ASSESSMENT OF EU DIGITAL IDENTITY WALLET FROM SECURITY PERSPECTIVE

Authors

  • Alexander Yankov Law and History Faculty, South-West University “Neofit Rilski” Blagoevgrad, Bulgaria

DOI:

https://doi.org/10.68302/std2026.vol1.39

Keywords:

European Digital Identity Wallet, sovereign digital ecosystem, level of assurance, GDPR, digital euro

Abstract

The European Union tries to introduce a sovereign digital ecosystem centered on the European Digital Identity Wallet (EUDI), a user‑controlled instrument designed to combine strong technical safeguards—multi‑factor authentication, zero‑knowledge encryption, and secure hardware elements (SE/TEE)—with the legal mechanisms such as qualified electronic signatures (QES) under eIDAS 2.0. The wallet promises GDPR‑compliant local storage of personal identification data and streamlined access to cross‑border digital services, while supporting a risk‑based hierarchy of Levels of Assurance (LoA) to match authentication strength to transaction sensitivity. However, the architecture and policy choices that enable these benefits also introduce significant security, privacy and socio‑economic risks: key compromise and supply‑chain vulnerabilities; tensions between device‑centric and cloud‑assisted models; potential loss of financial privacy with a digital euro; profiling and exclusion of vulnerable populations; and data minimization. Successful deployment therefore requires not only robust cryptography and certified hardware, but also resilient recovery mechanisms, interoperable standards, transparent governance, independent audits and inclusion policies that balance security, convenience and civil liberties.

Downloads

Download data is not yet available.

References

[1] 2025 State of the Union Address by President von der Leyen, 10th September, 2025. [Online]. Available: https://ec.europa.eu/commission/presscorner/detail/ov/SPEECH_25_2053. [Accessed: Dec. 15, 2025].

[2] Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework, PE/68/2023/REV/1OJ L, 2024/1183, 30th April 2024. [Online]. Available: ELI: http://data.europa.eu/eli/reg/2024/1183/oj[Accessed: Oct. 26, 2025].

[3] (MFA) is a security process requiring users to provide two or more verification factors to gain access to an account, rather than relying solely on a password. By combining factors—something you know (password), have (smartphone), or are (biometrics)—MFA significantly reduces the risk of unauthorized access. [Online]. Available: https://trusted-digital-identity.europa.eu/eu-login-help/what-multi-factor-authentication-or-2fa_en [Accessed: Nov. 26, 2025].

[4] Secure Elements (SE) and Trusted Execution Environments (TEE), are foundational technologies for establishing a root of trust and protecting sensitive data in modern connected devices. “Hardware Security: Understanding the Differences Between a Secure Element, TPM, HSM, and a TEE”, June, 13th 2025. [Online]. Available: https://tropicsquare.com/blogs/hardware-security-understanding-the-differences-between-a-secure-element-tpm-hsm-and-a-tee. [Accessed: Jan. 10, 2026].

[5] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance), OJ L 119, 4.5.2016, pp. 1–88. [Online]. Available: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng. [Accessed: Nov. 14, 2025].

[6] S. Pabst “EU Digital Identity Wallet Pilots Roll Out Under the Radar”, October, 6th 2023. [Online]. Available: https://brownstone.org/articles/eu-digital-identity-wallet-pilots-roll-out-under-the-radar/?_gl=1*u4jcp6*_gcl_au*MTgxMzY3MDQwMS4xNzc0MTgwNjI4*_ga*MjEzMjc4NDc3My4xNzc0MTgwNjI4*_ga_P6T1TNYZ37*czE3NzQxOTEyNTEkbzIkZzAkdDE3NzQxOTEyNTEkajYwJGwwJGgw[Accessed March 3, 2026].

[7] A. Tomanová “EU chystávlastnídigitálnípeněženku do mobilu! Kdydorazí a co všemánabídnout?”, 23.08.2025. [Online]. Available: https://www.letemsvetemapplem.eu/2025/08/23/eu-chysta-vlastni-digitalni-penezenku-do-mobilu-kdy-dorazi-a-co-vse-ma-nabidnout/. [Accessed Jan. 12, 2026].

[8] “Commission Implementing Regulation (EU) 2024/2979 — integrity and core functionalities of European Digital Identity Wallets”. EUR-Lex. European Commission. 4 December 2024. [Online]. Available: https://eur-lex.europa.eu/eli/reg_impl/2024/2979/oj/eng[Accessed: Dec. 21, 2025].

[9] A. Kwiatkowska “Europe 2025: How Organisations Can Protect Data and Identity at Scale”, 31 October 2025. [Online]. Available: https://www.keepersecurity.com/blog/2025/10/31/how-organisations-can-protect-data-and-identity-at-scale/ [Accessed Feb. 16, 2026].

[10] What is a level of assurance? eIDAS Levels of Assurance. [Online]. Available: https://ec.europa.eu/digital-building-blocks/sites/spaces/DIGITAL/pages/467110081/eIDAS+Levels+of+Assurance.[Accessed: Feb. 13, 2026].

[11] EUDI Wallet: what are the mechanisms and guarantees of the trust model? 26 February 2025. [Online]. Available: https://www.idakto.com/blog/eudi-wallet-what-are-the-mechanisms-and-guarantees-of-the-trust-model/. [Accessed: Dec. 20, 2025].

[12] N. Tsakalakis, “Analysing the impact of the GDPR on eIDAS: Supporting effective Data Protection by Design for cross-border electronic identification through unlinkability measures”, Thesis for the degree of Doctor of Philosophy, University of Southampton. 2020. [Online]. Available: https://eprints.soton.ac.uk/447268/1/N_Tsakalakis_PHD_WAIS_201120.pdf . [Accessed: Jan. 26, 2026].

