attributes and states its purpose2 · The wallet shows who asks, for what purpose and which data — the user consentsOnly the requested attributes leave the wallet3 · The wallet presents them signed with a device-bound key, the relying party verifiesThe point: a proof can be given without handing over the data behind it
EUDI Wallet — a single query: request, consent, presentation

Selective disclosure is the actual innovation. The wallet does not present the entire document, but rather only the specific attribute requested. Proof of being “over 18” can be provided without revealing the date of birth.

Relying parties

An entity that requests and verifies a wallet template is a so-called “relying party”—for example, a bank during account opening, a merchant during age verification, a public authority during an application process, or a payment service provider during authentication.

Obligation to register (Article 5b): Any party acting in a trusted capacity that intends to use wallets must register in the Member State of its establishment and, in doing so, provide at least the following information:

  • Member State of establishment, name and registration number
  • Contact details
  • The intended use and the types of data required for it

The last point is the decisive one. The wallet cross-references every request against this registration and warns the user if more is being requested than was registered. Data minimization is thus technically enforced, not merely legally required.

The impact on payment transactions

Strong Customer Authentication

Article 5f(2) obliges relying parties to accept the wallet where strong user authentication is required by law or contract and users wish to use the wallet voluntarily. The provision lists the sectors concerned—expressly including banking and financial services. Payment service providers fall within this scope in any case, as Article 97 of PSD2 mandates strong customer authentication.

Micro-enterprises and small businesses are exempt, and the requirement applies only at the user’s request; therefore, no one is obliged to use the wallet.

Paragraph 1 imposes a parallel obligation on the public sector, while Paragraph 3 applies to very large online platforms within the meaning of Article 33 of the DSA.

Onboarding and due diligence obligations

Anti-Money Laundering Regulation (EU) 2024/1624 expressly permits electronic identification for the fulfillment of due diligence obligations. A PID with a “high” security level provides a robust basis for this and is a potential substitute for video identification procedures, with significant implications for costs and drop-out rates during account opening.

Sources