My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/2982 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards protocols and interfaces to be supported by the European Digital Identity Framework

Commission Implementing Regulation (EU) 2024/2982 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards protocols and interfaces to be supported by the European Digital Identity Framework

Implementing Regulation (EU) 2024/2982 · Regulation · 9 articles

Data as of 2026-07-04 · Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Subject matter and scope

Article 1

This Regulation lays down rules on the protocols and interfaces of wallet solutions for: (1) the issuance of person identification data and electronic attestations of attributes to wallet units; (2) the presentation of attributes of person identification data and electronic attestations of attributes, to wallet-relying parties and other wallet units; (3) the communication of data erasure requests to wallet-relying parties; (4) the reporting of wallet-relying parties to supervisory authorities established under Article 51 of Regulation (EU) 2016/679; to be updated on a regular basis to keep in line with technology and standards developments and with the work carried out on the basis of Recommendation (EU) 2021/946, and in particular the Architecture and Reference Framework.

Definitions

Article 2

For the purpose of this Regulation, the following definitions apply: (1) ‘wallet-relying party’ means a relying party that intends to rely upon wallet units for the provision of public or private services by means of digital interaction; (2) ‘wallet user’ means a user who is in control of the wallet unit; (3) ‘wallet solution’ means a combination of software, hardware, services, settings, and configurations, including wallet instances, one or more wallet secure cryptographic applications and one or more wallet secure cryptographic devices; (4) ‘wallet unit’ means a unique configuration of a wallet solution that includes wallet instances, wallet secure cryptographic applications and wallet secure cryptographic devices provided by a wallet provider to an individual wallet user; (5) ‘wallet provider’ means a natural or legal person who provides wallet solutions; (6) ‘wallet instance’ means the application installed and configured on a wallet user’s device or environment, which is part of a wallet unit, and that the wallet user uses to interact with the wallet unit; (7) ‘wallet secure cryptographic application’ means an application that manages critical assets by being linked to and using the cryptographic and non-cryptographic functions provided by the wallet secure cryptographic device; (8) ‘wallet secure cryptographic device’ means a tamper-resistant device that provides an environment that is linked to and used by the wallet secure cryptographic application to protect critical assets and provide cryptographic functions for the secure execution of critical operations; (9) ‘critical assets’ means assets within or in relation to a wallet unit of such extraordinary importance that where their availability, confidentiality or integrity are compromised, this would have a very serious, debilitating effect on the ability to rely on the wallet unit; (10) ‘wallet-relying party access certificate’ means a certificate for electronic seals or signatures authenticating and validating the wallet-relying party issued by a provider of wallet-relying party access certificates; (11) ‘provider of wallet-relying party access certificates’ means a natural or legal person mandated by a Member State to issue relying party access certificates to wallet-relying parties registered in that Member State; (12) ‘wallet unit attestation’ means a data object that describes the components of the wallet unit or allows authentication and validation of those components; (13) ‘embedded disclosure policy’ means a set of rules, embedded in an electronic attestation of attributes by its provider, that indicates the conditions that a wallet-relying party has to meet to access the electronic attestation of attributes; (14) ‘wallet-relying party registration certificate’ means a data object that indicates the attributes the relying party has registered to intend to request from users; (15) ‘provider of person identification data’ means a natural or legal person responsible for issuing and revoking the person identification data and ensuring that the person identification data of a user is cryptographically bound to a wallet unit; (16) ‘cryptographic binding’ means the method to link person identification data or electronic attestations of attributes to wallet units through cryptographic means.

