The law establishes the national legal framework for the introduction of the European Digital Identity Wallet (EUDI Wallet) in Germany, for which the eIDAS Regulation provides the framework. The following article summarizes the key provisions of the government draft.
Table of Contents
Under the eIDAS Regulation, the EUDI Wallet is introduced as a means of electronic identification in which users can store personal identification data and electronic attribute certificates (e.g., educational credentials, driver’s license) and present them to relying parties. The eIDAS Regulation requires each member state to provide at least one EUDI Wallet. Although the eIDAS Regulation is directly applicable, it still leaves Member States some leeway regarding its specific implementation, for example with regard to responsibilities and procedures. The key implementation provisions for Germany are to be consolidated in a law on the European Digital Identity Wallet (EBDIG) (Article 1 of the Digital Identities Act).
The EBDIG addresses the following key issues:
1. Competent Authorities
- The Federal Ministry for Digital Affairs and State Modernization (BMDS) will have central responsibility for providing the EUDI Wallet and issuing personal identification data; it also has residual competency for over all tasks not assigned to any other authority or ministry.
- The Federal Office of Administration is responsible for the registration of relying parties and validation mechanisms, which is a responsibility it already holds for other eIDAS certificates.
- The Federal Office for Information Security (BSI) is responsible for national certification systems, notifying users of security breaches, and taking measures in the event of security incidents.
- The Federal Network Agency is the competent supervisory authority for the EUDI Wallet framework and the point of contact pursuant to Article 46c (1) of the eIDAS Regulation.
In addition, there is an accreditation body (under the Accreditation Bodies Act) responsible for accrediting conformity assessment bodies.
2. Quick Decision Required: Three Possible Approaches to Providing the Wallet
The eIDAS Regulation permits three models for providing an EUDI wallet, and the German implementation essentially allows for all three:
(1) Directly provided by the Federal Republic of Germany (Section 4 EBDIG): The state provides the wallet itself or delegates this task to a government agency.
(2) On behalf of the Federal Republic of Germany (Section 5 EBDIG): Awarded as a public contract to a contractor in accordance with public procurement regulations.
(3) Independently of the Federal Republic of Germany but recognized by it (§ 6 EBDIG): Private providers may apply for recognition; the details of the recognition procedure are set forth by statutory order.
However, the law does not specify whether all three models must be adopted; instead, it delegates the decision to the BMDS, which may choose one, several, or all three models in parallel, although this lack of clarity has been criticized repeatedly during the legislative process. After all, time is running out, and investments in a German EUDI wallet will not be made unless it is clear that private providers have any chance at all of being recognized. So perhaps a preliminary decision has already been made by the legislator. The decision regarding the method of provision will not take effect until it is published in the Federal Gazette. The BMDS may still adjust its decision in favor of one or more models at its discretion at a later point in time. A limit of the number of private providers to be recognized is expressly prohibited.
3. Regulations Governing the Operation of the EUDI Wallet
- Validity and Revocation: an issued wallet is generally valid. Revocation is carried out by the wallet provider at the request of the competent authority or at the user’s request. In the event of security breaches, the BSI may suspend the provision and use of the wallet.
- Personal Identification Data: the authority designated by the BMDS is the provider of personal identification data. For sole traders and legal entities eligible for registration, the respective registers (commercial, cooperative, corporate, partnership, foundation, and association registers) serve as authentic sources within the meaning of the eIDAS Regulation. For other legal entities, such as local governments, public-law foundations and institutions, or legal entities under foreign law, the Register of Basic Business Data serves as a supplementary authentic source.
- Registration of Relying Parties: the Federal Administrative Office registers companies and other entities that wish to retrieve data from the Wallet as relying parties and maintains the corresponding list centrally for the entire federal territory. Registration must be denied if there are factual or legal grounds for doing so. The law remains vague on this point regarding what constitutes grounds for rejection and provides few concrete details on the procedure. For relying parties that are legally required to accept the EUDI Wallet (see Article 5f of the eIDAS Regulation), the law therefore offers no guidance on how to prepare.
- Interoperability: the wallet should be linkable to user accounts under the Online Access Act and the National Once-Only Technical System (NOOTS), for example, logging into the portal network or exchanging data via the respective mailbox.
It is important to note that the EBDIG also applies to wallets that do not offer the full range of functions specified by eIDAS. This is intended to prevent the deliberate offering of limited wallets to circumvent regulations.
