EU Digital Identity Wallet: Complete EUDI Guide for 2026
A practical guide to the EUDI Wallet: what it is, when it launches, how it works, what it stores, and what relying parties should prepare.
On this briefing
- 01 EUDI Wallet at a glance
- 02 What is the EU Digital Identity Wallet?
- 03 EUDI is an ecosystem, not one super-app
- 04 What data can an EUDI Wallet contain?
- 05 How an online EUDI Wallet presentation works
- 06 What selective disclosure does—and does not—mean
- 07 When will EUDI Wallets be available?
- 08 What does EUDI Wallet mean for businesses?
- 09 EUDI Wallet and eIDAS 2.0: what is the difference?
- 10 What organizations can prepare now
- 11 Frequently asked questions
The EU Digital Identity Wallet—usually shortened to EUDI Wallet—is the European Union's framework for letting people and organizations hold and present trusted digital identity data from a mobile wallet.
It is not one central EU app and it is not a database containing every European's identity. Each Member State must provide at least one certified wallet. Those wallets are meant to interoperate under common rules, technical specifications and trust mechanisms, so a credential issued in one country can be used with a service in another.
The legal framework is already in force. The wallets themselves are approaching rollout: the European Commission says Member States must provide them by the end of 2026. Availability will still vary by country, credential and use case as national implementations move from pilots to certified production services.
This guide separates what the law establishes, what the technical architecture is designed to do, and what is actually available today.
EUDI Wallet at a glance
| Question | Short answer |
|---|---|
| What is it? | A Member-State-provided digital wallet for identity data, attestations and electronic signatures or seals. |
| Is there one EU wallet app? | No. Member States provide one or more wallets that follow a common European framework. |
| Who can use it? | EU citizens, residents and businesses; use is voluntary. |
| When does it launch? | Member States are required to provide wallets by the end of 2026. National launch dates and capabilities can differ. |
| What can it hold? | Person Identification Data and electronic attestations such as qualifications, licences or other attributes. |
| Can a business request data? | Yes, as a registered wallet-relying party, within its declared purpose and permitted data scope. |
| Does it support signatures? | The regulation requires wallet support for qualified electronic signatures and seals. That is distinct from merely presenting identity data. |
| Is it already production-ready everywhere? | No. Reference implementations, pilots and national systems exist, but EU-wide production coverage is still emerging. |
What is the EU Digital Identity Wallet?
The legal definition appears in Regulation (EU) 2024/1183, the amendment that created the European Digital Identity Framework. In practical terms, a wallet lets its user:
- obtain and store person identification data;
- hold electronic attestations of attributes;
- choose what information to present to a relying party;
- authenticate to public and private services online and, where supported, offline;
- view a history of wallet transactions;
- create qualified electronic signatures or seals; and
- manage data under the user's control.
The wallet is an electronic identification means, but it is broader than a login button. It can carry claims about a person, organization or object and can support transactions where a service needs a verified fact rather than a reusable account password.
The Commission's EUDI Wallet overview gives examples including mobile driving licences, education credentials, proof of a right to reside, and information used to open a bank account or apply for a job.
EUDI is an ecosystem, not one super-app
“The European wallet” is convenient shorthand, but it can create the wrong mental model.
The regulation allows a wallet to be provided directly by a Member State, under a Member-State mandate, or independently and then recognized by a Member State. That means Europe will have multiple wallet solutions. The common layer is the legal and technical framework that makes those wallets recognizable across borders.
Four roles matter in a typical transaction:
- Wallet provider: provides the certified wallet solution.
- Credential or attestation provider: issues trusted information into the wallet.
- Wallet user: controls the wallet and approves a presentation.
- Relying party: requests and verifies specific information to provide a service.
A fifth layer—the national and EU trust infrastructure—helps participants determine which wallets, issuers and relying parties are legitimate.
This distinction matters for product planning. Supporting “EUDI” does not mean connecting to one endpoint and receiving every possible European credential. A real integration must understand credential types, trust lists, national relying-party registration, presentation protocols, issuer coverage and the exact claims needed for each use case.
What data can an EUDI Wallet contain?
The framework groups wallet data into several categories.
Person Identification Data (PID)
PID is the core identity dataset associated with the wallet under a high-assurance electronic identification scheme. Depending on the request and the available credential, it can include information such as a name, date of birth or other identifying attributes.
