Digital Identity with Mandatory Acceptance: EUDI Wallet and European Business Wallet at a Glance
Update Data Protection No. 267
Whether opening a bank account, entering into a contract with an energy supplier or applying for a trade licence, anyone who must identify themselves online or submit official evidence has so far had to navigate a patchwork of different procedures, ranging from the online identification function to video identification and the upload of scanned documents. With the reform of the eIDAS Regulation, the EU legislature created the European Digital Identity Wallet (EUDI Wallet), which is scheduled to launch in Germany under the name “d-you” on 2 January 2027, shortly after the deadline for making it available under EU law. The Digital Identity Act (DIdG) required for this purpose, however, is still in the parliamentary process following its first reading in the Bundestag. The counterpart proposed by the Commission for businesses, the so-called European Business Wallet (EBW), is far less concrete at this stage. Negotiations between the Council and the European Parliament are only just beginning, meaning that both the final regulatory content and the date of applicability remain open. This article presents the current status of the EUDI Wallet and the resulting obligations for businesses, outlines the key features of the planned EBW and identifies preparations that can already be undertaken.
I. Legal framework
By recasting the eIDAS Regulation through Regulation (EU) 2024/1183, the EU legislature laid the foundation for digital identity credentials to be issued and recognised under the same rules in all Member States. The core of this framework is the EUDI Wallet, a smartphone application that allows customers, contractual counterparties and employees to identify themselves and present evidence such as a driving licence, professional qualification or proof of age, without having to rely on copies of identity documents or video identification. Each Member State is required to make at least one such wallet available by 24 December 2026, for citizens to use free of charge and on a voluntary basis. Users decide for themselves which information to disclose. An online retailer that only needs to verify that a customer has reached the age of majority should receive only that information, rather than the customer’s complete identity record.
This gives rise to two principal requirements for businesses. Anyone wishing to use the Wallet must first register and specify which data they request and for what purpose (Art. 5b). Businesses that are required to identify their customers using strong authentication under statutory or contractual requirements, such as banks, energy suppliers or telecommunications providers, are required to accept it (Art. 5f). Unless a business in one of these sectors qualifies as a microenterprise or small enterprise, it must enable its customers, at their request, to identify themselves using the Wallet from the end of December 2027. The same applies to very large online platforms, while public authorities are required to accept it in any event.
II. Germany’s EUDI Wallet “d-you”
Germany is relying on a state-run wallet, developed under the name “d-you” on behalf of the Federal Ministry for Digital and State Modernisation (BMDS) by the Federal Agency for Disruptive Innovation (SPRIND). The DIdG, currently being debated in the Bundestag, is intended to supplement the requirements of the eIDAS Regulation with national rules, including rules on responsibilities and the registration of businesses as relying parties. The Federal Government is pursuing a phased approach. The Wallet is expected to launch at the beginning of 2027 with a basic offering and then be expanded gradually to include additional credentials and applications.
At launch on 2 January 2027, only the digital identity card is initially expected to be usable. To set it up, the user reads the data from the chip in their identity card using the identity-card PIN via the smartphone’s NFC interface and then sets a personal Wallet PIN. According to the Ministry, the data is stored in encrypted form on the device, while signatures are created through a secure cloud connection using a person-specific key. A photo identity credential is expected to follow shortly after launch, and a driving licence somewhat later, although no fixed date has yet been set for the latter. Further credentials, including those issued by municipalities and universities, are in preparation. Around 40 partners from business, academia and public administration are currently developing use cases intended to be available at launch. These include parcel collection, proof-of-age checks in retail and customer verification in the banking sector.
Several functions that the eIDAS Regulation provides for the Wallet will not yet be available at launch. For the time being, the Wallet can only be used with an internet connection because cryptographic authenticity verification takes place on a server rather than on the device. Offline use will only become possible once device manufacturers make the required security components of smartphones available. Nor is it possible to confirm merely that a user has reached a minimum age without transmitting additional identity data. Authorities also cannot send administrative notices to the Wallet because it does not have a notification function.
If the smartphone is replaced, the identity data must be read in again because device-bound content cannot be transferred and cloud backups cannot be created. A Wallet locked after multiple incorrect PIN entries must be set up again in full. It also remains unclear whether a PIN-reset service will be available in time, as does the pending security assessment. At present, the app can only be obtained through the Apple App Store or Google Play Store, making a user account with one of these providers necessary.
