Regulation (EU) 2024/1183, known as eIDAS 2.0, which entered into force on 20 May 2024, establishes a European Digital Identity Wallet (the EUDI Wallet). Each Member State must offer its citizens an application capable of holding identity documents, attestations and supporting credentials, interoperable across the Union. The stated objective is twofold: to simplify access to online and public services, and to take back control of personal data from the major platforms. The text also promises safeguards — selective disclosure of attributes and user control. The real issue is not the existence of the tool, but whether these guarantees are actually upheld.
Definition. The EUDI wallet is a mobile application, provided or certified by each Member State, allowing verifiable credentials (identity, diplomas, licences, attestations) to be stored and presented in a cryptographically controllable way. "Selective disclosure" refers to the ability to prove only a specific attribute — for example "I am over 18" — without revealing one's name or date of birth.
eIDAS 2.0 extends the first eIDAS regulation of 2014, centred on cross-border electronic identification and digital signatures. The novelty of 2024 is the wallet: a personal identity container that each Member State must make available, accompanied by common technical specifications (the Architecture and Reference Framework) intended to guarantee interoperability between countries. The text was adopted on 11 April 2024 and published in the Official Journal of the Union on 30 April 2024; Member States then have 24 months after the implementing acts enter into force to provide at least one wallet, placing the deadline at the end of 2026.
The intended coverage is broad. The wallet is meant to hold, beyond the identity document, attestations from the physical world: one thinks of the mobile driving licence, whose ISO/IEC 18013-5:2021 standard already defines presentation from a phone with cryptographic verification of authenticity. It is one of the first "physical world" credentials to migrate to the digital wallet, foreshadowing the moment when all attestations — diplomas, rights, authorisations — could reside there.
The justifications put forward by the Union are concrete and, in part, verifiable. Three drivers dominate:
These objectives are not mere window-dressing: the absence of reliable digital identity has a real cost, in exclusion and in fraud. But recognising the legitimacy of a goal does not exempt one from examining the risks of the tool that serves it. This is precisely the honest stance: neither denial of usefulness, nor blindness to danger.
The regulation does not ignore the fears: it inscribes protection principles in the text itself. Three verifiable properties deserve to be followed closely, for they are what distinguish a tool of sovereignty from a point of control.
A point of honesty is needed: these guarantees figure in the regulation and its specifications, but their real value will depend on the technical implementation by Member States and the vigilance of data protection authorities. The European Data Protection Supervisor (EDPS) notes, in its December 2025 analysis, that wallets already allow selective disclosure but do not yet meet the non-correlation ("unlinkability") requirements: a legal principle is only a bulwark if it is verifiable and technically realised. The promise is not the proof; the architecture must be demanded, not merely announced.
The identity wallet is dangerous neither by its existence nor by its convenience, but by its capacity for aggregation: the more credentials it concentrates, the more it becomes a single point of control whose cut-off would amount to a form of digital civil death. If, tomorrow, access to an account, a health service or a subscription depended on a single identifier, any failure — technical or political — of that identifier would become an exclusion. This is also the concern voiced by the Electronic Frontier Foundation, which warns of risks of "over-identification" and traceability if non-correlation guarantees are not imposed by default.
Foreign experience illuminates the two faces of the tool. In India, the Aadhaar system has registered the biometric data of around 1.4 billion people: an instrument of mass inclusion (access to accounts, to subsidies paid directly), but also a point of control that the Indian Supreme Court had to bound, ruling in 2018 that the system was constitutional while restricting its mandatory character for private actors. Inclusion and control are not two opposed systems: they are two uses of the same infrastructure. The architectural choice — centralised like Aadhaar, or distributed like Estonia's X-Road, where data remains spread across administrations — determines the reversibility of the power conferred.
One must set aside a determinism: an announced digital identity project is not a successful project. In the United Kingdom, the GOV.UK Verify programme was a documented failure — the National Audit Office noted in 2019 that it had reached only around 3.6 million users out of the 25 million targeted, with a verification success rate of around 48%, leading to its abandonment. Conversely, Singapore shows massive and largely consented adoption with SingPass, used by around 97% of adults.
