eIDAS 2.0 does not prescribe a single, standardized backup and recovery mechanism for the European Digital Identity Wallet. Instead, the regulation sets out high-level principles around security, continuity, and user control, while leaving the technical implementation of backup and recovery to Member States and wallet providers. This means the practical approach can vary, but the underlying rules about what can and cannot be backed up are consistent across the framework. The sections below unpack the key questions organizations and users are asking about wallet backup and recovery under eIDAS 2.0.
What data can actually be backed up in an EUDI Wallet?
Not all data stored in a European Digital Identity Wallet can or should be backed up in the traditional sense. The EUDI Wallet holds two broad categories of data: the wallet itself (the application and its configuration) and the credentials stored inside it, such as a mobile driving licence, a diploma, or a health insurance card. Whether each of these can be backed up depends on the nature of the credential and the rules set by the issuer.
Credentials issued by governments or regulated institutions typically carry strict rules about portability. A qualified electronic signature certificate, for example, is cryptographically bound to a specific device or secure element. Copying it to another device is not simply a technical action – it may violate the security requirements that make the credential legally valid in the first place.
Personal configuration data, such as preferences, linked accounts, and transaction history, is generally easier to back up because it does not carry the same cryptographic constraints. However, it still falls under GDPR, which means users must have control over it and organizations must handle it responsibly.
In practice, the safest mental model is this: the wallet application can be restored, but individual credentials usually need to be re-issued by the original issuer rather than copied from a backup.
How does eIDAS 2.0 define wallet backup and portability rules?
eIDAS 2.0 does not use the term “backup” explicitly, but it does establish clear obligations around continuity, portability, and user control that directly shape how backup and recovery must work. The regulation requires that users retain sovereignty over their identity data and that wallet solutions do not create lock-in with a single provider or Member State.
Portability is a key principle. Users must be able to move between wallet solutions without losing access to their identity data or being forced to re-verify from scratch unnecessarily. This connects directly to the regulation’s broader goal of interoperability across EU Member States.
The Architecture and Reference Framework (ARF), which provides the technical blueprint for the EUDI Wallet, goes further by specifying requirements for wallet instance management. This includes how wallet instances are activated, suspended, and revoked, all of which are relevant to what happens when a user needs to recover access. The ARF does not mandate a specific backup format, but it does require that wallet providers support processes that allow users to regain access in a secure and verifiable way.
For organizations operating in regulated sectors such as financial services or government, understanding these portability obligations is important because it affects how identity data flows between systems and what continuity planning is required.
What happens when a user loses access to their EUDI Wallet?
When a user loses access to their EUDI Wallet, whether through a lost device, a forgotten PIN, or a software failure, they cannot simply restore it from a cloud backup the way they might restore a photo library. The recovery process is more structured and involves multiple parties, because the integrity of the credentials inside the wallet must be preserved.
The general recovery path works as follows:
- Wallet instance revocation: The compromised or lost wallet instance is revoked to prevent misuse. This is a critical security step that happens before any recovery begins.
- Identity re-verification: The user re-verifies their identity through the wallet provider or the relevant national identity scheme. This is how the system confirms that the person requesting recovery is the legitimate owner.
- New wallet instance activation: A new wallet instance is issued to the user on their new or recovered device.
- Credential re-issuance: Individual credentials, such as a driving licence or educational qualification, are re-requested from their original issuers. They are not copied from the old wallet but re-issued fresh.
This process is more involved than a typical app restore, but it is intentional. The security model of the EUDI Wallet is built on the assumption that credentials are tied to verified identities and secure devices, not to files that can be freely copied.
Who is responsible for wallet recovery – the user, the provider, or the issuer?
Responsibility for wallet recovery is shared across three parties, and understanding who does what is essential for organizations building services around the EUDI Wallet.
- The wallet provider is responsible for managing the wallet application itself, including the ability to revoke a lost instance and issue a new one. Under eIDAS 2.0, wallet providers must meet certification requirements and are accountable for the security and continuity of the wallet infrastructure.
- The credential issuer is responsible for re-issuing credentials when a wallet is recovered. An issuer, such as a national authority or a licensed institution, cannot simply transfer a credential from one wallet to another without re-verifying the underlying data. This protects the integrity of the credential.
