eIDAS 2.0 protects user privacy by giving people direct control over their identity data. Rather than forcing users to share full personal profiles, the regulation requires that only the minimum necessary information is disclosed in any given interaction. These protections apply to every EU citizen, resident, and business that uses a European Digital Identity Wallet, and they are built into the technical architecture of the system itself.
The sections below unpack the specific privacy rights users gain, how the technology enforces those rights, and what all of this means for organizations building compliant digital services.
What specific privacy rights does eIDAS 2.0 give users?
eIDAS 2.0 gives users the right to control what personal data they share, with whom, and for what purpose. Users can choose which attributes to disclose in any given transaction, keep track of which organizations have accessed their data, and refuse to share anything beyond what is strictly necessary for the service they are using. These rights are not optional features – they are legal requirements built into the regulation.
In practical terms, this means a user accessing a public service online can share only their name and address, without revealing their date of birth, national ID number, or any other data the service does not need. The same applies to private sector interactions, such as opening a bank account or verifying age for an online platform.
The core privacy rights eIDAS 2.0 establishes for users include:
- Data minimisation: Only the data strictly required for a specific purpose may be requested or processed.
- User consent and control: Users actively choose what to share before any data leaves their wallet.
- Transparency: Users can see which organizations have requested access to their data and for what reason.
- Portability: Users can carry their verified identity data across borders and services without re-verifying from scratch.
- Right to refuse: Users can decline data requests that go beyond what is necessary, without losing access to the core service.
These rights represent a significant upgrade from the original eIDAS regulation, which focused mainly on cross-border recognition of national eIDs without addressing personal data control at this level of detail.
How does selective disclosure work in the EUDI Wallet?
Selective disclosure allows a user to share only specific attributes from a credential, rather than the full document. In the EUDI Wallet, this means a user can prove they are over 18 without revealing their exact date of birth, or confirm their nationality without disclosing their home address. The wallet handles this at a technical level using cryptographic methods that make partial disclosures verifiable and tamper-proof.
Think of it this way: a traditional ID card shows everything at once. A digital wallet credential lets you present only the relevant field, while the receiving party can still verify that the underlying data is authentic and issued by a trusted source.
This is made possible through verifiable credentials and cryptographic techniques such as zero-knowledge proofs. These approaches allow a wallet to generate a proof that a specific claim is true (for example, “this person is older than 18”) without transmitting the underlying data point (the actual birth date). The verifying party receives a confirmed answer, not raw personal data.
For organizations, this changes how identity verification needs to be designed. Rather than collecting and storing full identity records, a service can request only the specific attributes it needs and receive a cryptographically verified response. This reduces data liability, simplifies compliance, and creates a better experience for users who are increasingly aware of how their personal information is handled. Organizations looking to understand how this fits into their digital identity solutions will need to align their verification flows accordingly.
How does eIDAS 2.0 prevent user tracking across services?
eIDAS 2.0 prevents cross-service user tracking by requiring that each interaction uses unlinkable or pseudonymous identifiers, so that different service providers cannot combine their data to build a profile of a user’s activity. This is a deliberate architectural requirement, not just a policy recommendation. The technical specifications for the EUDI Wallet include mechanisms that prevent any single party from tracking where and how often a user presents their credentials.
This matters because one of the biggest risks with digital identity systems is the potential to create a surveillance infrastructure. If every time you use your digital ID a central party or a network of service providers can log the interaction, your daily behavior becomes visible in ways that paper documents never allowed.
The EUDI Wallet addresses this through several technical and governance measures:
- Pseudonymous presentation: When a user presents credentials to a service, the wallet can generate a session-specific identifier rather than a permanent one, making it harder to link interactions across services.
- No central logging requirement: The architecture does not require a central registry to track when or where credentials are used.
- Wallet provider restrictions: Wallet providers are explicitly prohibited from collecting data about which services their users interact with.
- Selective attribute disclosure: By sharing only the minimum necessary attributes, users naturally limit the data footprint they leave behind with each service.
For sectors like financial services or healthcare, where users interact with multiple providers, these anti-tracking measures are especially relevant. They allow organizations to verify identity without creating unnecessary data dependencies or exposure.
