Skip to main content
The Signicat Blog
An image with a purple background showing an icon of a digital wallet on a smartphone with the EU flag, and the text 'The EU Digital Identity Wallet: Questions from around the world'.
Portrait of Esther Makaay
Esther Makaay

VP of Digital Identity at Signicat & Member of EUDI Wallet Consortium

The EU Digital Identity Wallet : Questions from around the world

You asked. We answered.

Updated on May 29, 2026

The European Digital Identity Wallet (EUDI Wallet) is one of the biggest changes to digital identity in Europe in recent years, and naturally, it has generated a lot of questions.

Through our EUDI Wallet webinars, businesses from different industries and countries have asked about everything from the wallet's role in the digital identity ecosystem to onboarding, authentication, compliance, signing, payments, privacy, and trust.

In this article, we've collected some of the most common questions and our answers.

Questions from Preparing for EUDI Wallets webinar (May 2026)


What is Signicat’s role in the eIDAS and EUDI Wallet ecosystem?

One of Signicat’s most important roles in the EUDI Wallet ecosystem is to support customers in engaging all certified EUDI Wallets, whether they must accept them for compliance reasons, or want to use them for data-sharing, authentication, identity proofing, data verification, or signing documents. This will be supported through the eID and Wallet Hub.

Signicat will act as intermediary for customers and facilitate intermediated relying party registration in the member state where the relying party is established. Registration in each country depends on national policies and registrar readiness. As soon as this becomes possible (national registers are not established yet), Signicat will register where necessary as intermediary and/or relying party.

We aim to take on as much of the administrative burden involved in relying party registration on behalf of customers as possible, including certificate management.

Signicat is also a qualified trust service provider (QTSP) for various existing trust services, including Qualified Electronic Signatures (QES), and will register as a QTSP for Qualified Electronic Attestations of Attributes (QEAA). We already provide a remote Personal Identification Data (PID) issuing service based on identity verification at eIDAS Level High that can be used by Member States and wallets.

Learn more about how Signicat can help you prepare for EUDI wallets.

How will businesses support EUDI wallets alongside existing eIDs?

When you “open up” your online service to different authentication methods – such as eIDs or wallets – there is no way of knowing beforehand whether a user already has one of your allowed methods. Some users may have multiple options available and need to choose which one they want to use.

Most services therefore provide a menu (drop-down or otherwise) allowing the user to choose how they want to log in. EUDI Wallets can simply become one of the available options. Depending on the user’s choice, the next step in the authentication flow will present the relevant interface, for example, a username/password or national eID flow, or a QR code flow for an EUDI Wallet.

When offering an online service, it is generally the service provider’s decision which eIDs to accept. Organisations may choose based on where their users are located, which attributes different eIDs can provide, or specific business and compliance requirements. The same applies to wallet-based solutions, whether EUDI-certified or not. However, organisations subject to mandatory acceptance requirements under the revised eIDAS regulation will not be able to pick and choose – they must accept all certified EUDI Wallets.

What is the role of the eID and Wallet Hub?

All certified EUDI Wallets will be integrated into Signicat's eID and Wallet Hub  as they become available. This will let our customers support both eIDs and new wallets without changing existing integrations or losing verification coverage. It allows for hybrid solutions, where users can choose to use their eIDs or an EUDI Wallet as they prefer, and offers the possibility of enriching transactions with required data when this is not available through the EUDI Wallet.

The eID and Wallet Hub will handle all necessary verifications that are part of interacting with the EUDI Wallet: it verifies the certification of the EUDI Wallet and the validity of the wallet instance, it checks the attestations on validity and the cryptographic signatures on the attestations against the issuers and their trust registration, it adheres to all revocation and selective disclosure policies, and it handles the consent for data sharing by the end user.

Can the EUDI Wallet be used for Qualified Electronic Signatures (QES)?

The EUDI Wallet can be used for qualified signing. In practice, this means a QES is created based on the identity contained in the PID. There are various alternative ways to support this, based on the wallet and the use case for which signing is required. As an example, the European Wallet Consortium (EWC) has published an overview of signing methods for use with EUDI Wallets.

For more information on electronic signatures, read our article: Electronic signature: what is it and how to use it.
 

How will EUDI Wallets impact Strong Customer Authentication (SCA) and payments?

The use of EUDI Wallets for authorising payment transactions has a broad set of motivations, but one stands out: when combining identity verification with a payment, fraud rates drop impressively. Guidance on using EUDI Wallets for Strong Customer Authentication (SCA), which allows payment initiation and authorisation, is being provided by the European Commission.

