The EU Digital Identity Wallet stores personal data that users actively choose to add, such as government-issued identity attributes, professional qualifications, health information, and other certified credentials. Crucially, this data lives on the user’s own device, not on a central government or company server. The sections below unpack exactly what types of data the wallet can hold, how that data is protected, and what privacy rights users have under eIDAS 2.0.
Who controls the personal data in the EUDI Wallet?
The user controls their own personal data in the EUDI Wallet. Under the eIDAS 2.0 framework, the wallet is designed around the principle of user sovereignty: you decide what credentials to store, what data to share, and with whom. No third party, including the wallet provider or any government authority, can access or share your data without your explicit consent.
This is a significant departure from many existing digital identity systems, where identity data is held and managed by a central authority. With the European Digital Identity Wallet, the user holds the keys, both literally and figuratively. The wallet uses cryptographic mechanisms that ensure only the user can authorize disclosure. Wallet providers are required by regulation to be neutral infrastructure, not data processors with access to the contents of your wallet.
For organizations in regulated sectors such as finance, healthcare, or government, this user-centric model has important implications. It means that when a customer presents credentials from their wallet, those credentials carry a high level of assurance precisely because the user has actively chosen to share them, and the underlying data has been certified by a trusted issuer.
What types of credentials and attributes can the wallet hold?
The EUDI Wallet can hold a wide range of certified credentials and personal attributes, from government-issued identity documents to professional qualifications, health data, and beyond. The wallet is designed to be a flexible container for any verifiable credential that has been issued by a trusted source within the European digital identity ecosystem.
The most foundational credential is the Person Identification Data (PID), which is issued by a government authority and includes core identity attributes such as:
- Full name
- Date of birth
- Place of birth
- Current address
- Nationality
- A unique identifier tied to the national identity system
Beyond the PID, the wallet can also hold what the eIDAS 2.0 framework calls Electronic Attestations of Attributes (EAAs). These are credentials issued by qualified or non-qualified trust service providers and can cover a much broader range of use cases. Examples include a mobile driving licence, a university diploma, a professional licence, a health insurance card, or an age verification credential. Over time, as more sectors adopt the wallet standard, the range of supported credentials is expected to grow significantly.
One of the most practical features is selective disclosure: a user can choose to share only a specific attribute from a credential rather than the full document. For example, instead of sharing an entire passport, a user can prove they are over 18 without revealing their date of birth or any other detail.
How is personal data protected inside the wallet?
Personal data inside the EUDI Wallet is protected through a combination of device-level security, cryptographic binding, and regulatory safeguards. The data is stored in an encrypted format on the user’s device, and each credential is cryptographically linked to that specific wallet instance, making it extremely difficult to copy, forge, or misuse.
At a technical level, the wallet relies on secure hardware elements where available, such as the secure enclave in modern smartphones, to store private keys and sensitive credential data. These keys never leave the device. When a user presents a credential to a service provider, a cryptographic proof is generated on the device and shared, not the raw credential data itself. This means the relying party receives only what is necessary to verify the claim, nothing more.
From a regulatory standpoint, eIDAS 2.0 mandates that wallet providers undergo conformity assessments and meet strict security requirements before they can operate. This provides an additional layer of assurance for both users and the organizations that accept wallet-based credentials. The framework also prohibits wallet providers from tracking users’ transactions or building profiles based on wallet usage, which is a meaningful privacy protection built into the regulation itself.
What data is shared when you use the wallet to log in or verify identity?
When you use the EUDI Wallet to log in or verify your identity, only the specific data attributes that you explicitly approve are shared with the requesting party. The wallet uses a selective disclosure mechanism, meaning a service provider receives the minimum data necessary for the transaction, not your entire identity profile.
The exact data shared depends on what the service provider requests and what you agree to. A typical login to an online service might only require your name and a verified email address. An age-restricted purchase might only require a yes or no confirmation that you meet the age threshold. A financial services onboarding process might require a more complete set of identity attributes, including your address and document number, to satisfy KYC requirements.