- The user is responsible for initiating the recovery process and completing any required identity verification steps. The user also bears responsibility for keeping their recovery credentials, such as backup codes or linked authentication methods, secure and accessible.
In practice, Member States play a coordinating role because they are legally required to provide wallets to citizens and residents. This means national governments carry an overarching duty of care to ensure that recovery processes are accessible, clear, and do not leave users permanently locked out of their digital identity.
What are the security risks of backing up a digital identity wallet?
Backing up a digital identity wallet introduces real security risks that are different from backing up ordinary data. The core risk is that a backup could be used to clone a wallet, allowing an attacker to impersonate the legitimate user. This is why the EUDI Wallet’s security architecture is designed to limit what can be copied and under what conditions.
The most significant risks include:
- Private key exposure: Cryptographic keys that underpin qualified signatures and high-assurance credentials must never leave the secure element of a device. If a backup process extracts these keys, it breaks the security model entirely.
- Replay attacks: A stolen backup could allow an attacker to replay credential presentations, potentially gaining access to services or signing documents fraudulently.
- Insecure storage: If backup data is stored in an unencrypted or weakly protected environment, such as an unsecured cloud account, it becomes a target for data breaches.
- Phishing recovery flows: Attackers may attempt to trigger recovery processes fraudulently, impersonating users to take over wallet instances.
These risks explain why the EUDI Wallet framework favors re-issuance over restoration. Re-issuance requires the user to re-verify their identity each time, which is a stronger security guarantee than trusting that a backup file has not been compromised. Organizations working on digital identity solutions should factor these risks into their architecture and user journey design from the start.
How should organizations prepare for wallet recovery scenarios?
Organizations that rely on EUDI Wallets for onboarding, authentication, or compliance purposes need to plan for the reality that users will occasionally lose access to their wallets. A recovery event should not mean starting a business relationship from scratch, but it does require clear processes on the organization’s side.
Practical steps organizations should take include:
- Design for re-verification flows: Build onboarding and authentication flows that can accommodate a user presenting a freshly recovered wallet with re-issued credentials. Do not assume that a returning user will always have the same wallet instance they used initially.
- Maintain your own verified records: Where regulations allow, store the outcome of a verified identity check rather than relying solely on the wallet. This means a recovered wallet can be re-linked to an existing customer record without requiring a full re-onboarding.
- Understand issuer dependencies: Map out which credentials your services depend on and which issuers are responsible for them. If a key credential takes days or weeks to re-issue, that creates a gap in your service continuity.
- Communicate clearly with users: Recovery processes that are confusing or opaque lead to drop-off and support costs. Invest in clear user communication about what happens when a wallet is lost and what steps are needed.
- Stay aligned with evolving standards: The ARF and national implementation guidelines are still being refined. Organizations in sectors such as healthcare or government services should monitor updates and adjust their processes accordingly.
Recovery planning is not just a technical exercise. It connects to compliance, user experience, and operational resilience, which means it deserves attention from legal, IT, and business teams together. Organizations looking for broader guidance on how to approach digital identity readiness can find useful starting points in the TrustTech resource library.
How TrustTech helps with EUDI Wallet backup and recovery readiness
Preparing for wallet recovery scenarios requires more than technical knowledge – it requires a clear understanding of how eIDAS 2.0 obligations translate into practical infrastructure, compliance processes, and user journeys. TrustTech helps organizations across regulated sectors do exactly that.
Working with TrustTech, organizations can:
- Map their current identity infrastructure against EUDI Wallet requirements, including continuity and recovery obligations
- Design onboarding and re-verification flows that handle wallet recovery without creating friction or compliance gaps
- Build reusable identity and compliance data that reduces the impact of a wallet recovery event on the user experience
- Stay ahead of evolving ARF specifications and national implementation guidelines that affect backup, portability, and recovery rules
- Implement qualified electronic signatures and trust services that meet the security requirements relevant to credential re-issuance
Whether your organization is in the early stages of understanding eIDAS 2.0 or actively building wallet-ready infrastructure, TrustTech provides the expertise and technology to move forward with confidence. Get in touch with TrustTech to discuss how we can support your digital identity readiness.