Businesses that wish to integrate the Wallet into their processes, or will be required to do so from the end of 2027, should therefore not expect broad use immediately after launch. Existing identification procedures will have to be maintained in parallel for the foreseeable future. Planning should also take into account that the Wallet’s functionality will expand gradually over the coming months.
III. The European Business Wallet (EBW)
While the EUDI Wallet is intended for natural persons, the EBW is intended to provide businesses with their own instrument for conducting digital legal transactions with authorities and business partners. In November 2025, the Commission presented a proposal for a regulation to this effect. Unlike the EUDI Wallet, the EBW is conceived as cloud-based infrastructure rather than a smartphone application, because business processes should not in every case require the personal involvement of an executive.
Under the proposal, businesses would be able to identify themselves across the EU via the EBW, electronically sign and seal documents, and store and present credentials such as a VAT identification number or a trade licence. Employees could be granted different levels of authorisation. A secure delivery channel would also enable legally binding communications with authorities, comparable to a digital registered letter. The Commission identifies tax returns, applications for grants, procurement procedures and the establishment of a branch in another Member State as potential use cases, among others. Transactions conducted through the Wallet would be legally equivalent to paper-based procedures or appearing in person. Use of the EBW would be voluntary for businesses, self-employed persons and associations, but public authorities would be required to accept it.
The Council and the European Parliament established their negotiating positions in June and September 2026, respectively. Among other things, the Parliament is calling for providers not to be controlled directly or indirectly by third countries and for the data to be stored exclusively in the EU. A political agreement is sought by the end of 2026. Since formal adoption and technical implementing acts will still be required thereafter, the EBW is unlikely to be practically available for at least several years.
IV. Recommendations for action
Businesses should first clarify whether they are subject to the acceptance obligation under Art. 5f. The key questions are whether they are required to identify their customers using strong authentication under statutory or contractual requirements and whether they exceed the thresholds for small enterprises. Even without a corresponding obligation, voluntary integration may be worthwhile, for example where proof of age or identity is checked regularly. The currently limited functionality suggests that this decision should not be based solely on the launch date.
A review should then be undertaken of the processes in which customers, contractual counterparties or employees are identified, for example when opening an account, entering into a contract or restoring access. This provides the basis for planning where the Wallet can be integrated technically. Since it will initially function only online and individual features will be added gradually, existing procedures should be retained as a fallback option. Businesses that use external service providers for identity verification should clarify at an early stage whether and when those providers will offer integration with the Wallet.
Registration as a relying party should be prepared before use. It must be determined which data is actually required for which purpose, since no data may be requested beyond the information registered. Users should also be able to understand the requests and report suspected unlawful data requests to the data protection authorities. Registration should therefore be combined with a data protection law review. This should cover, in particular, the legal basis, information obligations, the records of processing activities and, where appropriate, a data protection impact assessment (DPIA).
Organisational questions must also be addressed. Responsibilities for implementation and operation should be defined, as should procedures for technical disruptions. Since the Wallet must be set up again after a device change or lockout, customer enquiries should be expected. Customer-service staff should be prepared for them.
With regard to the EBW, monitoring and preparing is currently more appropriate than implementation. Businesses can, however, already identify the procedures in which they communicate with authorities and review their rules on representation and signing authority. Such an inventory will make it easier to develop an authorisation concept for the Wallet later. It should also be clarified how incoming deliveries through a digital channel would be recorded and processed within the applicable deadlines. The further legislative process should be monitored, particularly with regard to the requirements for providers and the transitional periods.
V. Conclusion and outlook
With the launch of “d-you” at the beginning of 2027, the EUDI Wallet will become practically usable in Germany for the first time, although initially with significantly limited functionality and subject to the DIdG being adopted in time. For businesses, the end of December 2027 is particularly important, when the acceptance obligation will apply to many private providers. The extent to which the Wallet will be useful in everyday life will depend largely on how quickly key functions, such as offline use, confirmation of individual attributes and additional credentials, are added.
The EBW, by contrast, is still in the legislative process. Even if a political agreement is reached by the end of 2026, some time is likely to pass before it becomes practically available. Businesses would therefore be well advised to prepare for the foreseeable obligations relating to the EUDI Wallet and initially monitor the development of the EBW.
This article was created in collaboration with our student employee Emily Bernklau.