d-you

Published on

10/09/2026

Updated on

10/09/2026

Reading time

4 min

Last updated: 10 September 2026

d-you is the name of the German state implementation of the European identity wallet. The “d” stands for digital and for Germany, the “you” for the user, who is meant to hold the data. The app was presented in September 2026 and is due to launch in early 2027.

A wallet, not “the” EUDI wallet

The most important point comes first, because public reporting blurs it almost throughout: the EUDI wallet is not a product but a European framework. Regulation (EU) 2024/1183 obliges every member state to provide its citizens with at least one wallet and sets out the requirements it has to meet.

d-you is Germany’s answer to that obligation – one wallet among many, not the standard itself. Every other member state provides its own, and within Germany d-you is not meant to remain alone: further providers will be able to seek certification after launch. Anyone speaking of “the EUDI wallet” while meaning d-you is confusing the framework with one of its instances. For banks this is not an academic distinction – they will have to accept credentials from wallets of all member states, not only from d-you.

Legal framework

The framework sits on two levels. At European level the revised eIDAS regulation establishes the entitlement to a wallet and its requirements. Nationally, the German Digital Identities Act provides the basis for operation and supervision; the cabinet has approved it.

Two decisions shape the project: use is voluntary and free of charge, and the existing routes remain in place. Anyone who prefers to identify themselves with a physical card or by video can continue to do so.

Who is building it

Behind d-you stands not a single contractor but a consortium: the federal agency for disruptive innovation SPRIND as project lead, the Federal Office for Information Security for the security requirements, Bundesdruckerei and D-Trust for core components, plus research and consulting partners. This constellation explains why the project builds on the assurance level “high” – for the first time for a solution running on a smartphone.

How it works

The process falls into two parts, far apart in time. The set-up happens once: the wallet is activated through the online ID function of the identity card, which is read wirelessly for the purpose. After that a digital twin of the card sits on the device; further credentials are to follow step by step.

Every use then runs as a short dialogue: the other side – an authority, a merchant, a bank – asks which details it needs. The user releases what they want to release, and ideally transmits only that. To prove majority, confirming the age threshold is enough; name and address need not travel with it.

set-up – onceidentity cardd-you on the smartphoneread the online ID functionuse – in every transactionbank or serviced-you on the smartphonerequest: which details are needed?release: only the details neededCredentials stay encrypted on the device – there is no central database.

Timeline and ecosystem

Launch is planned for early 2027, accompanied by some forty partners from business, research and public administration contributing the first use cases. Roughly a year after launch, further wallet providers are to be able to seek certification. d-you is therefore the beginning of a market and not its conclusion – a perspective that matters more for planning your own connections than the exact launch date.

Relevance for banks and payment service providers

For institutions the topic touches three processes previously thought of separately: identification at onboarding, authentication in day-to-day operation, and the release of individual payments. All three can in future run through the same wallet.

One point is regularly overlooked: a bank cannot simply request data from a wallet. It must first register as a relying party, stating which details it needs and for what purpose. That registration is not a formality but the mechanism preventing arbitrary parties from requesting arbitrary data.

Select view:
Use casecommon todaywith d-youwhat the bank needs
opening an accountvideo or postal identification, with a media breakidentity credential straight from the walletregistration as a relying party and connection of the verification path
releasing a paymentapp-based procedure, SMS code or card readerrelease from the wallet as strong customer authenticationintegration into the existing authentication path
proving ageshowing the ID card, all data visibleconfirmation of the age threshold, nothing elseno reading of the full identity data
signing a contractsignature in person or a separate signing servicesignature from within the walletconnection of the trust service

Data protection

Data protection is not an afterthought in the design but structural. Four decisions carry it:

  • The data stays on the device. Credentials are stored locally in encrypted form; there is no central database in which identities could accumulate.
  • Selective disclosure. Instead of a complete identity document, only what the transaction requires is transmitted – ideally a confirmation rather than a data set.
  • Registered counterparties. Whoever wants to request details must be registered and state the purpose. The user sees who is asking and for what.
  • Open source code. European rules require the wallet's source code to be published, so the implementation can be examined.

Added to this is voluntariness: nobody may be disadvantaged for not using the wallet – the analogue routes stay open.

More on this topic

The European framework into which d-you fits is described in the glossary entry on the EUDI wallet. Further video material on digital identities and payments is available on the CPG Finance Systems YouTube channel.

Sources