PID should not be confused with “the whole identity record.” A relying party asks for defined data, and the wallet shows the user what is requested before presentation.
Electronic Attestations of Attributes (EAAs)
An EAA is a digital statement that authenticates an attribute. The framework distinguishes ordinary EAAs, qualified electronic attestations of attributes (QEAAs), and attestations issued by or on behalf of public-sector bodies responsible for authentic sources.
Examples can include a professional qualification, university credential, driving entitlement, residency status or membership. The trust and legal effect depend on the type of attestation and its issuer—not simply on the fact that it appears inside a wallet.
The Commission's service-provider guide provides a useful overview of PID, QEAA, public-body attestations and other EAAs.
Electronic signatures and seals
The amended eIDAS framework also requires wallets to let natural persons create qualified electronic signatures by default and free of charge, although Member States may limit free use to non-professional purposes. Legal persons can use electronic seals.
That does not mean every wallet presentation is a qualified electronic signature. Identification, attribute presentation and signing are different operations with different evidence. A service should say which one it is requesting and should not market a simple PID disclosure as a signed contract.
Read EUDI Wallet signatures: identity presentation is not document signing for the boundary in more detail.
How an online EUDI Wallet presentation works
A remote transaction generally follows this shape:
- A person starts an action on a relying party's website or app.
- The relying party creates a request describing the credential and attributes it needs.
- The request is transferred to the user's wallet, on the same device or across devices.
- The wallet authenticates the relying party and displays the requested data and purpose.
- The user approves or declines.
- The wallet returns a cryptographically protected presentation.
- The relying party validates the wallet, issuer, credential status, request binding and disclosed data before using the result.
The Architecture and Reference Framework defines the ecosystem and its high-level requirements. Current interoperability work uses specifications including OpenID for Verifiable Presentations for remote presentation, OpenID for Verifiable Credential Issuance for issuance, and ISO/IEC 18013-5 for mobile-document use cases. The Commission's Launchpad testing scope shows these standards being tested between wallets, issuers and readers.
The protocol is only part of verification. A relying party must also establish trust in the issuer and wallet, validate the transaction challenge, enforce the registered request scope, handle status or revocation, and bind the verified result to the correct application session.
For a closer technical explanation, see How the EUDI Wallet architecture works.
What selective disclosure does—and does not—mean
The EUDI framework is designed around user control and data minimisation. A relying party should request the attributes necessary for its declared purpose, and the wallet should make the request visible to the user.
That enables better patterns than copying an entire identity document. An age-restricted service, for example, may be able to request an age-related proof instead of collecting a full document image.
But “selective disclosure” is not the same as anonymity. If a service requests a name and date of birth, those values are still disclosed. Transaction metadata, the relying party's own account data, legally required records and downstream systems also remain part of the privacy analysis.
The regulation requires wallet use to be voluntary and says access must not be restricted or made disadvantageous for people who do not use a wallet. Existing identification and authentication methods must remain available. It also requires privacy-preserving techniques where an attestation does not require identification.
When will EUDI Wallets be available?
The Digital Identity Regulation entered into force on 20 May 2024. Core implementing regulations established common rules for wallet functionality, protocols, certification, PID and attestations. The Commission now states that Member States must provide wallets by the end of 2026.
That date is a legal rollout milestone, not a promise that every country, issuer, browser, relying party and use case becomes available on the same day.
As of August 2026:
- Member States and implementation teams are preparing national wallet solutions;
- reference wallet components and technical specifications are public and evolving;
- six large-scale pilot projects have tested or are testing more than eleven everyday use cases;
- interoperability events are testing issuance, remote presentation and proximity presentation; and
- the Commission has started a relying-party engagement programme for organizations preparing to integrate.
The official large-scale pilot overview reports participation from hundreds of public and private organizations across most Member States, plus associated countries.
For the dated milestones and what remains uncertain, read The EUDI Wallet timeline from eIDAS 2.0 to rollout.
What does EUDI Wallet mean for businesses?
An organization that requests data from a wallet is a wallet-relying party. Article 5b requires relying parties to register in the Member State where they are established and declare, at minimum:
- information needed to authenticate the relying party;
- contact details;
- the intended wallet use; and
- the data the relying party intends to request.
The relying party may not request data beyond that declared scope. It must identify itself to the user and is responsible for authenticating and validating PID and attestations it receives. Intermediaries acting for relying parties are also treated as relying parties and face a specific restriction against storing transaction content.
