eIDAS 2.0 gives citizens direct control over their personal data by requiring that the European Digital Identity (EUDI) Wallet lets users decide exactly what information they share, with whom, and when. This is a significant shift from earlier digital identity systems, where data sharing was often opaque or bundled. The regulation places personal data sovereignty at the centre of digital identity in Europe. Below, we break down the most important questions citizens and organisations are asking about this new framework.
What rights does eIDAS 2.0 give citizens over their personal data?
Under eIDAS 2.0, citizens have the right to selectively share only the personal data that is strictly necessary for a given interaction, without exposing additional information. The regulation requires that the EUDI Wallet be designed with privacy by default, meaning data minimisation is built into the system rather than left to individual service providers. These rights apply to all EU citizens, residents, and businesses.
In practical terms, eIDAS 2.0 strengthens an individual’s position in digital interactions in several important ways:
- Informed consent: Users must explicitly agree to share any piece of data before it is transmitted to a third party.
- Data minimisation: Only the data genuinely required for a service can be requested. A service asking for your age cannot demand your full date of birth if a simple age confirmation suffices.
- Transparency: Citizens can see which organisations have requested access to their data and for what purpose.
- Portability: Identity data stored in the wallet can be reused across different services without starting from scratch each time.
- Revocability: Users can withdraw consent and stop sharing data with a particular service at any point.
These rights represent a meaningful step toward genuine personal data sovereignty. Rather than handing over a physical document or filling in lengthy forms, citizens interact with digital services on their own terms.
How does selective disclosure work in the EUDI Wallet?
Selective disclosure in the EUDI Wallet means that a user can share a single attribute from their identity, such as proof of age or nationality, without revealing any other personal details stored in the wallet. This is made possible through verifiable credentials and cryptographic techniques that allow specific claims to be confirmed without exposing the underlying data.
A straightforward example makes this concrete. Suppose you want to buy a ticket for an age-restricted event online. Instead of uploading a copy of your passport, the EUDI Wallet lets you share only a confirmed “over 18” signal. The service receives a cryptographically verified answer to the question it actually needs, and nothing more. Your name, address, and date of birth remain entirely private.
This approach is fundamentally different from how identity has traditionally worked online. Most current systems require users to hand over more information than necessary, simply because the infrastructure was not designed to separate individual attributes. The EUDI Wallet’s architecture, built on open technical specifications developed through large-scale pilot programmes across 26 EU Member States, is designed specifically to enable this kind of granular, attribute-level sharing.
For organisations, selective disclosure also reduces liability. When a service only receives the data it genuinely needs, it holds less sensitive information, which limits exposure in the event of a data breach.
Who can access the data stored in the EUDI Wallet?
Only the wallet holder controls access to data stored in the EUDI Wallet. No third party, including the wallet provider or the Member State that issued it, can access or share the user’s data without explicit consent. Access is granted on a per-interaction basis, meaning each data request must be individually approved by the user.
Organisations wishing to request data from a wallet must be registered as a Relying Party under the eIDAS 2.0 framework. This means they have been verified and accepted within the trust ecosystem, and users can see exactly who is making a request before deciding whether to respond. Unregistered or unverified parties cannot receive wallet data.
It is also worth noting that the EUDI Wallet is designed so that data is stored on the user’s own device rather than in a centralised database. This architectural choice significantly reduces the risk of large-scale data breaches and prevents any single organisation from building a profile of a user’s activity across different services. The wallet facilitates the exchange of identity data within a user’s home country and across other EU Member States, all while keeping the individual in control.
What is the difference between eIDAS 2.0 and GDPR data rights?
eIDAS 2.0 and the GDPR both protect personal data, but they operate at different levels. The GDPR sets out broad legal rights around how organisations collect, store, and process personal data. eIDAS 2.0 goes a step further by defining the technical and regulatory infrastructure that actively enforces data minimisation and user control at the point of interaction, before data is even shared.
Think of it this way: the GDPR gives you the right to request that an organisation delete your data after the fact. eIDAS 2.0 gives you the technical means to avoid sharing unnecessary data in the first place. The two frameworks are complementary rather than competing.
There are a few key distinctions worth understanding:
- Scope: The GDPR applies to all personal data processing by organisations. eIDAS 2.0 specifically governs digital identity, authentication, and trust services across the EU.
- Mechanism: The GDPR relies on legal obligations and enforcement. eIDAS 2.0 embeds data control directly into the technical architecture of the EUDI Wallet.
- Timing: GDPR rights are often exercised after data has been shared. eIDAS 2.0 operates at the moment of sharing, giving users real-time control over what leaves their wallet.
- Enforcement: Both frameworks carry compliance obligations for organisations, but eIDAS 2.0 introduces specific requirements around Relying Party registration and technical interoperability that go beyond GDPR’s scope.
For organisations operating in regulated sectors, both frameworks must be addressed together. Compliance with one does not automatically mean compliance with the other.
How can organisations ensure compliance with eIDAS 2.0 data control requirements?
Organisations can ensure compliance with eIDAS 2.0 data control requirements by registering as a Relying Party within the trust framework, updating their data request practices to align with data minimisation principles, and integrating their systems with EUDI Wallet-compatible infrastructure. Compliance is not only a legal obligation but also a practical opportunity to streamline identity verification and reduce onboarding friction.
In 2026, Member States are legally required to make the EUDI Wallet available to all citizens, residents, and businesses. This means organisations across financial services, government, and healthcare need to be ready to accept wallet-based credentials as a valid form of identity verification. Organisations that delay preparation risk both regulatory non-compliance and a poor user experience compared to competitors who have already integrated wallet-ready flows.
Practical steps organisations should take include reviewing which personal data they currently collect during onboarding or verification processes, identifying where data requests can be reduced to the minimum necessary, and working with identity infrastructure providers who already support verifiable credentials and eIDAS 2.0 standards.
How TrustTech helps organisations with eIDAS 2.0 data control
Preparing for eIDAS 2.0 is not just a compliance exercise. It is an opportunity to build a more efficient, user-friendly, and trustworthy digital identity infrastructure. TrustTech supports organisations in making this transition with practical expertise and technology that is ready for the EUDI Wallet era.
Working with TrustTech, organisations can:
- Implement wallet-ready identity verification that supports selective disclosure and data minimisation from day one
- Replace repeated identity checks with reusable, cryptographically verified credentials that work across services and borders
- Integrate qualified digital signatures and identity-linked consent into existing workflows without rebuilding everything from scratch
- Navigate the regulatory requirements of eIDAS 2.0 alongside GDPR, AML, and KYC obligations through a single, coherent platform
- Reduce onboarding drop-off and compliance overhead simultaneously, turning regulatory readiness into a measurable business advantage
TrustTech’s platform sits between the parties that need to interact, enabling secure and trusted digital exchanges without creating new data silos or dependencies. Whether your organisation operates in finance, government, healthcare, or another regulated sector, TrustTech brings the technical depth and implementation experience needed to move from complexity to clarity. Ready to take the next step? Get in touch with TrustTech to discuss how your organisation can prepare for eIDAS 2.0.