The lesson is twofold. On one hand, where access is constrained — as in Nigeria, where the mandatory linking of national identity number and SIM card led to the suspension of tens of millions of lines — digital identity becomes a lever of coercion. On the other, where choice is left, citizens may not adopt if the benefit is unclear or if control is feared. The eIDAS 2 regulation states the non-mandatory principle: it is precisely this principle that will have to be defended over time.
The debate is not only institutional: it is also technical, and public. In 2024, a group of leading cryptographers — among them Anna Lysyanskaya, Jaap-Henk Hoepman, Bart Preneel, Carmela Troncoso and René Mayrhofer — sent the Commission's working group a critical opinion on the Architecture and Reference Framework (ARF). Their objection is precise: the chosen credential format (SD-JWT) allows selective disclosure but, in their view, does not guarantee the non-correlation required by the regulation, since it may leave a traceable thread between presentations. They advocate "anonymous credentials," designed precisely to authenticate without enabling tracking. The point must be held coolly: it is a disagreement about implementation, not a finding that surveillance is written into the law — the text itself requires non-correlation; the issue is that it be technically honoured.
The EUDI wallet is not deployed in a legal vacuum. The General Data Protection Regulation (GDPR, EU 2016/679) strictly governs the processing of personal data and confers enforceable and free rights — access, rectification, erasure, objection, portability; biometric data are "sensitive" data benefiting from reinforced protection. Moreover, the European regulation on artificial intelligence (AI Act, EU 2024/1689) explicitly prohibits, since February 2025, social scoring by public authorities and the untargeted scraping of facial images. The Union has not legalised a control grid: it has, by law, proscribed several of its most dystopian building blocks.
A caveat is nonetheless needed, to remain honest about the blind spots. The "trust services" strand of eIDAS, and notably its Article 45 on qualified website authentication certificates (QWACs), drew public opposition from Mozilla, the EFF and hundreds of security experts, who saw in it a risk of weakening web encryption if browsers were compelled to trust authorities designated by the states. This debate, distinct from the wallet itself, reminds us that the whole edifice is not free of serious technical criticism.
Will the European digital identity wallet be mandatory? No. Regulation (EU) 2024/1183 obliges each Member State to provide a wallet, but provides that its use remains under the control of the citizen and is not imposed. The practical risk lies elsewhere: if too many services required its use, the "optional" would become binding in fact — hence the importance of preserving alternatives.
Does selective disclosure really protect my privacy? In principle, yes: it allows an attribute (majority, for example) to be proven without revealing the rest of one's identity. But it is a design guarantee, whose effectiveness depends on the technical implementation by each Member State. At this stage, the EDPS notes that wallets allow selective disclosure but do not yet meet the non-correlation requirements. The principle is sound; it must be verified that it is upheld.
Does eIDAS 2 establish a European-style social credit? No, and this claim is inaccurate. The wallet is a tool for presenting credentials, not a scoring system. The AI Act (EU 2024/1689) even explicitly prohibits social scoring by public authorities since February 2025. Confusing verifiable identity with a citizen score is rumour, not document.
To situate digital identity within the whole file — its coupling with digital currency and the biometric gaze, and the constant distinction between capability and intention — read the pillar article: Digital identity, panopticon or simplification. And if you want the complete investigation, marked out level of certainty by level of certainty and grounded in official texts, Volume 2 — The Architecture of Control takes up each piece of the file.
No. Regulation (EU) 2024/1183 obliges each Member State to provide a wallet, but provides that its use remains under the control of the citizen and is not imposed. The practical risk lies elsewhere: if too many services required its use, the "optional" would become binding in fact — hence the importance of preserving alternatives.
In principle, yes: it allows an attribute (majority, for example) to be proven without revealing the rest of one's identity. But it is a design guarantee, whose effectiveness depends on the technical implementation by each Member State. At this stage, the EDPS notes that wallets allow selective disclosure but do not yet meet the non-correlation requirements. The principle is sound; it must be verified that it is upheld.
No, and this claim is inaccurate. The wallet is a tool for presenting credentials, not a scoring system. The AI Act (EU 2024/1689) even explicitly prohibits social scoring by public authorities since February 2025. Confusing verifiable identity with a citizen score is rumour, not document.
Dossier : Monnaie & identité numérique : l'architecture du contrôle
TOME 2: L'Architecture du Contrôle
Accueil · Collection · Journal · Dossiers · Sources