d-you
Published on
10/09/2026
Updated on
10/09/2026
Reading time
4 min
Last updated: 10 September 2026
d-you is the name of the German state implementation of the European identity wallet. The “d” stands for digital and for Germany, the “you” for the user, who is meant to hold the data. The app was presented in September 2026 and is due to launch in early 2027.
A wallet, not “the” EUDI wallet
The most important point comes first, because public reporting blurs it almost throughout: the EUDI wallet is not a product but a European framework. Regulation (EU) 2024/1183 obliges every member state to provide its citizens with at least one wallet and sets out the requirements it has to meet.
d-you is Germany’s answer to that obligation – one wallet among many, not the standard itself. Every other member state provides its own, and within Germany d-you is not meant to remain alone: further providers will be able to seek certification after launch. Anyone speaking of “the EUDI wallet” while meaning d-you is confusing the framework with one of its instances. For banks this is not an academic distinction – they will have to accept credentials from wallets of all member states, not only from d-you.
Legal framework
The framework sits on two levels. At European level the revised eIDAS regulation establishes the entitlement to a wallet and its requirements. Nationally, the German Digital Identities Act provides the basis for operation and supervision; the cabinet has approved it.
Two decisions shape the project: use is voluntary and free of charge, and the existing routes remain in place. Anyone who prefers to identify themselves with a physical card or by video can continue to do so.
Who is building it
Behind d-you stands not a single contractor but a consortium: the federal agency for disruptive innovation SPRIND as project lead, the Federal Office for Information Security for the security requirements, Bundesdruckerei and D-Trust for core components, plus research and consulting partners. This constellation explains why the project builds on the assurance level “high” – for the first time for a solution running on a smartphone.
How it works
The process falls into two parts, far apart in time. The set-up happens once: the wallet is activated through the online ID function of the identity card, which is read wirelessly for the purpose. After that a digital twin of the card sits on the device; further credentials are to follow step by step.
Every use then runs as a short dialogue: the other side – an authority, a merchant, a bank – asks which details it needs. The user releases what they want to release, and ideally transmits only that. To prove majority, confirming the age threshold is enough; name and address need not travel with it.
Timeline and ecosystem
Launch is planned for early 2027, accompanied by some forty partners from business, research and public administration contributing the first use cases. Roughly a year after launch, further wallet providers are to be able to seek certification. d-you is therefore the beginning of a market and not its conclusion – a perspective that matters more for planning your own connections than the exact launch date.
Relevance for banks and payment service providers
For institutions the topic touches three processes previously thought of separately: identification at onboarding, authentication in day-to-day operation, and the release of individual payments. All three can in future run through the same wallet.
One point is regularly overlooked: a bank cannot simply request data from a wallet. It must first register as a relying party, stating which details it needs and for what purpose. That registration is not a formality but the mechanism preventing arbitrary parties from requesting arbitrary data.
| Use case | common today | with d-you | what the bank needs |
|---|---|---|---|
| opening an account | video or postal identification, with a media break | identity credential straight from the wallet | registration as a relying party and connection of the verification path |
| releasing a payment | app-based procedure, SMS code or card reader | release from the wallet as strong customer authentication | integration into the existing authentication path |
| proving age | showing the ID card, all data visible | confirmation of the age threshold, nothing else | no reading of the full identity data |
| signing a contract | signature in person or a separate signing service | signature from within the wallet | connection of the trust service |
Data protection
Data protection is not an afterthought in the design but structural. Four decisions carry it:
- The data stays on the device. Credentials are stored locally in encrypted form; there is no central database in which identities could accumulate.
- Selective disclosure. Instead of a complete identity document, only what the transaction requires is transmitted – ideally a confirmation rather than a data set.
- Registered counterparties. Whoever wants to request details must be registered and state the purpose. The user sees who is asking and for what.
- Open source code. European rules require the wallet's source code to be published, so the implementation can be examined.
Added to this is voluntariness: nobody may be disadvantaged for not using the wallet – the analogue routes stay open.
The European framework into which d-you fits is described in the glossary entry on the EUDI wallet. Further video material on digital identities and payments is available on the CPG Finance Systems YouTube channel.