eIDAS 2.0 and GDPR are designed to work together, not against each other. eIDAS 2.0 governs how digital identities are established, verified, and used across Europe, while GDPR governs how personal data is processed. Both frameworks share a common foundation: privacy by design, data minimisation, and user control. For organisations implementing the EUDI Wallet or verifiable credentials, this means compliance with one framework generally supports compliance with the other, but there are specific overlaps and responsibilities that require careful attention.
The sections below walk through the most common questions organisations ask when trying to understand how these two major European regulations interact in practice.
Where do eIDAS 2.0 and GDPR actually overlap?
eIDAS 2.0 and GDPR overlap wherever personal data is used to establish or verify digital identity. Both frameworks require data minimisation, purpose limitation, and user consent where applicable. eIDAS 2.0 builds on these GDPR principles by making them structural requirements of the European Digital Identity ecosystem, particularly through the design of the EUDI Wallet.
The most visible area of overlap is data minimisation. GDPR requires that only the minimum necessary personal data is collected for a given purpose. eIDAS 2.0 reinforces this directly: the EUDI Wallet is designed so that users share only the specific attributes needed for a transaction, and nothing more. For example, a user proving they are over 18 can share that fact alone, without revealing their date of birth, name, or any other personal detail.
Both frameworks also emphasise user control. GDPR gives individuals rights over their personal data, including the right to access, correct, and erase it. eIDAS 2.0 extends this by giving users active control over what identity data is shared, with whom, and when. This is not just a technical feature of the wallet; it is a regulatory requirement built into the architecture of the entire identity ecosystem.
Finally, both frameworks require organisations to implement appropriate security measures when handling personal data. Under eIDAS 2.0, trust service providers and relying parties must meet defined security standards. These requirements align closely with the GDPR obligation to implement technical and organisational measures to protect personal data.
Does eIDAS 2.0 override or conflict with GDPR?
No, eIDAS 2.0 does not override GDPR. The two regulations operate in parallel and are mutually reinforcing. eIDAS 2.0 explicitly states that it does not affect the application of GDPR. Where eIDAS 2.0 introduces new obligations around digital identity, those obligations must still be fulfilled in a way that is consistent with GDPR requirements.
In practice, this means that organisations cannot use eIDAS 2.0 compliance as a reason to bypass their GDPR obligations. For instance, even if a relying party is legally required to verify a user’s identity under eIDAS 2.0, it must still have a valid legal basis under GDPR for processing the personal data involved in that verification.
Where potential tension can arise is around record-keeping and audit trails. eIDAS 2.0 requires that certain transactions involving qualified electronic signatures and trust services are logged and verifiable. GDPR, on the other hand, limits data retention to what is necessary. Organisations need to ensure that their audit and logging practices are proportionate, clearly documented, and tied to a legitimate purpose under both frameworks.
The good news is that the EU legislator designed eIDAS 2.0 with GDPR in mind. The architecture of the EUDI Wallet, for example, is built around selective disclosure and unlinkability, meaning that wallet providers cannot track which services a user accesses. This is a direct response to GDPR’s requirements around purpose limitation and data minimisation.
How does the EUDI Wallet affect GDPR data subject rights?
The EUDI Wallet strengthens GDPR data subject rights in meaningful ways. By giving users direct control over which attributes they share and with whom, the wallet makes it easier for individuals to exercise their rights to data minimisation and purpose limitation. At the same time, organisations accepting wallet-based credentials must still fulfil their obligations under GDPR when they process the data they receive.
Consider the right to erasure. Under GDPR, individuals can request that an organisation deletes their personal data. When identity data is shared via the EUDI Wallet, the relying party receives a verified credential containing specific attributes. That data, once received and processed, is still subject to GDPR. The relying party must have a retention policy in place and be prepared to respond to erasure requests where no legal obligation requires it to keep the data.
The wallet also affects how organisations think about consent and transparency. GDPR requires that individuals are clearly informed about how their data will be used. The EUDI Wallet’s selective disclosure mechanism makes it easier to present users with a clear picture of exactly what data is being requested and why. This supports GDPR’s transparency requirements in a way that traditional identity verification processes often struggle to achieve.
One area that organisations in financial services and other regulated sectors should pay attention to is the interaction between wallet-based identity verification and their existing GDPR consent frameworks. Accepting a credential from an EUDI Wallet does not replace the need to inform users about downstream data processing. The wallet handles the identity verification step; your organisation still owns the data processing relationship that follows.