General provisions

Article 3

Regarding the protocols and interfaces referred to in Articles 4 and 5, wallet providers shall ensure that wallet units: (1) authenticate and validate the wallet-relying party access certificates where interacting with wallet-relying parties; (2) authenticate and validate the wallet unit attestations of other wallet units where interacting with other wallet units; (3) authenticate and validate requests made using wallet-relying party access certificates or wallet unit attestations from other wallet units, where applicable; (4) authenticate and validate the wallet-relying party registration certificate, where applicable; (5) display to wallet users information contained in the wallet-relying party access certificates or in the wallet unit attestations; (6) display to wallet users, where applicable, the attributes that wallet users are requested to present; (7) display to wallet users, where applicable, information contained in the wallet-relying party registration certificate; (8) present wallet unit attestations of the wallet unit to wallet-relying parties or wallet units that request it; (9) do not present any requested attributes to wallet-relying parties or wallet units until the following requirements are met: (a) verify the wallet secure cryptographic application has authenticated the identity of the wallet user; (b) verify embedded disclosure policies have been processed within the wallet unit in accordance with Article 11 of Implementing Regulation (EU) 2024/2979, where applicable; (c) verify wallet users have partially or in full approved the presentation. (10) enable privacy preserving techniques which ensure unlinkability where the electronic attestations of attributes do not require the identification of the wallet user, when presenting attestations or person identification data across different wallet-relying parties.

Issuance of person identification data and electronic attestations of attributes to wallet units

Article 4

1.   Wallet providers shall ensure that wallet solutions support protocols and interfaces for the issuance of person identification data and electronic attestations of attributes to wallet units. 2.   Wallet providers shall ensure that wallet units request issuance of person identification data and electronic attestations of attributes only from parties having an authentic and valid wallet-relying party access certificate attesting them as: (a) a provider of person identification data; (b) a provider of a qualified electronic attestation of attributes; (c) a provider of an electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source; or (d) a provider of non-qualified electronic attestations of attributes. 3.   In relation to the issuance of person identification data and electronic attestations of attributes to a wallet unit, wallet providers shall ensure that the following requirements are complied with: (a) where wallet users use their wallet unit to request the issuance of person identification data or of electronic attestations of attributes from providers of person identification data or providers of electronic attestations of attributes that enable issuance of person identification data or electronic attestations in more than one format, the wallet unit shall request it in all formats referred to in Article 8 of Implementing Regulation (EU) 2024/2979 laying down rules for the application of Regulation (EU) No 910/2014 as regards the integrity and core functionalities of European Digital Identity Wallets; (b) where wallet users use their wallet unit to interact with providers of person identification data or electronic attestations of attributes, wallet units shall enable authentication and validation of the wallet unit components by presenting the wallet unit attestations to those providers upon their request; (c) wallet solutions shall support mechanisms that enable providers of person identification data to verify issuance, delivery and activation in compliance with assurance level high requirements set out in Commission Implementing Regulation (EU) 2015/1502  ( 11 ) ; (d) wallet units shall verify the authenticity and validity of person identification data and electronic attestations of attributes.

Presentation of attributes to wallet-relying parties

Article 5

1.   Wallet providers shall ensure that wallet solutions support protocols and interfaces for the presentation of attributes to wallet-relying parties, remotely, and where appropriate in proximity, in accordance with the standards set out in the Annex. 2.   Wallet providers shall ensure that, at the request of users, wallet units respond to successfully authenticated and validated requests from wallet-relying parties referred to in Article 3, in accordance with the standards set out in the Annex. 3.   Wallet providers shall ensure that wallet units support proving the possession of private keys corresponding to public keys used in cryptographic bindings. 4.   Wallet providers shall ensure that wallet solutions support the selective disclosure of attributes of personal identification data and of electronic attestations of attributes. 5.   Paragraphs 1 to 4 shall apply mutatis mutandis to interactions between two wallet units in proximity.

Communication of data erasure requests

Article 6

1.   Wallet providers shall ensure that wallet units support protocols and interfaces allowing wallet users to request from wallet-relying parties, with whom they have interacted through those wallet units, the erasure of their personal data provided through those wallet units, in accordance with Article 17 of Regulation (EU) 2016/679. 2.   The protocols and interfaces referred to in paragraph 1 shall allow wallet users to select the wallet-relying parties to which data erasure requests are to be submitted. 3.   Wallet units shall display to the wallet user previously submitted data erasure requests made through those wallet units.

