Skip to content
Ver.iDhttps://ver.id/articles/blog/2025-02-11-eidas-glue
All articles

Article

What eIDAS 2.0 means for your organisation

European wallets and digital credentials bring new opportunities and obligations. Where do they affect your organisation, which choices do they involve and how can you prepare?

Organisations use identity data and credentials to grant access, assess applications and work with other parties. They also hold information that others need to be able to trust. eIDAS 2.0 changes the European framework within which that information can be issued and used digitally.

What this means for your organisation depends on the services you provide and your role in the exchange. Good preparation brings together legal obligations, opportunities for service delivery and the agreements needed. It clarifies which choices need attention now and what implementation can follow.

What changes with eIDAS 2.0?

eIDAS 2.0 extends the European rules for electronic identification and trust services. A key element is the European Digital Identity Wallet. It enables people to prove their identity, receive digital credentials and share data with organisations. Electronic signing is also part of the framework. The European Commission describes the wallet's functions.

Common rules and technical agreements are intended to enable this use across organisations and national borders. A recipient can, for example, check a digital credential's origin and validity. Users can share data from their wallet where it is needed. Whether this works for a particular service depends on factors including available credentials, supported wallets and agreements with the parties involved.

This article focuses on the choices around wallets and digital credentials within that broader European framework.

Where does this affect your organisation?

First, look at the information your organisation uses. Where do customers, residents, employees or business partners need to prove their identity, attributes or authority? As the receiving party, you determine which data is needed, which sources you accept and how the evidence informs a decision. An age check, for example, requires different information from establishing authority to represent someone else.

Then look at the data you hold yourself. Could other parties make use of it if you issued a digital credential based on it? Think of a membership, a permit or an authorisation. As an issuer, you need to stand behind the credential's meaning and origin and arrange how it remains valid, is corrected or is revoked.

An organisation can fulfil both roles. For each service or data exchange, clarify what you receive, what you issue and who depends on it. This reveals where eIDAS affects your organisation and which internal and external parties you need to involve in preparation.

The issuer issues a digital credential, the holder shares it from a wallet and the recipient assesses it for its service. One organisation can both issue and receive credentials.

Which obligations and choices come with that role?

Determine which rules apply to the services you have identified. Online public services must accept compliant European wallets where a Member State requires electronic identification and authentication for access.

Different conditions apply to private services: Article 5f(2) links the acceptance obligation to strong user authentication for online identification required by law or contract. Microenterprises and small enterprises are exempt; the other parties within that provision must accept wallets at the user's voluntary request by 24 December 2027. A separate rule applies to designated very large online platforms. The eIDAS explainer and timeline describe the scope and legal basis.

An organisation wishing to request data from a European wallet must register in the Member State where it is established, declare its intended use and data requests, and identify itself to the user. Requests must remain within the registered data set. See the obligations for receiving parties.

For issuance, the credential's legal category and its conditions require a separate assessment. A credential does not automatically become qualified because it is stored in a wallet. An obligation to accept wallets is also not a general obligation to issue credentials yourself. Article 45b of eIDAS describes the legal effects of different categories.

Alongside these obligations, assess the value for your services. Which data exchanges could become easier, which collaborations become possible and what would that require of the parties involved? This lets you give both legal preparation and desired improvements an appropriate place in your planning.

Which agreements make the exchange useful?

To act on a digital credential, parties need to know what it means and what they can rely on. Which source supports the data? Who may issue the credential? What does the recipient check and how current must the information be? Technical verification checks the origin and whether the data is unchanged. This does not automatically make the source information correct or sufficient for a decision. The recipient remains responsible for the assessment within its own service.

Connect these agreements to the rules of the trust framework in which the credential is used. A rulebook can record the meaning, data, roles and conditions for issuance, use and management. Investigate which agreements already exist and what needs to be added for your organisation. Read more in the explainer on trust frameworks.

The user's position is part of this too. Request only the data that is necessary and permitted, explain what you use it for and ensure errors can be corrected. Confirmation in the wallet does not replace a valid GDPR legal basis. Wallet use remains voluntary, so people without a wallet must also be able to proceed. See Articles 5 and 6 of the GDPR and Article 5a(15) of eIDAS.

What does preparation require of your organisation?

Bring together service delivery, legal, privacy, security, technical and operations teams. Their choices are connected: the data you need helps determine what you request, which source you use and how your systems must connect. Record who makes those decisions and who is responsible for day-to-day use.

Then take stock of what already exists: identification methods, source records, data definitions, agreements and integrations. Work with suppliers and other parties to establish what is usable and which dependencies remain unresolved. The result is an overview of the services requiring attention, the decisions needed and the order in which you can prepare them.

That overview also helps determine which work is useful now. In some areas, responsibilities or acceptance agreements need to be clarified first. Elsewhere, an existing design can be tested or a tested application connected to day-to-day operations.

Choose support that fits your question

Ver.iD helps with the substantive choices and implementation around digital credentials. The right support depends on your question and the work already completed:

These services are separate entry points. An existing rulebook, earlier research or a tested integration can be the starting point. Your organisation retains ownership of substantive decisions and priorities; together, we agree which work Ver.iD carries out.

Focused preparation clarifies what eIDAS requires of your organisation and where you want to invest your effort. Discuss with Ver.iD where you stand and which choices you want to work through.