Read more in our article: Strong Customer Authentication (SCA) with EUDI Wallets: what financial services need to know.

Which attributes will EUDI Wallets contain?

All EUDI Wallets will launch with basic capabilities of providing identity attributes (PID), which can be used for authentication and identity proofing, and age-verification capabilities, allowing for proving a variety of "over/under a certain age" without disclosing full identity or even full date of birth.

Will all wallets contain the same identity data?
No. The identity attributes that are available in the EUDI Wallet depend on the national governments who issue them. Not all European governments are able to provide the same information for various reasons. As an example, Belgium provides a verified residential address in their national eID and will likely do so in their EUDI Wallet, while France does not have a data source capable of providing a verified residential address.

The data provided in PID attestations is covered by Implementing Regulation 2024/2977. It currently contains name, date of birth, place of birth, and nationality as mandatory elements. In a recent proposed update, a portrait photo is also considered as a mandatory element.

You may notice that PID does not cover a "unique personal identifier" as a mandatory option. This does not mean that it is impossible to uniquely identify a person through an EUDI Wallet. Some governments will provide such an identifier, as it is commonly used in their country; others will only do so under a specific disclosure policy (for example, for national governmental organisations only); and some will omit it entirely. On national levels, solutions are provided to governmental organisations to do cross-border identity matching.

Not all national PIDs will contain the same data set, and some of the PIDs might be too limited to perform accurate identity-matching. For use cases needing more attributes, these can come from other attestations issued by public or private sector providers. The Signicat eID and Wallet Hub also provides add-on capabilities that allow the usage of integrated data sources for data verification as part of hybrid solutions.

How will private sector credentials and other attestations work within the wallet?

Government agencies can add information such as a person’s residence permit, tax residency details, or real estate and vehicle ownership to a user’s wallet. Businesses can also add credentials like credit and mortgage information. This not only opens up significant opportunities for businesses and the public sector to share information more seamlessly with citizens, but also helps unlock the true potential of wallets.

Most use cases will need specific information, especially in B2B and B2C contexts. Many of those credentials will be made available through private sector issuing services.

This does however raise the question of how they could get paid for doing so, and how to motivate them to engage – a topic we have explored further in our article: The elephant in the European Digital Identity Wallet room: how can actors get paid?

What is the difference between physical and digital credentials in the EUDI Wallet?

We expect governments and QTSPs to provide many existing physical credentials in a digital format: mobile driving licences, digital passports, insurance cards, and others. These can be used with EUDI Wallets as an alternative to the physical cards, but they are not the same. There may be differences in the validity period and legal context of usage — for example, the use of a digital credential in an EUDI Wallet is purely voluntary.

How will EUDI Wallets affect customer onboarding under the new EU AMLR?

eIDAS is at the heart of compliant customer onboarding under the EU Anti-Money Laundering Regulation (AMLR). The EUDI Wallets are by far the cheapest options to use, but they will not cover all of the European citizens by mid-2027 when AMLR comes into force. And when they are available, they might not cover all of the needed attestations.

For organisations working on AMLR readiness, existing eIDs, EUDI Wallets, Qualified Electronic Signatures (QES), and hybrid identity approaches will therefore likely coexist for some time.

For more on AMLR compliance and the eIDAS toolkit, read our article: From fragmented rules to a single playbook: eIDAS and the future of AML compliance in Europe.

How do EUDI Wallets support European digital sovereignty against Big Tech?

The very effort of the EUDI Wallet is founded in the ambition to provide European trustworthy alternatives to identity wallets in an era where big-tech wallets (often used for payments) are emerging. It is clear that many existing big-tech wallets are quite capable of covering the EUDI Wallet use cases without too much effort, but experience shows that it is really hard to hold them to European requirements in terms of citizen protection.

EUDI Wallets are bound to a very strict regime in terms of security, privacy, and trust, and are forcibly upheld to European legislation ensuring compliance. This however does not change the fact that these wallets are working on mobile and other devices that are not European, and engaging with websites and services (made accessible by internet browsers and other applications) that depend on non-European technology.

Security and trust: can EUDI Wallets really be trusted?

There are quite some concerns about how safe and secure the EUDI Wallets are and the many ways in which they might be breached, especially given that they contain very relevant and personal data. That is why there are very strict technical and legal requirements in place, ensuring as much as possible that both users and service providers are protected.