This registration model is still being translated into national procedures. A software integration therefore needs an operational onboarding path, not only standards-compliant code.
Who must accept EUDI Wallets?
The acceptance rules are often overstated.
- Public-sector bodies that require electronic identification for an online service must also accept compliant EUDI Wallets.
- Certain private relying parties—excluding micro and small enterprises—must accept wallets where law or contract requires strong user authentication for online identification. The regulation lists sectors such as banking, health, transport, energy, telecommunications and education, and ties the deadline to the relevant implementing acts.
- Very large online platforms that require authentication must accept the wallet for authentication at the user's voluntary request and with the minimum necessary data.
This is not a blanket rule that every European website must add an EUDI button on launch day. Organizations should map Article 5f and applicable sector or national law to their actual service with counsel.
See EUDI Wallet for businesses: a relying-party readiness guide for a practical preparation checklist.
EUDI Wallet and eIDAS 2.0: what is the difference?
eIDAS is the EU legal framework for electronic identification and trust services. “eIDAS 2.0” is the common informal name for the 2024 amendment, Regulation (EU) 2024/1183.
EUDI Wallet is one major system created by that amended framework. The regulation also covers trust services such as electronic signatures, seals, timestamps, website authentication, electronic archiving and electronic ledgers.
So EUDI Wallet and eIDAS 2.0 are related, but they are not synonyms. One is a wallet ecosystem; the other is the wider legal framework. Read eIDAS 2.0 explained for the legal map without the jargon.
What organizations can prepare now
Even before national production access is available, teams can make decisions that reduce later rework:
- Define the fact, not the document. Write down the minimum verified attributes each journey truly needs.
- Separate authentication from authorization. A valid wallet presentation proves facts; the application still decides what those facts permit.
- Inventory relying-party entities. Establishment country, legal identity, domains, purposes and requested attributes affect registration.
- Design consent and fallback paths. Wallet use is voluntary, so unsupported users need a clear alternative.
- Plan trust validation. Protocol parsing without issuer, wallet, status and request-binding validation is not verification.
- Treat country coverage as a matrix. Track wallet, credential, issuer, trust and registration availability separately.
- Test with synthetic credentials. Reference environments can validate user journeys and protocol handling without pretending test credentials are production identity.
- Keep evidence claims precise. An identity presentation, age result, advanced signature and qualified signature are different outcomes.
Alentra is building a composable API layer around these concerns: applications request small identity and signing primitives while route-specific wallet, credential and trust details remain behind a canonical coverage model. Production EUDI routes remain coming soon; the current sandbox uses synthetic reference credentials and must not be represented as live identity verification.
Frequently asked questions
Is the EUDI Wallet mandatory for citizens?
No. The regulation says wallet use is voluntary. Natural persons must receive issuance, use and revocation free of charge, and services must keep alternative access methods available.
Is there a single EU Digital Identity Wallet app?
No. Every Member State must provide at least one wallet, and a country may provide or recognize more than one. The common framework is intended to make certified wallets interoperable.
Can I download an EUDI Wallet today?
Some national identity wallets, pilots and reference apps already exist, but that is not the same as universal certified EUDI production availability. Check the responsible authority in your Member State and the credential or service you want to use.
Does the wallet replace a passport or physical identity card?
Not automatically. A wallet can carry digital identity data and credentials, but whether it replaces a physical document in a particular situation depends on the credential, applicable law and accepting authority.
Can a wallet prove age without sharing a birth date?
The framework supports selective disclosure and privacy-preserving proofs. Actual availability depends on the credential, requested attribute, wallet implementation and relying-party integration.
Does an EUDI Wallet make every signature qualified?
No. The wallet must support creation of qualified electronic signatures, but an ordinary identity presentation or approval gesture is not automatically a QES.
Can one integration cover all 27 Member States?
Common standards make reuse possible, but production coverage still depends on national registration, wallet and issuer trust, available credentials and interoperability. Treat “EUDI support” as a changing route matrix rather than a single boolean.
Where are the authoritative rules?
Start with Regulation (EU) 2024/1183, the Commission's EUDI policy page, and the latest Architecture and Reference Framework. Technical documents continue to evolve, so check version dates before making production decisions.
This article is an informational overview, not legal advice or a claim that any specific national wallet, credential or relying-party route is currently available.
Our field notes are checked against primary regulations, standards, and official provider documentation. Read the research standard.