4. Use of the EUDI Wallet
- As a means of electronic identification: whenever laws require proof of electronic identity under the Identity Card Act, the eID Card Act, or the Residence Act, such proof can in the future also be provided via the wallet. This is ultimately nothing new, as it is already stipulated by the eIDAS Regulation; it is simply the implementation of eIDAS into the German legal framework. Natural and legal persons are themselves responsible for managing powers of representation (such as corporate or statutory representation); proof is provided via electronic attribute certificates linked to authentic sources. Section 15 of the EBDIG thus also clarifies that, contrary to its heading, Article 5f of the eIDAS Regulation applies not only to cross-border situations but also to domestic ones.
- Electronic attribute certificates: after a transition period of 24 months following the enactment of the law, federal authorities must, upon request, also issue their decisions and documents, which are issued upon application, as electronic attribute certificates. Such certificates are equivalent, within the scope of federal law, to the written form required by law, unless this is expressly excluded or subject to additional requirements (such as a qualified electronic signature). However, certificates issued by state authorities. which are important in practice, are not covered.
- NFC and RFID Access: the law generally permits the integration of NFC and RFID authorizations or technologically similar methods into the EUDI Wallet, but only if this does not impair the wallet’s functions, compromise security, or pose unreasonable risks to users.
Important Information for Payment Service Providers: Integration of Payment Methods
According to Section 17 of the EBDIG, the EUDI Wallet may, as an additional feature, integrate the user’s existing payment methods (although the law refers to “means of payment” which could be confused with legal tender) provided by an authorized payment service provider. This implicitly clarifies that it is not the EUDI Wallet provider that must hold authorization as a payment service provider, but rather the provider of the payment instrument selected by the user. Who and how many payment service providers will be authorized remains to be determined and is subject to the regulation yet to be issued, which must, however, ensure non-discriminatory access. Here, too, the market must continue to wait to learn the specific conditions under which integration will be possible.
Integration is subject to the condition that the core functions or security of the wallet are not compromised and that it does not create unreasonable risks for users, relying parties, or legal transactions (similar provision applies to NFC/RFID authorization, see above). The planned integration must be reported to the BSI at least three months before it becomes operational.
The law contains no provisions regarding the hotly debated allocation of liability among wallet providers, payment service providers, and relying parties in the event that something goes wrong. Contractual arrangements will likely have to be established in this regard; however, this is of no help to such relying parties, who are legally required under Article 5f of the eIDAS Regulation to accept the EUDI wallet for identification and strong customer authentication and who generally do not have a contract with the wallet provider.
Changes to the Money Laundering Act
In addition to the introduction of the EBDIG, the Digital Identities Act also contains other articles that amend existing laws. Of particular note are the amendments to the German Money Laundering Act (GwG):
Additional Means of Identification
The EUDI wallet is introduced as an additional means of identification in Section 12(1) of the GwG as a new subparagraph 4a. This may seem redundant because notified electronic identification systems are already listed in No. 4; however, the electronic identity feature of the national ID card, the eID card, and the electronic residence permit are already listed separately in No. 2, even though they are notified identification systems. Thus, the provision remains within its own logic strictly redundant.
Record-Keeping Requirement
A new Section 8(2), sentence 9 of the GwG also clarifies that the authentication and validation process must be recorded. These regulations will not remain in effect for long, as the AML Regulation will take effect on July 10, 2027.
No More Reference Transfers with QES
Nevertheless, the law introduces a new provision for this transitional period that is independent of the EUDI wallet: The reference transfer, which was previously required when using a qualified electronic signature as proof of identity pursuant to Section 12(1), sentence 3 of the GwG, will be eliminated in light of the future legal situation under the AML Regulation.
Surprising Developments for Young and Old
The government draft also includes an experimental clause under which the BMDS may permit temporary deviations from the EBDIG; for example, following a risk assessment, personal identification data could be issued to individuals as young as 13 years of age. Let’s get kids using the EUDI Wallet!
The legislature, however, places fewer demands on older adults and has amended the Identity Card Act to stipulate that individuals who applied for their identity card at the age of 70 or older may continue to use it indefinitely; however, this does not apply to the eID function and is unrelated to the EUDI wallet
Criticism of the Draft Bill
Criticism focuses primarily on the fact that key provisions will only be established through a regulation issued by the Federal Ministry of Digital and Society (BMDS)—such as those regarding the method of provision, additional functions, the recognition procedure for private providers (if they are approved at all), requirements for the integration of payment providers, and the potential obligation for companies to accept or issue electronic attribute certificates. These further delays the important decision-making basis for companies (after all, the EUDI wallet is scheduled to launch at the end of the year) and is also somewhat questionable from the perspective of the rule of law if key decisions are deferred to a statutory regulation.
