Before accepting the European Digital Identity Wallet, businesses must register as a Relying Party under eIDAS 2.0, meet defined technical integration standards, and put data protection measures in place that comply with GDPR and the specific requirements of the EUDI Wallet framework. These obligations apply to any organization that wants to accept wallet-based credentials for identity verification or attribute sharing. The sections below walk through each compliance area in practical detail.
Which regulations govern EUDI Wallet acceptance for businesses?
EUDI Wallet acceptance is primarily governed by eIDAS 2.0, the revised EU regulation on electronic identification and trust services. Alongside eIDAS 2.0, businesses must comply with GDPR when processing personal data retrieved from wallet credentials. Together, these two frameworks define the legal basis for accepting, verifying, and storing identity data presented through the European Digital Identity Wallet.
eIDAS 2.0 introduces a new category called Relying Parties: organizations that request and verify credentials from wallet holders. Any business wishing to accept the EUDI Wallet must formally register as a Relying Party with the relevant national authority. This registration is not optional. It is a legal prerequisite that establishes accountability and ensures that only verified organizations can request wallet-based identity data from users.
Beyond registration, eIDAS 2.0 sets rules around which attributes businesses are permitted to request, how those requests must be structured, and what trust levels apply to different use cases. The regulation also mandates that Relying Parties request only the minimum data necessary for their specific purpose, a principle that directly connects to GDPR’s data minimization requirements.
Sector-specific regulations add further layers. Financial institutions must align EUDI Wallet compliance with AML directives and KYC obligations. Healthcare organizations face additional requirements under health data regulations. Understanding which regulatory frameworks apply to your sector is therefore an essential starting point before any technical work begins. TrustTech’s work with financial sector clients illustrates how these overlapping obligations can be mapped and addressed systematically.
What technical requirements must businesses meet to accept the EUDI Wallet?
To accept the EUDI Wallet, businesses must integrate with the wallet’s technical infrastructure using standardized protocols defined in the Architecture and Reference Framework (ARF). This includes supporting OpenID for Verifiable Presentations (OID4VP) for credential requests and ISO/IEC 18013-5 for mobile document formats. These standards ensure interoperability across all wallet implementations issued by EU Member States.
In practical terms, this means your systems need to be capable of the following:
- Generating and sending compliant credential requests to wallet holders
- Receiving and cryptographically verifying signed credential responses
- Validating the trust chain back to the issuing authority via the national trust registries
- Supporting both online (remote) and proximity (in-person) verification flows where relevant
- Logging verification events in a way that supports audit requirements
Businesses also need to ensure their backend systems can handle the selective disclosure model that the EUDI Wallet uses. Rather than receiving a full identity document, your system will receive only the specific attributes the user has consented to share, such as age confirmation or nationality. Your verification logic must be built to work with these granular, attribute-level responses rather than full document copies.
For most organizations, meeting these technical requirements will involve either building a custom integration or working with a platform that already supports the relevant standards. Starting with a clear mapping of your existing identity infrastructure against the ARF requirements will reveal where gaps exist and what needs to change.
What data protection obligations apply when verifying EUDI Wallet credentials?
When verifying EUDI Wallet credentials, businesses must comply with GDPR as data controllers. This means establishing a lawful basis for processing the identity data received, applying data minimization strictly, informing users about how their data is used, and ensuring that verified attributes are not retained longer than necessary for the stated purpose.
The EUDI Wallet framework reinforces these obligations through its design. Users control what they share and with whom. As a Relying Party, your credential request must specify exactly which attributes you need and why. Requesting more data than your use case justifies is both a GDPR violation and a breach of eIDAS 2.0 Relying Party obligations.
Retention is a particularly important area to address. Many organizations default to storing identity verification records for extended periods, but under the EUDI Wallet model, you should retain only what is genuinely necessary. For some use cases, you may only need to log that a verification occurred and what the outcome was, without storing the underlying attribute data at all.
Businesses should also update their privacy notices and data processing agreements to reflect the new verification method. If you use a third-party service provider to handle wallet verification on your behalf, a data processing agreement under Article 28 GDPR is required. Conducting a Data Protection Impact Assessment (DPIA) before going live is strongly recommended, particularly for high-risk processing contexts such as financial services or healthcare.
How should businesses update their legal and compliance frameworks?
Businesses should update their legal and compliance frameworks by formally incorporating EUDI Wallet acceptance into their existing identity governance documentation, updating relevant policies, and assigning clear internal ownership for ongoing compliance. This is not a one-time technical project but a sustained compliance function that needs to be embedded in how your organization manages digital identity.
A structured approach to updating your compliance framework typically involves these steps:
- Register as a Relying Party with the national authority in your Member State, following the registration process defined under eIDAS 2.0.
- Update your identity and access management policies to include EUDI Wallet as an accepted verification method, alongside your existing methods.