The EUDI Wallets need to be certified by Member States to ensure they meet the requirements set out in the legislation. Qualified attestation issuers will be audited every two years to ensure that the necessary security measures are taken to address all risks. Every service provider that relies on information in the wallet , also known as relying parties, must register their activities and declare how they will use EUDI Wallet data. This is all embedded in the trust infrastructure of the European Digital Identity Framework.

Of course, anything can be breached and cybercrime is evolving. But take a look at some examples of how EUDI Wallets are an improvement to our current solutions for authentication and data sharing.

You only share what is needed. If you log on with an eID, the full data set is shared always, every time. If you have to provide a passport or other document, all information is shared. With the EUDI Wallet you can select only what is requested. Selective disclosure also allows relying parties to comply with General Data Protection Regulation (GDPR) data minimisation requirements more easily. They might want to use data from a passport, but requesting the full passport is often a violation of that requirement. The EUDI Wallet allows them to specifically target exactly what they need and nothing more.

Issuers of attestations are not allowed to know where the information they provided is being used. They cannot track and trace a user across services. When you log on with an eID, the central authentication service of that eID knows exactly for which service you authenticate – and when and how often.

Attestations can be cryptographically bound to the identity (PID) of the user, to other attestations, to the wallet, or even to the device. This makes it hard for someone else to use your attestations, unless you cooperate, of course.

For more details on privacy, security, and the trust model behind EUDI Wallets, read more on the European Commission guidance on EUDI Wallets, or dive into the technical details on security and the trust model in the Architecture Reference Framework (ARF)

Questions from Navigating the Wallet Era webinar (May 2025)


Is the wallet for EU citizens only, or residents too? 

Many different aspects of the legislation are designated to be set up by the Member States (MS).  They decide whether to issue wallets to residents alongside citizens, just as they do with national eIDs.  

If an individual holds multiple citizenships, would this imply he holds multiple EUDI wallets that operate independently and aren't synchronised at the EU level?

For the near future this will be the case, because the current approach for wallet certification, which includes the PID issuing and user onboarding on a national level will not allow issuance of PID into the wallet of a different Member State. 

Will non-EU countries like Norway participate in the EUDI Wallet?

 Yes. eIDAS applies to the EU and the European Economic Area (EEA): Iceland, Liechtenstein, and Norway, totaling 30 issuing countries. EU Member States must issue wallets by December 2026, while the EEA gets an extra year to comply. 

Will there be wallets for companies? 

Organisational wallets are part of eIDAS, but require further testing. Large-Scale Pilots (LSPs), like WE Build, which include Signicat, are actively testing real life use cases. Member States will issue (legal) Person Identification Data (PID) into organisational wallets, likely collaborating with national business registers 

Do all regulated industries need to accept the wallet at the same time? 

All regulated industries must accept the EUDI Wallet for strong customer authentication by December 2027. (Article 5.f)

Will the EU wallet make the existing European eIDs redundant? 

A person using an EUDI Wallet does not need to also use other eIDs. In that sense it’s redundant. However, usage of an EUDI Wallet will not be possible or desirable for all persons. Phasing out existing solutions for eIDs is not an easy task. Therefore, we expect that the existing eIDs will be around for a longer period of time, co-existing with the EUDI Wallets. 

These are also different solutions. The identity in an EUDI Wallet is based on a specific type of attestation called PID (Person Identification Data). The issuance of PID can be done through existing eIDs, but each Member State will set up and certify their own processes for this. The procedures for notification of national eIDs remain as a different part of eIDAS. 

What eIDAS-compliant or Signicat solutions help financial institutions obtain missing ID data (like place of birth) for AML compliance without requesting extra documents? 

Signicat's Data verification service offers access to 200+ national and international data registers for KYC and AML checks via the Signicat platform. Any financial institution can automate looking up missing data elements such as place of birth, credit worthiness and PEP & sanction checks from these data sources without requesting supplementary documents from a customer. This dramatically reduces friction in the digital customer journey. 

Additionally, Signicat helps wallet issuers, organisations and these data registry companies themselves issue these types of missing data into a user's digital wallet (including the EUDI wallet) 

Signicat’s eID and Wallet Hub currently also provides access to 35 European IDs which will be extended with EUDI wallets and other wallets for ensuring a seamless transition to wallet based future. 

How is this GDPR compliant with so much personal data being accessible? 