What is the relationship between eIDAS 2.0 and GDPR?
eIDAS 2.0 and GDPR work together rather than in competition. GDPR sets the overarching legal framework for how personal data must be handled across the EU, while eIDAS 2.0 defines the technical and regulatory standards for digital identity specifically. Any processing of personal data within an eIDAS 2.0 context, including the use of EUDI Wallets, must comply with GDPR requirements such as lawful basis, purpose limitation, and data subject rights.
In practice, eIDAS 2.0 reinforces many GDPR principles at the technical level. Data minimisation, which is a core GDPR requirement, is built directly into the selective disclosure model of the EUDI Wallet. Privacy by design, another GDPR obligation, is reflected in the wallet’s architecture, which defaults to sharing the least possible data rather than the most.
Where the two frameworks interact most directly is in the area of user consent. Under GDPR, consent must be freely given, specific, informed, and unambiguous. The EUDI Wallet’s model of explicit, attribute-level disclosure before any data is shared aligns well with this standard. Users are not presented with a blanket consent screen – they see exactly what is being requested and actively approve each disclosure.
Organizations operating in regulated sectors such as healthcare or government should treat eIDAS 2.0 compliance and GDPR compliance as complementary workstreams. Implementing one without considering the other creates gaps that regulators are increasingly likely to scrutinize.
Who is responsible for privacy compliance in an eIDAS 2.0 ecosystem?
Privacy compliance in an eIDAS 2.0 ecosystem is a shared responsibility distributed across several parties: wallet providers, credential issuers, and relying parties (the organizations that request and verify credentials). Each party has distinct obligations, and no single actor bears all of the responsibility. The regulation is explicit about this distribution to prevent any one party from becoming a single point of failure or control.
Wallet providers are responsible for ensuring the technical integrity of the wallet, protecting stored credentials, and complying with the prohibition on tracking user activity. They must meet certification requirements set by their Member State and adhere to the technical specifications defined in the Architecture and Reference Framework.
Credential issuers, such as government agencies or qualified trust service providers, are responsible for the accuracy of the data they attest to and for issuing credentials in formats that support selective disclosure and privacy-preserving verification.
Relying parties, meaning the organizations that ask users to present credentials, are responsible for requesting only the data they genuinely need, having a lawful basis for processing it under GDPR, and not retaining it beyond what is necessary. This is where many organizations will face the most immediate compliance work, since it requires redesigning onboarding flows, data collection forms, and internal processing logic.
For organizations still mapping out their responsibilities, working with partners who understand both the regulatory and technical dimensions of the eIDAS 2.0 ecosystem is a practical starting point. The TrustTech approach to digital identity implementation is built around exactly this kind of multi-party accountability.
How TrustTech helps with eIDAS 2.0 privacy compliance
Translating eIDAS 2.0’s privacy requirements into working systems is not straightforward. The regulation sets clear principles, but implementing selective disclosure, anti-tracking measures, and GDPR-aligned data flows requires both technical depth and regulatory understanding. That is where TrustTech adds value.
TrustTech helps organizations across regulated sectors prepare for and implement eIDAS 2.0-compliant identity infrastructure. Specifically, TrustTech supports:
- EUDI Wallet integration: Connecting your services to wallet-based identity flows that support selective disclosure and data minimisation by design.
- Verifiable credential infrastructure: Implementing cryptographically verified credentials that allow users to share only what is necessary.
- Compliance mapping: Aligning your data processing practices with both eIDAS 2.0 and GDPR requirements, including lawful basis and purpose limitation.
- Reusable identity flows: Enabling users to verify once and reuse their identity across your services, reducing friction while maintaining full compliance.
- Sector-specific guidance: Practical implementation support for finance, government, healthcare, and other regulated industries with specific identity and trust requirements.
Whether you are just starting to assess your eIDAS 2.0 readiness or already working through implementation, TrustTech provides the expertise and technology to move forward with confidence. Get in touch with TrustTech to discuss what eIDAS 2.0 privacy compliance means for your organization.