What the regulation introduces
Regulation (EU) 2024/1183 amends the original eIDAS and creates the framework for the European digital identity wallet, which will let each person hold and present their credentials from their own device.
Member States must offer at least one wallet within twenty-four months of the entry into force of the implementing acts the regulation itself provides for.
What it means for businesses
Anyone who today identifies customers or employees with copies of an identity document will instead be able to receive a verifiable credential, without keeping the copy.
That reduces the personal data retained, which is exactly what the GDPR minimisation principle has been asking for years.
What does not change
The three signature levels remain the same and a qualified signature keeps its equivalence with a handwritten one. Anyone whose signing circuit already works does not have to rebuild it.
What an auditor usually asks for
- An inventory of where identity document copies are requested today
- Tracking the wallet timetable in your Member State
- A review of your trust service provider and its qualification
- A signing circuit ready to accept verifiable credentials
How to prepare with Kimobox
- 1Start now by limiting identity document copies to the cases where they are unavoidable.
- 2Document which identification method is used in each signing process.
- 3Keep the evidence file exportable, so a change of provider does not tie you down.
Useful preparation for eIDAS 2 is the same the GDPR already asks for: hold less identity and verify it better.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Regulation (EU) 910/2014 (eIDAS) on electronic identification and trust services EUR-Lex · 23/07/2014
- Regulation (EU) 2024/1183, European digital identity framework (eIDAS 2) EUR-Lex · 11/04/2024
- Spanish Law 6/2020 on certain aspects of electronic trust services BOE-A-2020-14046 · 12/11/2020