[13] Digital death refers to the management, legacy, and transformation of a person's digital footprint—social media, cloud storage, emails, and assets—after they pass away. It covers legal, ethical, and personal issues regarding who owns, controls, or deletes this data, alongside the rise of digital, AI-generated memorialization and immortality. See also S. Pitsillides, M. Waller and D. Fairfax, “Digital Death: What Role Does Digital Information Play in the Way We are (Re)Membered?”, In book: Digital Identity and Social Media, pp.75-90. July 2012. [Online]. Available: https://www.researchgate.net/publication/291811561_Digital_Death_What_Role_Does_Digital_Information_Play_in_the_Way_We_are_ReMembered [Accessed Jan. 12, 2026]. DOI: 10.4018/978-1-4666-1915-9.ch006.

[14] Personally Identifiable Data (PID or Personal Identifiable Information - PII) is any data that can distinguish, trace, or locate an individual’s identity, such as names, Social Security numbers, biometric records, or combinations of data like date of birth and address. It is used to verify identity and is heavily protected by privacy laws to prevent fraud.[Online]. Available: https://www.ibm.com/think/topics/pii. [Accessed: Jan. 16, 2026].

[15] An Electronic Attestation of Attributes (EAA) is a type of digital document that confirms the accuracy of a specific attribute, such as a place of residence or professional qualification. Unlike the attribute itself, which is merely a data point, the EAA serves as an official, machine-readable document. It is issued by an authorized provider, guaranteeing authenticity and carrying the same legal value as its paper-based equivalent. An EAA can be added, stored and presented with the EU Digital Identity Wallet. [Online]. Available: https://www.digital-identity-wallet.eu/news/what-are-the-3-types-of-electronic-attestations-of-attributes-eaa/ [Accessed: Jan. 16, 2026].

[16] WSCD a highly secure, tamper-resistant hardware component designed to store, manage, and protect sensitive cryptographic assets like private keys, credentials, and biometric templates, specifically for digital ID wallets. See also “Is WSCD and WSCA described in European Digital Identity Wallet (EUDIW) ARF equivalent to SSCD?”. [Online]. Available: https://www.methics.fi/is-wscd-and-wsca-equivalent-to-sscd/. [Accessed: Feb. 22, 2026].

[17] Architecture and Reference Framework (ARF) is a a set of common standards and technical specifications and a set of common guidelines and best practices. IT is a the main narrative text that describes the European Digital Identity Wallet and its ecosystem. See also “Version 2.0 of the Architecture and Reference Framework now available”, 29th May 2025. [Online]. Available: https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/900014854/Version+2.0+of+the+Architecture+and+Reference+Framework+now+available . [Accessed: Nov.20, 2025].

[18] ISO 18013-5:2021 is the international standard for mobile driver’s licenses (mDLs), defining secure, interoperable technology for storing and presenting driver’s licenses on mobile devices. It enables contactless verification via NFC, QR codes, or Bluetooth, ensuring high-level security, data integrity, and privacy-preserving,, user-controlled sharing. [Online]. Available: https://www.iso.org/standard/69084.html. [Accessed: Dec. 12, 2025].

[19] Qualified electronic signature (QES) is the most secure, legally binding electronic signature under EU eIDAS regulation, equivalent to a handwritten signature. It requires strict identity verification, a qualified certificate, and a secure signature creation device (QSCD). [Online]. Available: https://commission.europa.eu/system/files/2023-03/Instructions%20for%20QES%20signature%20of%20documents.pdf. [Accessed: Dec. 18, 2025].

[20] OpenID4VP is a protocol that extends the OpenID Connect standard, enabling users to securely present cryptographically verifiable credentials to prove their digital identity online without relying on passwords or traditional forms of authentication. [Online]. Available: https://www.corbado.com/glossary/open-id-4-vp. [Accessed: Jan. 17, 2026].

[21] G.Belova and G. Georgieva Fake News as a Threat to National Security, International conference KNOWLEDGE-BASED ORGANIZATION, Vol. 24, Issue 1, pp. 19-22, June 2018. [Online]. Available: https://www.researchgate.net/publication/326653453_Fake_News_as_a_Threat_to_National_Security .[Accessed March 3, 2026].DOI:10.1515/kbo-2018-0002.

[22] T. Marinova and B. Popov Bulgaria Moves to Introduce European Digital Identity Wallet, Bill set for Public Consultation, BTA, 21.02.2026, [Online]. Available: BTA: Bulgaria Moves to Introduce European Digital Identity Wallet, Bill Set for Public Consultation Accessed: March 8, 2026].

[23] EUDI Wallet – NiScy – Comprehensive Use Cases and User Research Report DLV-03-02.01-08. [Online]. Available: What do Europeans want out of their EUDI Wallets New study sheds light - EU Digital Identity Wallet -. Accessed: March 8, 2026.

[24] A. Lozenska-Todorova, “Introduction of Digital Wallets in Bulgaria and the EU”, International Politics, vol 2, 2024, pp. 91-115. А. Лозенска-Тодорова „Въвежданенацифровпортфейл в България и ЕС“, сп. „Международнаполитика“, бр.2, 2024, с. 91-115. [Online]. Available: http://ip.swu.bg/mod/data/view.php?d=1&advanced=1&filter=1&paging&page=1. [Accessed Feb. 23, 2026].

Downloads

Published

17.09.2026

How to Cite

[1]
A. Yankov, “ASSESSMENT OF EU DIGITAL IDENTITY WALLET FROM SECURITY PERSPECTIVE”, SysTechDev, vol. 1, pp. 241–245, Sep. 2026, doi: 10.68302/std2026.vol1.39.