Importantly, the wallet is designed so that the user sees a clear, readable summary of what is being requested before they approve any disclosure. You can accept, decline, or in some cases modify the scope of what is shared. This transparency is a core requirement under eIDAS 2.0 and is intended to give users genuine informed control over every interaction.
For organizations in financial services or other regulated industries, this model is particularly relevant. Wallet-based identity verification can satisfy strong customer authentication requirements while simultaneously respecting data minimization principles under GDPR, making compliance more straightforward rather than more complex.
Is data in the EUDI Wallet stored centrally or on the device?
Data in the EUDI Wallet is stored on the user’s device, not in a central database. This is one of the defining architectural principles of the European Digital Identity Wallet framework. There is no central repository where all European citizens’ identity data is collected and held.
This decentralized approach is deliberate. It reduces the risk of large-scale data breaches, eliminates single points of failure, and ensures that no single authority, whether a government body, a technology company, or a wallet provider, has access to the combined identity data of all wallet users. Each user’s wallet is their own private store of credentials.
Credential issuers, such as a national identity authority or a university, do maintain records of what they have issued. But once a credential is delivered to the wallet, the issuer does not need to be contacted every time the user presents that credential to a third party. This is known as an offline-capable or issuer-independent verification model, and it is another important privacy feature: the credential issuer does not get notified every time you use your diploma or your driving licence.
For organizations in the government sector or healthcare, this architecture raises practical questions about credential revocation and updates, which the eIDAS 2.0 technical specifications address through standardized revocation mechanisms that work without compromising user privacy.
What are the data privacy rights of EUDI Wallet users?
EUDI Wallet users have strong data privacy rights that are grounded in both eIDAS 2.0 and the General Data Protection Regulation (GDPR). These rights include the right to access, correct, and delete their personal data, as well as the right to know exactly what data is being requested and why before any disclosure takes place.
The key privacy rights that apply to wallet users can be summarized as follows:
- Right to informed consent: Users must be clearly informed about what data is requested and for what purpose before they approve any transaction.
- Right to data minimization: Service providers may only request the data that is strictly necessary for the specific purpose. Requesting more than needed is not permitted.
- Right to portability: Users can take their credentials with them and are not locked into a single wallet provider or ecosystem.
- Right to erasure: Users can delete credentials from their wallet at any time. Where personal data has been processed by a relying party, GDPR erasure rights also apply.
- Right to non-tracking: Wallet providers are explicitly prohibited from tracking users’ interactions or profiling them based on wallet activity.
These rights are not optional features, they are regulatory requirements. Organizations that accept wallet-based credentials as relying parties must also comply with these principles, which means building data request flows that respect minimization, transparency, and purpose limitation. For many organizations, aligning existing onboarding and verification processes with these requirements will require a review of current data practices.
How TrustTech helps organizations prepare for the EUDI Wallet
Understanding how personal data works in the EU Digital Identity Wallet is one thing. Adapting your organization’s systems, compliance frameworks, and customer journeys to work with it is another challenge entirely. That is where TrustTech comes in.
TrustTech supports organizations across regulated sectors in making this transition practical and manageable. Whether you are in finance, healthcare, government, or another trust-sensitive industry, TrustTech brings together the technical expertise and implementation experience needed to get ready for eIDAS 2.0 and the EUDI Wallet. Specifically, TrustTech helps with:
- Assessing your current identity and verification infrastructure against eIDAS 2.0 requirements
- Integrating wallet-based credential acceptance into your onboarding and authentication flows
- Building reusable compliance processes that align with GDPR, KYC, and data minimization principles
- Connecting your organization to the broader European digital identity ecosystem through interoperable, standards-based solutions
- Supporting qualified electronic signatures and trust services that are ready for the wallet era
If your organization is working through the implications of the European Digital Identity Wallet and wants to move from understanding to action, explore our identity solutions or get in touch with TrustTech to discuss your specific situation.