- Revise your data processing records under Article 30 GDPR to document wallet-based verification as a new processing activity.
- Conduct a DPIA if your use case involves sensitive data categories or large-scale processing of identity attributes.
- Update contractual documentation with vendors and partners who are involved in the verification process.
- Train relevant teams, including compliance, legal, IT, and customer-facing staff, on how the wallet works and what obligations it creates.
It is also worth reviewing your incident response and breach notification procedures. If a verification event is later found to involve fraudulent credentials, your organization needs a clear process for responding, notifying the relevant authorities, and documenting the incident. Building this into your existing frameworks now avoids gaps later.
Which sectors face the strictest EUDI Wallet compliance deadlines?
Financial services, government, and healthcare are among the sectors facing the most immediate and stringent EUDI Wallet compliance obligations. Under eIDAS 2.0, public sector bodies and public service providers must accept notified EUDI Wallets as a means of identification from 24 December 2026. For regulated private sector organizations — including banks and financial services providers, healthcare providers, telecoms operators, energy suppliers, transport companies, and very large online platforms with more than 45 million users in the EU — the mandatory acceptance obligation under Article 5f of eIDAS 2.0 applies from 24 December 2027, where strong user authentication is legally or contractually required. These sectors also carry the most overlapping regulatory requirements from existing frameworks.
For financial institutions, the intersection of EUDI Wallet compliance with AML, KYC, PSD2, and Strong Customer Authentication requirements creates a complex compliance landscape. The wallet can actually simplify some of these obligations by providing cryptographically verified identity data, but only if the integration is built correctly from the start. It is also worth noting that the evolving AML framework is moving towards identity verification via notified schemes, the EUDI Wallet, and qualified trust services — a parallel development that reinforces the case for early preparation, though it operates under a separate legal basis from the eIDAS 2.0 acceptance obligation.
Government organizations are both issuers and verifiers in the EUDI Wallet ecosystem. Public sector bodies must accept the wallet for access to digital public services from 24 December 2026 and, in many cases, are also responsible for issuing official credentials into citizens’ wallets. This dual role means their compliance obligations are broader than those of most private sector organizations.
Healthcare providers face strict requirements around the handling of health-related attributes, which fall under the special categories of personal data in GDPR. Any use of the EUDI Wallet to share or verify health data requires explicit consent and additional safeguards beyond standard identity verification.
Organizations in education, telecommunications, energy, and other regulated sectors also have compliance timelines to meet under the 24 December 2027 deadline. For private sector organizations in scope, 2026 is the year to have your compliance framework well advanced — wallets will become available and testable from that point — so that you are fully prepared ahead of the 2027 acceptance obligation.
Where should businesses start their EUDI Wallet readiness assessment?
Businesses should start their EUDI Wallet readiness assessment by mapping their current identity verification processes against the requirements of eIDAS 2.0 and identifying the gaps. This means looking at your existing onboarding flows, authentication methods, data processing practices, and legal documentation to understand what already aligns with EUDI Wallet requirements and what needs to change.
A practical readiness assessment covers four areas. First, your regulatory position: have you identified your obligations as a Relying Party, and do you know which attributes your use cases require? Second, your technical infrastructure: can your systems support the protocols required for wallet-based verification, or does significant development work lie ahead? Third, your data governance: are your GDPR documentation, retention policies, and DPIAs up to date and fit for purpose in a wallet context? Fourth, your organizational readiness: do the right people in your organization understand what is coming and who owns the compliance response?
Starting with a gap analysis across these four dimensions gives you a clear picture of where you stand and what your priorities should be. From there, you can build a realistic roadmap with timelines, resource requirements, and measurable milestones. Waiting until implementation pressure forces action is a common mistake. Organizations that begin their assessment now have time to make thoughtful decisions rather than reactive ones. Explore the resources available to support your readiness planning.
How TrustTech helps with EUDI Wallet compliance
TrustTech supports organizations at every stage of their EUDI Wallet compliance journey, from initial readiness assessment through to live implementation. Whether you are working through the regulatory requirements for the first time or moving from planning to integration, TrustTech brings the technical depth and compliance expertise needed to get it right.
Specifically, TrustTech helps organizations with:
- Relying Party registration and eIDAS 2.0 compliance mapping
- Technical integration of EUDI Wallet verification into existing onboarding and authentication flows
- GDPR alignment, including DPIA support and data minimization design
- Sector-specific compliance guidance for finance, government, and healthcare
- Reusable identity infrastructure that reduces friction for users while meeting regulatory requirements
TrustTech’s platform is built on European digital identity standards and designed to be eIDAS 2.0 ready from the ground up. Rather than building a compliance workaround on top of legacy systems, TrustTech helps you build a future-ready identity solution that scales with your organization and adapts as the regulatory landscape continues to evolve.
If you are ready to understand where your organization stands and what needs to happen next, get in touch with TrustTech to start your EUDI Wallet readiness assessment.