Citizens have full control over what data they share from their EUDI Wallet. The European Digital Identity Wallet is built on the principle that you decide what information to share, with whom, and when. No data is shared without your explicit consent, and you are never required to hand over more than what a specific interaction actually needs.
This design is not accidental. It reflects the core requirements of eIDAS 2.0, which place user control and data minimisation at the heart of the European Digital Identity framework. Whether you are accessing a government service, opening a bank account, or simply proving your age, the wallet puts you in charge of your own data.
The sections below walk through exactly how that control works in practice, from what the wallet stores to what happens to your data after it has been shared.
What data does the EUDI Wallet actually store about you?
The EUDI Wallet stores verified digital documents and identity attributes that you choose to add to it. This can include your national identity credentials, but also a wide range of other documents such as a driving licence, academic qualifications, health certificates, travel credentials, and more. The wallet does not automatically collect or store data beyond what you actively load into it.
Think of the wallet as a secure digital equivalent of your physical wallet or document folder. Just as you decide which cards and documents to carry with you, you decide what goes into your EUDI Wallet. The difference is that the digital version stores verified credentials issued by trusted authorities, such as your national government, a university, or a healthcare provider.
Importantly, the data in your wallet is stored on your own device, not on a central server controlled by a government or private company. This architecture is a deliberate privacy safeguard. It means no single organisation has a complete view of everything your wallet contains.
Examples of what the wallet can store include:
- National identity data (name, date of birth, nationality)
- A mobile driving licence
- Educational diplomas and certificates
- Healthcare documents and prescriptions
- Travel credentials
- Payment-related credentials
- Social security information
How does selective disclosure let you share only what’s needed?
Selective disclosure is the mechanism that allows you to share a specific piece of information from your EUDI Wallet without revealing anything else. Instead of handing over an entire document, you share only the single attribute that is actually required. For example, you can prove you are over 18 without disclosing your exact date of birth, or confirm your nationality without sharing your full address.
This is one of the most important privacy features of the European Digital Identity Wallet, and it represents a significant improvement over how identity verification works today. When you show a physical ID card to prove your age, the other party sees your name, address, and date of birth, even though they only needed to know your age. Selective disclosure eliminates that unnecessary exposure.
In practice, when a service asks your wallet for a specific piece of data, you see exactly what is being requested before anything is shared. You can then approve or decline the request. If you approve, only that specific attribute is transmitted. Nothing more leaves your wallet.
This approach directly supports the principle of data minimisation, which is a core requirement under both eIDAS 2.0 and the GDPR. Sharing only what is strictly necessary reduces the risk of personal profiling and limits the potential impact of any data breach on the receiving side.
Real-world examples of selective disclosure in action include:
- Booking a cinema ticket for an age-restricted film: share only that you are 18 or older, nothing else.
- Registering for a public service: share your postal code for a local vote, without disclosing your full identity.
- Opening a bank account online: share the identity attributes the bank needs for verification, without handing over unrelated credentials.
- Accessing a healthcare portal: share your patient identifier and relevant health credentials, not your driving licence or education history.
Who can request access to your EUDI Wallet data?
Only officially recognised and registered organisations, known as relying parties, can request data from your EUDI Wallet. These are public authorities and private businesses that have been formally registered under the eIDAS 2.0 framework. A random website or unverified app cannot simply ask your wallet for information.
Relying parties must identify themselves to the wallet before making any data request. This means you can see who is asking for your data and for what purpose before you decide whether to share anything. The wallet will display the identity of the requesting organisation, the specific attributes being requested, and the stated reason for the request.
This requirement creates a layer of accountability that does not exist with many current identity verification methods. If an organisation wants to access data from citizens’ wallets, it must be part of the trusted ecosystem established under eIDAS 2.0. Government services and regulated private sector organisations in areas such as finance, healthcare, and telecommunications are among the sectors actively preparing to become recognised relying parties.
You always have the right to decline a data request. If you do not consent, no data is shared, and you can still choose to use alternative methods to access the service if available.
Can you see and revoke which organisations have accessed your data?
Yes. The EUDI Wallet is designed to give you a clear overview of which organisations have received data from your wallet and when. This transparency log allows you to track your data sharing history and understand exactly where your information has gone.
This level of visibility is a meaningful step forward compared to how personal data flows today, where it is often difficult or impossible to know which third parties have received your information. With the EUDI Wallet, that history is visible to you directly within the app.
Beyond visibility, the wallet framework also supports the ability to withdraw consent or limit future data sharing with specific organisations. While the exact implementation of revocation features may vary slightly depending on the wallet solution provided by each Member State, the underlying eIDAS 2.0 regulation requires that users maintain meaningful control over their data, including the ability to manage and review ongoing data sharing relationships.
This kind of user-facing control is especially relevant for organisations in financial services and other regulated sectors, where data governance and audit trails are critical requirements. For citizens, it means that consenting to share data once does not mean giving up control permanently.
What happens to your data after a relying party receives it?
Once a relying party receives data from your EUDI Wallet, that data is governed by existing EU data protection law, primarily the GDPR. The organisation that received your data is legally obligated to use it only for the specific purpose stated at the time of the request, and they cannot retain it longer than necessary for that purpose.
This is an important distinction. The EUDI Wallet controls what data leaves your device and under what conditions. But once data has been transmitted to a relying party, the wallet itself no longer governs what happens to it. That is where the GDPR takes over.
What this means in practice is that relying parties cannot use your wallet data for purposes beyond what they declared when requesting it. They cannot sell it to third parties without a separate legal basis, and they must comply with data subject rights, including your right to access, correction, and erasure under the GDPR.
The combination of eIDAS 2.0 and the GDPR creates a two-layer protection model. The wallet controls the moment of disclosure, ensuring you only share what is needed with verified parties. Data protection law then governs what happens to that data once it has been shared. Understanding this distinction helps organisations and citizens alike set realistic expectations about what EUDI Wallet data control actually covers.
For organisations preparing to integrate with the EUDI Wallet ecosystem, digital identity solutions need to account for both layers: the technical requirements for becoming a recognised relying party, and the compliance obligations that apply once user data is received.
How TrustTech helps organisations prepare for EUDI Wallet data privacy
Navigating the privacy architecture of the European Digital Identity Wallet is not just a technical challenge. It requires a clear understanding of eIDAS 2.0, GDPR obligations, relying party requirements, and the practical implications for your organisation’s systems and processes. That is exactly where TrustTech comes in.
TrustTech supports organisations across regulated sectors in preparing for and implementing the EUDI Wallet framework. This includes:
- Assessing your current identity infrastructure and identifying gaps relative to eIDAS 2.0 requirements
- Guiding your organisation through the process of becoming a recognised relying party
- Designing data minimisation and selective disclosure flows that meet both regulatory and user experience requirements
- Aligning your data governance and compliance frameworks with the obligations that apply once wallet data is received
- Supporting implementation across sectors including healthcare, finance, and government
Whether you are in the early stages of understanding what EUDI Wallet citizen data control means for your organisation, or ready to move into active implementation, TrustTech provides the expertise to make it practical and manageable. Get in touch with TrustTech to discuss how we can support your organisation’s journey toward trusted, privacy-respecting digital identity.