My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/2979 CHAPTER III — CORE FUNCTIONALITIES AND FEATURES OF EUROPEAN DIGITAL IDENTITY WALLETS

Article 8–Article 14 · 7 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Formats for person identification data and electronic attestations of attributes

Article 8

Wallet providers shall ensure that wallet solutions support the usage of person identification data and electronic attestations of attributes issued in compliance with the list of standards set out in Annex II.

Transaction logs

Article 9

1.   Irrespective of whether or not a transaction is successfully completed, wallet instances shall log all transactions with wallet-relying parties and other wallet units, including electronic signing and sealing. 2.   The logged information shall at least contain: (a) the time and date of the transaction; (b) the name, contact details, and the unique identifier of the corresponding wallet-relying party and the Member State in which that wallet-relying party is established, or in case of other wallet units, relevant information from the wallet unit attestation; (c) the type or types of data requested and presented in the transaction; (d) in the case of non-completed transactions, the reason for such non-completion. 3.   Wallet providers shall ensure integrity, authenticity and confidentiality of the logged information. 4.   Wallet instances shall log reports sent by the wallet user to the data protection authorities via their wallet unit. 5.   The logs referred to in paragraphs 1 and 2 shall be accessible to the wallet provider, where it is necessary for the provision of wallet services, on the basis of explicit prior consent by the wallet user. 6.   The logs referred to in paragraphs 1 and 2 shall remain accessible for as long as they are required by Union law or national law. 7.   Wallet providers shall enable wallet users to export the logged information referred to in paragraph 2.

Embedded disclosure

Article 10

1.   Wallet providers shall ensure that electronic attestations of attributes with common embedded disclosure policies set out in Annex III can be processed by the wallet units that they provide. 2.   Wallet instances shall be able to process and present such embedded disclosure policies referred to in paragraph 1 in conjunction with data received from the requesting wallet-relying party. 3.   Wallet instances shall verify whether the wallet-relying party complies with the requirements of the embedded disclosure policy and inform the wallet user of the result.

Qualified electronic signatures and seals

Article 11

1.   Wallet providers shall ensure that wallet users are able to receive, qualified certificates for qualified electronic signatures or seals which are linked to qualified signature or seal creation devices that are either local, external, or remote in relation to the wallet instances. 2.   Wallet providers shall ensure that wallet solutions are able to securely interface with one of the following types of qualified signature or seal creation devices: local, external, or remotely managed qualified signature or seal creation devices for the purposes of using the qualified certificates referred to in paragraph 1. 3.   Wallet providers shall ensure that wallet users who are natural persons have, at least for non-professional purposes, free-of-charge access to signature creation applications which allow the creation of free-of-charge qualified electronic signatures using the certificates referred to in paragraph 1.

Signature creation applications

Article 12

1.   The signature creation applications used by wallet units may be provided either by wallet providers, by providers of trust services or by wallet-relying parties. 2.   Signature creation applications shall have the following functions: (a) signing or sealing wallet user-provided data; (b) signing or sealing relying party-provided data; (c) creating signatures or seals in accordance with at least the mandatory format s referred to in Annex IV; (d) informing wallet users about the result of the signature or seal creation process. 3.   The signature creation applications may either be integrated into or be external to wallet instances. Where signature creation applications rely on remote qualified signature creation devices and where they are integrated into wallet instances, they shall support the application programming interface referred to in Annex IV.

Data export and portability

Article 13

Wallet units shall, where technically feasible and excepting cases of critical assets, support secure export and portability of personal data of the wallet user, to allow the wallet user to migrate to a wallet unit of a different wallet solution in a way that ensures level of assurance high as set out in Implementing Regulation (EU) 2015/1502.

Pseudonyms

Article 14

1.   Wallet units shall support the generation of pseudonyms for wallet users in compliance with the technical specifications set out in Annex V. 2.   Wallet units shall support the generation, upon the request of a wallet-relying party, of a pseudonym which is specific and unique to that wallet-relying party and provide this pseudonym to the wallet-relying party, either standalone or in combination with any person identification data or electronic attribute attestation requested by that wallet-relying party.

Back to Commission Implementing Regulation (EU) 2024/2979 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next