What are the data minimization principles in eIDAS 2.0?

Sealed envelope on a white desk with documents sliding out beside a stack of closed confidential folders in soft natural light.

The data minimization principles in eIDAS 2.0 require that only the personal data strictly necessary for a specific purpose may be requested or processed during an identity interaction. This means organizations can no longer ask for a full identity profile when a simple age confirmation or nationality check will do. The sections below unpack what this looks like in practice, what it means for your organization, and how to prepare.

How does data minimization work in practice under eIDAS 2.0?

Under eIDAS 2.0, data minimization means that every request for identity data must be limited to what is genuinely necessary for the task at hand. If a service only needs to confirm that a user is over 18, it should receive a yes or no confirmation, not a full date of birth, name, and address. This principle is built directly into the architecture of the European Digital Identity Wallet.

In practical terms, the EUDI Wallet allows users to share individual attributes from their digital identity rather than handing over an entire document. Think of it as showing only one page of a passport instead of the whole booklet. A user applying for a prescription service shares only the relevant health credential. A user accessing an age-restricted platform shares only an age confirmation. The underlying personal data stays with the user.

This approach reflects a deliberate shift in how identity verification is designed. Rather than collecting data and deciding later what to use, organizations must define upfront exactly what data they need and why. That design-first mindset is central to eIDAS 2.0 compliance.

What specific obligations does eIDAS 2.0 place on relying parties?

Relying parties, meaning the organizations that request and receive identity data from a user’s EUDI Wallet, have clear obligations under eIDAS 2.0. They must only request attributes that are necessary and proportionate to the service they are providing. Requesting more data than needed is not just poor practice, it is a compliance violation.

The key obligations for relying parties include:

  • Purpose limitation: Each data request must be tied to a clearly defined and legitimate purpose.
  • Proportionality: The scope of the data request must match the minimum needed to fulfil that purpose.
  • Registration and transparency: Relying parties must register their intended use cases and data requests, making them visible to both regulators and users.
  • No retention beyond necessity: Data received through the wallet may not be stored or reused for purposes beyond the original transaction without a separate legal basis.
  • User consent and control: Users must be able to see what is being requested and actively choose to share it.

These obligations align closely with GDPR principles, but eIDAS 2.0 goes further by embedding them into the technical layer of the wallet interaction itself, making compliance harder to ignore and easier to audit.

How does selective disclosure differ from traditional identity verification?

Selective disclosure is the technical mechanism that makes data minimization possible in the EUDI Wallet. It allows a user to share a single verified attribute from a credential without revealing the rest of the underlying data. Traditional identity verification, by contrast, typically involves presenting a full document or submitting a complete data set, leaving the service provider to decide what to use.

In a traditional verification flow, a user might upload a passport to confirm their nationality. That process also reveals their full name, date of birth, document number, and expiry date, even if none of that information is needed. With selective disclosure, the wallet presents only the nationality field as a cryptographically verified claim, and nothing else is transmitted.

This is a fundamental change in the trust model. Instead of the service provider holding and processing raw personal data, the user retains control, and the service provider receives only a verified, purpose-specific answer. The result is less data exposure, reduced storage liability for organizations, and greater privacy for individuals. For organizations operating in financial services or other regulated sectors, this shift also reduces the risk of data breaches involving sensitive identity information.

Which technical standards support data minimization in the EUDI Wallet?

The EUDI Wallet relies on a set of established technical standards to make data minimization and selective disclosure work reliably and interoperably across Europe. These standards define how credentials are structured, how attributes are disclosed, and how trust is established between parties.

The most relevant standards include:

  1. ISO/IEC 18013-5 (mdoc): The standard for mobile documents, including mobile driving licenses. It supports selective disclosure of individual fields and is designed for both online and in-person use.
  2. W3C Verifiable Credentials (VC) Data Model: A widely adopted framework for expressing digital credentials in a way that is machine-verifiable and privacy-preserving. It underpins much of the wallet’s credential exchange logic.
  3. SD-JWT (Selective Disclosure JSON Web Token): A format that allows individual claims within a credential to be disclosed separately, giving users fine-grained control over what they share.
  4. OpenID for Verifiable Presentations (OID4VP): The protocol used to request and present credentials in the wallet ecosystem, supporting minimal disclosure flows.
  5. Architecture and Reference Framework (ARF): The technical blueprint developed by the eIDAS Expert Group that defines how all these components fit together in the EUDI Wallet.

Together, these standards create a technical foundation where data minimization is not just a policy goal but a built-in feature of every identity interaction. Organizations building or integrating with digital identity solutions should ensure their systems are compatible with these specifications.

How should organizations prepare their systems for eIDAS 2.0 data minimization?

Preparing for eIDAS 2.0 data minimization requires both a technical and an organizational shift. The starting point is a thorough review of every identity verification flow your organization currently operates, with the goal of identifying what data is collected, why, and whether all of it is genuinely necessary.

A practical preparation approach looks like this. First, map your current data collection points and assess each one against the principle of necessity. Ask: what is the minimum we need to complete this interaction? Second, review your legal basis for each data request, since eIDAS 2.0 tightens the link between purpose and data scope. Third, assess your technical infrastructure for compatibility with wallet-based credential presentation and selective disclosure formats. Many legacy systems were built to receive full identity documents, not individual verified attributes.

Organizations in sectors such as healthcare or government services will often find that their verification flows collect far more data than the underlying process requires. Redesigning these flows around minimum necessary data is not only a compliance requirement, it also reduces data liability and improves user experience by making interactions faster and less intrusive.

Training compliance, IT, and product teams on what data minimization means in practice is equally important. The principle is straightforward, but applying it consistently across complex service journeys requires deliberate effort and clear internal governance.

How TrustTech helps with eIDAS 2.0 data minimization

Implementing data minimization principles in line with eIDAS 2.0 is not just a compliance exercise. It requires rethinking how your organization collects, uses, and stores identity data at a fundamental level. TrustTech helps organizations navigate exactly this challenge.

Working with TrustTech, your organization can:

  • Map and redesign identity verification flows to align with minimum necessary data principles
  • Integrate EUDI Wallet-compatible credential exchange using the right technical standards, including SD-JWT and OID4VP
  • Build reusable, privacy-preserving onboarding processes that reduce repeated data collection across interactions
  • Prepare compliance documentation and governance frameworks that reflect eIDAS 2.0 obligations for relying parties
  • Connect identity, qualification, and signature processes in a single trusted infrastructure, reducing data exposure at every step

TrustTech’s platform is built on European digital identity standards and designed to be eIDAS 2.0 ready from the ground up. Whether you are just beginning to assess your readiness or already working toward implementation, the team brings both technical depth and practical experience across regulated industries. Get in touch with TrustTech to discuss how your organization can move forward with confidence.