The amended version of eIDAS (including the Implementing Acts) is fully aligned to GDPR. The accessibility of the data is limited to the user of the wallet and can only with their explicit consent be shared with Relying Parties (who need to be registered in a MS). The data is stored on the phone or on storage accessible through the wallet (this will be different for different wallet solutions and can be decentralized) and only accessible and decryptable by the user. 

By allowing their users to use an EUDI Wallet, service providers can meet the GDPR requirements such as data minimization more easily because they can rely on high-assured confirmation of minimal claims and selective disclosure. 

If EUDI wallets are national, who is liable for unauthorised cross-border wallet usage? 

Liability is not directly addressed in the current legislation. eIDAS does however define levels of assurance (and the requirements for them), includes liability in the certification scheme of wallets and addresses liability for Trust Service Providers in case of non-compliance. 

Must a Relying Party (RP) register globally or pan-EU, and how can Signicat help? 

The Implementing Regulation on the registration of wallet-relying-parties describes that there will be national registers in the Member States where the Relying Party (RP) must register and obtain an access certificate. Each Member State will have their own policy for this, which can include issuance of registration certificates. Only RPs with an access certificate are able to interact with EUDI Wallets.   

If a RP works with an intermediary (such as Signicat) then Signicat will take over the registration responsibilities for that RP. This is described in section 3.11 of the ARF (note that the ARF is being updated regularly). 

The current legislation does not address “peer-to-peer” interaction (wallet-to-wallet by natural persons). It is part of the “discussion topics” in the ARF.

What will happen to private wallets such as Google Wallet? Will they also be included into EUDI Wallets? 

Member States are responsible for issuing and certifying EUDI Wallets on a national level. Each Member State will have their own approach for this. This can be issuance of their own developed wallet or designating a 3rd party (public or private) to do this on their behalf. Some Member States will have policies that allow for certification of any wallet meeting their requirements. This will allow any private-sector wallet to apply for certification as an EUDI Wallet. (Where it will then be certified as a specific national wallet.) 

Is there progress on digitally signing information, like emails or media, to verify identity? 

All data in the wallet is cryptographically signed and the transactions with the wallet also work with cryptographic signatures. This provides guaranteed and verifiable information on the contents (tamperproof) and the responsible source(s). All of this information can also be cryptographically linked to the identity (PID) of the user, the wallet or even the device of the wallet.  

Note that this is about signing of data and transactions. There’s also a trust services involving digital signatures, but that is about the signing of a document or file with the identity of the signer. 

Will the wallet allow verification of user authorisation for legal entities across the EU, similar to eHerkenning? 

This is at the core of what’s being worked on for organisational identity and wallets. These are part of eIDAS, but this area needs some more research and experience. This is being worked on in various Member States and Large Scale Pilots. The now-wrapped-up EWC has had a focus area on legal person identity (and organisational wallets) and it is the core topic of WE Build, an ongoing LSP. The eHerkenning suppliers will be collaborating in WE Build to work on approaches that can integrate eHerkenning with the EUDI Wallet. 

What will the EUDI wallet business model be for private sector? 

It is too early to know. Privacy regulations—like preventing issuers from tracking where attestations are used—make direct monetisation difficult. However, initiatives are exploring “billable events,” and EWC delivered a report on the ecosystem business model. For a deeper dive, read Signicat's Elephant in the room blog post. Ultimately, individual Member State policies will dictate commercial viability. 

Could an AI Agent use your wallet to represent you digitally? 

Wallets provide a strong identity anchor, making them excellent tools for future AI assistants. While wallet-based AI agents are currently just a concept, we expect them to emerge as EUDI Wallets mature.

Where to find more information

Finding simple answers within these complex regulations is difficult. For full technical details, refer to the eIDAS core regulation, the EDI legal framework, and the  Architectural Reference Framework (ARF). For a simpler breakdown, read our blog: “10 fundamental things businesses need to know about the EUDI Wallet”

Final Thoughts

For banks, fintechs, and governments, the EUDI Wallet is a strategic shift, not just an IT project. At Signicat, we help companies adapt, integrate, and thrive in this new wallet-based world. 

About the author

Esther Makaay is the VP of Digital identity at Signicat, a thought leader in the EU Digital Identity Wallet space and the winner of IDnext's Lifetime Achievement Award for her contribution to the field of Digital Identity. She is also a member of the EU Wallet Consortium (EWC) and is actively involved in several EUDI Wallet Large Scale Pilots (LSPs). She is frequently found sharing her insights on the EU Wallet at various conferences.