Who is the data controller under eIDAS 2.0 — the wallet provider, the relying party, or the user?
Under eIDAS 2.0, data controller responsibilities are distributed across multiple parties, depending on the specific processing activity. The wallet provider, the relying party, and in some cases the issuer of a credential each have distinct roles, and GDPR’s concept of data controllership applies to each of them separately for their own processing activities.
The wallet provider is responsible for the infrastructure that stores and transmits identity attributes. However, eIDAS 2.0 explicitly prohibits wallet providers from tracking which services a user accesses or combining data across transactions. This limits the wallet provider’s role as a data controller to the minimum necessary for operating the wallet itself.
The relying party, meaning the organisation that requests and receives identity data from the wallet, becomes a data controller the moment it processes that data. From that point, all GDPR obligations apply: lawful basis for processing, data subject rights, retention limits, and security requirements. Organisations in government services and healthcare that rely on identity verification for access to sensitive services need to be particularly clear on this point.
The credential issuer, such as a government authority that issues a digital driving licence or qualification certificate, is a data controller for the issuance process. Once the credential is in the user’s wallet, the issuer’s processing role typically ends, unless it is required to maintain records for legal or audit purposes.
The user is not a data controller in the legal sense, but they are the central actor in the consent and disclosure flow. The wallet puts users in a position of genuine control, which is consistent with GDPR’s emphasis on individual rights, without making them legally responsible for the processing that happens downstream.
What compliance steps should organisations take to align eIDAS 2.0 with their GDPR obligations?
Organisations should treat eIDAS 2.0 implementation as an opportunity to strengthen their GDPR compliance posture, not as a separate compliance exercise. The two frameworks share enough common ground that a well-designed digital identity approach can satisfy both simultaneously. The key is to be deliberate about how identity data flows through your systems and who is responsible at each stage.
Here are the most important steps to take:
- Map your identity data flows. Understand exactly what personal data is collected, from which sources, for what purpose, and how long it is retained. This is a GDPR requirement and the foundation of any eIDAS 2.0 implementation.
- Establish a lawful basis for each processing activity. Accepting identity credentials from an EUDI Wallet still requires a valid legal basis under GDPR. Document this clearly, especially where you are relying on legal obligation or legitimate interest rather than consent.
- Review your privacy notices. Users must be informed about how their identity data will be processed after verification. Update your privacy notices to reflect the wallet-based verification flow and any new data sources.
- Implement data minimisation by design. Work with your technical teams to ensure that your systems only request the attributes they genuinely need. This is both a GDPR requirement and a core principle of eIDAS 2.0.
- Define your data retention policies for identity data. Audit logs and identity records must be retained only as long as necessary. Balance eIDAS 2.0 audit requirements with GDPR’s storage limitation principle.
- Clarify data controller responsibilities with third parties. If you work with a trust service provider or wallet infrastructure partner, ensure that your data processing agreements are up to date and clearly define who is responsible for what.
Organisations in sectors such as healthcare and pharmaceuticals face additional complexity because they process special category data under GDPR. In these cases, a data protection impact assessment (DPIA) is strongly recommended before implementing any eIDAS 2.0-based identity verification process.
How TrustTech helps with eIDAS 2.0 and GDPR compliance
Aligning eIDAS 2.0 with your existing GDPR obligations is not just a legal exercise. It requires the right technical infrastructure, clear data governance, and a practical implementation approach that works for your organisation and your users.
TrustTech supports organisations across regulated sectors in building digital identity solutions that are compliant with both frameworks from the ground up. Working with TrustTech means you get:
- A platform built on European digital identity standards, including eIDAS 2.0 compliance by design
- Verifiable credentials and selective disclosure capabilities that support GDPR data minimisation requirements
- Reusable identity flows that reduce the need for repeated data collection, lowering your compliance risk
- Identity linked to qualified electronic signatures, with a complete audit trail for every interaction
- Practical implementation expertise for finance, government, healthcare, and other regulated sectors
Whether you are just starting to assess the implications of eIDAS 2.0 for your organisation, or you are ready to build a wallet-ready identity infrastructure, TrustTech can help you move forward with confidence. Explore our digital identity solutions or get in touch with our team to discuss your specific compliance and implementation needs.