Revocation of person identification data
Article 5
1. Providers of person identification data issued to a wallet unit shall have written and publicly accessible policies relating to validity status management, including, where applicable, the conditions under which such person identification data can be revoked without delay. 2. Only providers of person identification data or electronic attestation of attributes can revoke the person identification data or electronic attestations of attributes issued by them. 3. Where providers of person identification data have revoked person identification data, they shall, through dedicated and secure channels, inform wallet users subject of those person identification data within 24 hours of the revocation and of the reasons for the revocation. This shall be done in a manner that is concise, easily accessible and using clear and plain language. 4. Where providers of person identification data revoke person identification data issued to wallet units, they shall do so in each of the following circumstances: (a) upon the explicit request of the wallet user to whose wallet unit the person identification data or electronic attestation of attributes were issued to; (b) where the wallet unit attestation to which the person identification data was issued to has been revoked; (c) in other situations determined by the providers of person identification data or electronic attestations of attributes in their policies referred to in paragraph 1. 5. Providers of person identification data issued to a wallet unit shall ensure that revocations cannot be reverted. 6. The revoked person identification data shall remain accessible for as long as required by Union law or national law. 7. Where providers of person identification data revoke person identification data issued to wallet units, they shall make publicly available the validity status of person identification data they issue, in a privacy preserving manner, and indicate the location of that information in the person identification data. 8. Providers of person identification data shall enable privacy preserving techniques which ensure unlinkability where the electronic attestations of attributes do not require the identification of the user.