Health, finances, online behaviour: Digital IDs are poised to become an integral part of very sensitive aspects of our lives. Together with an international coalition we make it clear: Citizens will put no trust in the European Digital Identity Wallet without transparency and users being in control over their data.

The final technical design of the European Digital Identity Wallet is currently under negotiation. These blueprints will have a big impact on whether or not users will be sufficiently protected when using Europe's upcoming digital identity system. In concrete terms, this is currently being negotiated in the eIDAS implementation acts between the EU member states and the European Commission.

The positive changes in the first batch of technical rules show: Civil society works! Together with 15 organisations we thank the negotiators and acknowledge these significant improvements for privacy and human rights safeguards. The most recent proposals, however, still have some severe privacy and transparency problems that we address in our open letter to the European Commission.

What is the problem? 

The eIDAS regulation lays out concrete rules for those companies and government agencies who want to access personal information from citizens’ Wallets. This could be for example an online platform, a public transport company or your doctor. It obliges these so-called “relying parties” to register their intended use of the Wallet, that is which attributes they intend to request from users. The regulation also prohibits them from asking information that goes beyond their registration. This could mean for example that, according to its registration, an online shop is only allowed to ask for your name and address but not your birth date or other information. A porn platform might use the Wallet to verify your age, but couldn’t obtain not any other information about you or use other means to track your behaviour.

To protect everyone from such illegal requests, the EU’s Digital Identity Wallet needs to know what personal information a relying party is actually allowed to access. The EU Commission, however, proposes a loophole which would leave it to the Member State that registered the relying party to decide whether the Wallet knows about the contents of the registration or not. This would allow Facebook Ireland to circumvent the protections and ask European users for everything. Furthermore, the public register of relying parties risks being useless without harmonised specifications on how to access it and what results to expect. Ultimately, the trust we will put in the Wallet will depend on the protections and transparency that we can rely on.

15 Organisations demand: The Commission’s Loopholes Must be Closed!

If these loopholes remain, this would have disastrous consequences. Any discrimination based on illegal access to attributes in the Wallet (health, gender, income, etc.) would be unchecked. Given the track record of lax data protection enforcement in countries like Ireland, companies like Facebook Ireland would likely have a wildcard certificate, virtually empowering them to request any data they want. Member States dedicated to protecting their users from illegal requests (e.g. Germany, the Netherlands, Spain or Austria), on the other hand, would be incapable of doing so.

We therefore ask the Commission to make relying party registration certificates mandatory for all relying parties and to issue a harmonized specification to access the relying party registry of each Member State.

Read Our Letter

We also discussed about this issue in our recent presentation at the 38. Chaos Communication Congress (38c3):

[Translate to English:]

Since you're here

… we have a small favour to ask. For articles like this, we analyse legal texts, assess official documents and read T&Cs (really!). We make sure that as many people as possible concern themselves with complicated legal and technical content and understand the enormous effects it has on their lives. We do this with the firm conviction that together we are stronger than all lobbyists, powerful decision makers and corporations. For all of this we need your support. Help us be a strong voice for civil society!

Become a supporter now!

Related stories: