eIDAS Regulation: Electronic Identification, Trust Services, and the EUDI Wallet

Introduction

Regulation (EU) No 910/2014 — the eIDAS Regulation (electronic IDentification, Authentication and Trust Services) — establishes a harmonised legal framework for electronic identification and trust services across the European Union. The Regulation creates a predictable and cross-border interoperable environment for secure electronic transactions, enabling citizens, businesses, and public administrations to interact electronically across Member States with the same legal certainty as paper-based transactions. The 2024 amendment (the “eIDAS 2” reform) introduces the European Digital Identity (EUDI) Wallet and expands the trust services framework to address emerging technological and societal needs.

Electronic Identification

Title II of eIDAS governs electronic identification schemes. Member States may notify electronic identification schemes to the Commission, which publishes them in the Official Journal (Article 9). Once notified, an electronic identification means issued under that scheme must be recognised for cross-border authentication by public sector bodies requiring electronic identification (Article 6), provided the scheme achieves assurance level “substantial” or “high.”

Three assurance levels are defined in Commission Implementing Regulation (EU) 2015/1502: low (limited confidence in the claimed identity, relying on evidence that provides some assurance); substantial (reasonable confidence, using verification methods that provide substantial assurance); and high (higher confidence, using verification methods designed to prevent identity theft and fraud). The assurance level is determined by the enrolment process, the authentication mechanism, and the management and organisational framework.

The mutual recognition principle (Article 6) requires one Member State to recognise electronic identification means from another Member State for access to online public services, unless the requesting service requires a higher assurance level than the means provides. This obligation has driven the development of cross-border interoperability infrastructure, including the eIDAS Node — a technical gateway enabling interconnection between national electronic identification schemes.

Trust Services

Title III establishes the legal framework for trust services — electronic services that enhance trust and confidence in online transactions. The Regulation distinguishes between qualified and non-qualified trust services. Qualified trust services benefit from a presumption of legal effect and are provided by qualified trust service providers (QTSPs) who are subject to supervision by national supervisory bodies, comply with security and liability requirements, and use qualified certificates.

Electronic Signatures

Article 25 provides that an electronic signature shall not be denied legal effect or admissibility as evidence in legal proceedings solely on the grounds that it is in electronic form. Three levels of electronic signature are recognised: (a) electronic signature (basic level — data in electronic form attached to or logically associated with other data and used by the signatory to sign); (b) advanced electronic signature (AdES) , which must be uniquely linked to the signatory, capable of identifying the signatory, created using means under the signatory’s sole control, and linked to the data in a way that detects subsequent changes; (c) qualified electronic signature (QES) , an advanced electronic signature created by a qualified electronic signature creation device and based on a qualified certificate for electronic signatures (Article 3(12)). A QES has the equivalent legal effect of a handwritten signature (Article 25(2)).

Electronic Seals, Time Stamps, and e-Delivery

Electronic seals (Articles 35–40) serve for legal persons what signatures serve for natural persons — they ensure the origin and integrity of documents. A qualified electronic seal benefits from the same presumption of legal effect as a seal from a public authority. Electronic time stamps (Articles 41–42) bind date and time to data, ensuring temporal integrity. Qualified time stamps benefit from a presumption of accuracy. Electronic registered delivery services (ERDS) (Articles 43–44) provide secure transmission of electronic data between parties, with qualified services offering a legal presumption of data integrity and transmission.

Website Authentication Certificates

Title III also introduced qualified website authentication certificates (QWACs) (Article 45), which enable users to verify the identity of a website’s legal operator — the electronic equivalent of a physical business licence displayed at a physical premises. QWACs are gaining importance as the EU moves towards enhanced TLS authentication for financial and public sector websites.

Supervisory Framework

Each Member State designates a supervisory body to oversee qualified trust service providers (Article 17). The supervisory body conducts audits, investigates complaints, and may impose sanctions, including withdrawal of qualified status. The European Commission maintains a trusted list of QTSPs published through each Member State’s Trusted List — a machine-readable list of QTSPs and their services (Article 22).

EUDI Wallet — The eIDAS 2 Reform

Regulation (EU) 2024/… (the eIDAS 2 amendment), adopted in February 2024, introduces the European Digital Identity (EUDI) Wallet — a personal digital wallet enabling citizens to securely store, manage, and share identity data, attributes, and credentials from public and private sources. The EUDI Wallet is designed to be privacy-preserving: users control what data is shared, with whom, and for what purpose (Article 5a). The Wallet supports: (a) electronic identification for access to public and private services; (b) qualified electronic signatures and seals; (c) presentation of attestations of attributes (university degrees, professional licences, driving licences); (d) qualified electronic attestations of attributes (QEAA) issued by qualified providers; and (e) payment authentication.

Member States must provide free EUDI Wallets to citizens by 2026. The Wallet architecture is based on open standards, including ISO/IEC 18013-5 for mobile driving licences and W3C Verifiable Credentials. The Regulation introduces an obligation for large online platforms (designated under the Digital Services Act) to accept EUDI Wallet authentication for access to services.

Liability and Data Protection

QTSPs are liable for damage caused intentionally or negligently to any person due to non-compliance with eIDAS obligations (Article 13). The Regulation’s liability framework coexists with the GDPR — trust service providers processing personal data must comply with GDPR requirements, and the EUDI Wallet must incorporate data protection by design and default, including purpose limitation, data minimisation, and user consent.

The Revised Trust Services Framework

eIDAS 2 expands trust services to include: (a) electronic archiving services — qualified services ensuring long-term preservation of electronic data and documents; (b) electronic ledgers — blockchain-based trust services ensuring integrity and immutability of records; (c) electronic attestations of attributes — digital attestations of personal or legal characteristics (professional status, age, nationality) issued by qualified or non-qualified providers; and (d) remote qualified electronic signature creation devices — cloud-based signature solutions meeting the qualified security requirements.

International Dimension

Third-country trust services may be recognised as equivalent to EU qualified trust services where the Commission adopts an implementing decision finding the third country’s legal framework equivalent (Article 14). Equivalence decisions have been adopted for Switzerland, Ukraine, and Moldova, enabling cross-border recognition of e-signatures and e-seals for international commercial transactions.