Reporting of wallet-relying parties to supervisory authorities established under Article 51 of Regulation (EU) 2016/679

Article 7

1.   Wallet providers shall ensure that wallet units allow wallet users to easily report wallet-relying parties to supervisory authorities established under Article 51 of Regulation (EU) 2016/679. 2.   Wallet providers shall implement the protocols and interfaces for reporting wallet-relying parties in compliance with national procedural laws of the Member States. 3.   Wallet providers shall ensure that wallet units allow wallet users to substantiate the reports, including by attaching relevant information to identify the wallet-relying parties, and the wallet users’ claims in machine-readable format.

Entry into force

Article 8

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union .

Supplementary provisions

ANNEXSupplementary provisions

ANNEX STANDARDS REFERRED TO IN ARTICLE 5(1) AND (2) — ISO/IEC 18013-5:2021 — ISO/IEC TS 18013-7:2024

Other acts of the same type
Commission Implementing Regulation (EU) 2023/1589 of 27 July 2023 approving non-minor amendments to the product specification for a name entered in the register of protected designations of origin and protected geographical indications (‘Alcachofa de Tudela’ (PGI))Commission Regulation (EU) 2023/1545 of 26 July 2023 amending Regulation (EC) No 1223/2009 of the European Parliament and of the Council as regards labelling of fragrance allergens in cosmetic products (Text with EEA relevance)Commission Implementing Regulation (EU) 2023/1546 of 26 July 2023 entering a name in the register of protected designations of origin and protected geographical indications ‘Pancetta de l’Ile de Beauté / Panzetta de l'Ile de Beauté’ (PGI), ‘Saucisson sec de l’Ile de Beauté / Salciccia de l'Ile de Beauté’ (PGI), ‘Bulagna de l’Ile de Beauté’ (PGI) and ‘Figatelli de l'Ile de Beauté / Figatellu de l'Ile de Beauté’ (PGI)Commission Implementing Regulation (EU) 2023/1547 of 26 July 2023 entering a name in the register of protected designations of origin and protected geographical indications (‘Gower Salt Marsh Lamb’ (PDO))Commission Implementing Regulation (EU) 2023/1557 of 26 July 2023 amending Regulation (EC) No 1484/95 as regards fixing representative prices in the poultrymeat and egg sectors and for egg albuminCommission Regulation (EU) 2023/1536 of 25 July 2023 amending Annex III to Regulation (EC) No 396/2005 of the European Parliament and of the Council as regards maximum residue levels for nicotine in or on certain products (Text with EEA relevance)Commission Implementing Regulation (EU) 2023/1537 of 25 July 2023 laying down rules for the application of Regulation (EU) 2022/2379 of the European Parliament and of the Council as regards statistics on the use of plant protection products to be transmitted for the reference year 2026 during the transitional regime 2025-2027 and as regards statistics on plant protection products placed on the market (Text with EEA relevance)Commission Implementing Regulation (EU) 2023/1538 of 25 July 2023 laying down rules for the application of Regulation (EU) 2022/2379 of the European Parliament and of the Council as regards crop production statistics (Text with EEA relevance)Commission Implementing Regulation (EU) 2023/1572 of 25 July 2023 establishing a derogation from Implementing Regulation (EU) 2019/2072 concerning the introduction into the Union territory of tubers of Solanum tuberosum L., other than those intended for planting, originating in certain regions of LebanonCouncil Regulation (EU) 2023/1782 of 25 July 2023 amending Regulation (EU) 2021/2085 establishing the Joint Undertakings under Horizon Europe, as regards the Chips Joint Undertaking (Text with EEA relevance)Commission Delegated Regulation (EU) 2023/2450 of 25 July 2023 supplementing Directive (EU) 2022/2557 of the European Parliament and of the Council by establishing a list of essential servicesCommission Implementing Regulation (EU) 2023/1535 of 24 July 2023 amending Implementing Regulations (EU) 2018/2019 and (EU) No 2020/1213 as regards certain plants for planting of Acer campestre, Acer palmatum, Acer platanoides and Acer pseudoplatanus originating in the United Kingdom

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next