The EUDI Wallet comes with meaningful privacy protections built in, but it also introduces real privacy risks that organisations and users should understand. The wallet is designed around principles like data minimisation and user control, yet risks around data misuse, tracking, and compliance responsibilities remain. This article walks through the most important privacy questions surrounding the European Digital Identity Wallet.
How does the EUDI Wallet handle personal data under eIDAS 2.0?
Under eIDAS 2.0, the EUDI Wallet handles personal data through a privacy-by-design framework. Users store their own data locally on their device and choose what to share with which service. No centralised database holds all wallet data, and service providers can only request the information they genuinely need for a specific interaction.
The regulation requires that wallet providers and relying parties comply with the General Data Protection Regulation (GDPR). This means data processing must have a legal basis, retention periods must be limited, and users must be informed about how their data is used. The wallet architecture is built so that personal data flows directly between the user and the requesting party, rather than being routed through a central broker.
In practice, this means a user presenting their age to access a service does not need to share their full name, address, or date of birth. The wallet issues what are called attestations, which are cryptographically signed pieces of information that can be verified without revealing more than necessary. This approach brings eIDAS 2.0 closely in line with GDPR principles, but it also places real responsibilities on the organisations that receive and process that data.
What are the main privacy risks of the EUDI Wallet?
The main EUDI Wallet privacy risks include unlawful data collection by relying parties, insufficient user understanding of what they are sharing, the potential for data aggregation across services, and implementation weaknesses that could expose personal information. While the wallet framework is privacy-aware, risks emerge in how organisations deploy and use it.
Key privacy concerns to be aware of include:
- Over-requesting data: Relying parties may ask for more attributes than they actually need, leading to unnecessary exposure of personal information.
- Weak consent mechanisms: If consent flows are poorly designed, users may share data without fully understanding what they are agreeing to.
- Data retention after use: Organisations that receive wallet data may retain it longer than permitted, creating compliance and security risks.
- Insecure storage or transmission: Technical vulnerabilities in wallet implementations or relying party systems could expose received data.
- Cross-context profiling: Even with selective disclosure, patterns of wallet use could be analysed to build profiles of individuals over time.
These risks do not mean the EUDI Wallet is fundamentally unsafe. They do mean that privacy protection depends heavily on how well organisations on the receiving end of wallet presentations implement their own systems and processes.
Can the EUDI Wallet be used to track users across services?
The EUDI Wallet is specifically designed to prevent cross-service tracking, but the risk cannot be ruled out entirely. The technical architecture uses mechanisms like pseudonymous identifiers and selective disclosure to prevent a single persistent identifier from linking a user’s activity across different services. However, tracking risks can still arise through indirect means.
For example, if a relying party receives a unique cryptographic attribute that is consistent across presentations, that attribute could theoretically be used to correlate a user’s activity. The Architecture and Reference Framework developed for the EUDI Wallet addresses this by specifying that wallet implementations should avoid issuing static, linkable identifiers where possible.
A more practical tracking concern comes from the relying parties themselves. If an organisation collects wallet-derived data and combines it with other data sources, it may be able to build a profile of a user even without a persistent wallet identifier. This is where GDPR enforcement and proper data governance on the organisation’s side become critical. The wallet limits what can be shared, but it cannot control what happens to data once it has been legitimately received.
How does selective disclosure reduce EUDI Wallet privacy risks?
Selective disclosure reduces EUDI Wallet privacy risks by allowing users to share only the specific attributes required for a transaction, rather than presenting a full identity document. Instead of showing an entire passport to prove age, a user can share a single yes or no confirmation that they are over a certain age. This limits the amount of personal data exposed in any given interaction.
This capability is one of the most significant privacy improvements the EUDI Wallet offers compared to traditional identity verification methods. With a physical document, the recipient sees everything. With selective disclosure, the user decides what is revealed.
The underlying technology uses cryptographic proofs, meaning the receiving party can verify the claim without the wallet provider or any third party needing to be involved in the transaction. This removes a common privacy risk in centralised identity systems, where a provider could theoretically log every time a user’s identity was checked.
Selective disclosure does not eliminate all risk, but it significantly reduces the surface area for data misuse. Organisations that accept wallet presentations should design their data requests around this principle, asking only for what they genuinely need rather than defaulting to requesting full credential sets.
Who is responsible for EUDI Wallet privacy compliance?
Responsibility for EUDI Wallet privacy compliance is shared between wallet providers, who must meet the technical and security requirements under eIDAS 2.0, and relying parties, who are responsible for how they request, receive, and process personal data. Under GDPR, the relying party acts as a data controller for any personal data it receives through a wallet transaction.
Wallet providers, which may be government bodies or certified private organisations, are responsible for the security of the wallet itself, the integrity of the attestations it issues, and the privacy of the user’s stored data. They must meet strict certification requirements under the eIDAS 2.0 framework.
Relying parties, meaning the organisations that ask users to present wallet credentials, carry a separate and significant compliance responsibility. They must:
- Have a lawful basis under GDPR for requesting and processing the data they receive.
- Only request the minimum data necessary for the specific purpose.
- Be registered or authorised to act as a relying party under the applicable national framework.
- Apply appropriate technical and organisational measures to protect received data.
- Respect retention limits and deletion obligations.
Organisations in regulated sectors such as financial services, healthcare, and government will also need to align their wallet-related data processing with sector-specific regulations alongside GDPR and eIDAS 2.0.
What should organisations do to address EUDI Wallet privacy risks?
Organisations should address EUDI Wallet privacy risks by reviewing their data minimisation practices, updating their privacy documentation, assessing their technical readiness to handle wallet-derived data securely, and ensuring their teams understand their compliance obligations as relying parties. Acting early gives organisations time to make thoughtful decisions rather than reactive ones.
A practical starting point is to map out which use cases will involve wallet presentations and what data will be requested in each. From there, organisations can assess whether their current data governance frameworks are sufficient or need updating. Privacy impact assessments are a useful tool here, particularly for high-risk processing activities.
Technical teams should also review how received wallet data will be stored, who will have access to it, and how long it will be retained. These are not just compliance questions. They are also risk management decisions that affect user trust and organisational reputation. Explore the available resources on digital identity to deepen your understanding of the technical and regulatory landscape.
How TrustTech helps with EUDI Wallet privacy risks
Navigating EUDI Wallet privacy risks requires both technical understanding and regulatory expertise. TrustTech supports organisations across regulated sectors in building a clear picture of their obligations and translating that into practical action. Whether you are preparing to act as a relying party, assessing your current data governance frameworks, or planning a broader digital identity implementation, TrustTech brings the expertise to guide that process.
Working with TrustTech, organisations can expect support with:
- Assessing current readiness for eIDAS 2.0 and EUDI Wallet compliance
- Defining data minimisation strategies for wallet-based interactions
- Reviewing and updating privacy documentation and impact assessments
- Aligning wallet implementation with GDPR and sector-specific regulations
- Building internal understanding across compliance, IT, and business teams
Privacy compliance for the EUDI Wallet is not a one-time project. It is an ongoing responsibility that evolves as the regulation matures and as your organisation’s use of wallet technology grows. Get in touch with TrustTech to discuss how we can help your organisation address EUDI Wallet privacy risks with confidence.