Kommisjonens gjennomføringsforordning (EU) 2026/1731 av 15. juli 2026 om endring av gjennomføringsforordning (EU) 2024/2977, (EU) 2024/2979, (EU) 2024/2980 og (EU) 2024/2982 med hensyn til gjeldende standarder og spesifikasjoner
eID digital lommebok: endringsbestemmelser om standarder og tekniske spesifikasjoner
Kommisjonsforordning publisert i EU-tidende 22.7.2026
Tidligere
- Utkast til forordning lagt fram av Kommisjonen 5.2.2026 med tilbakemeldingsfrist 5.3.2026
Bakgrunn
(fra kommisjonsforordningen)
(1) To ensure the highest level of harmonisation among Member States for the development of European Digital Identity Wallets, the technical specifications for the wallets rely on the work carried out on the basis of Commission Recommendation (EU) 2021/946 (2) and in particular the architecture and reference framework. As the architecture and reference framework has evolved significantly since Commission Implementing Regulations (EU) 2024/2977 (3), (EU) 2024/2979 (4), (EU) 2024/2980 (5), and (EU) 2024/2982 (6), those Implementing Regulations should now be amended to align them with new standards, specifications and procedures.
In accordance with the objectives of Regulation (EU) No 910/2014, a number of standards have been selected to meet these specific requirements. These standards should reflect established practices and be widely recognised within the relevant sectors. For example, as the W3C VCDM format is used as the reference format for attestations in particular in the educational sector, the European Digital Identity Wallets should also support this format when the new profiles on the W3C VCDM format are available. Where necessary, these standards should be adapted or complemented in order to ensure the security and trustworthiness of European Digital Identity Wallets, while facilitating cross-border interoperability and the effective functioning of the internal market.
(2) For any use of the wallet that requires the presentation of the wallet user’s portrait, the wallet solutions must support the functionality of selective disclosure and disclosure must be under the full control of the user. To protect the ability to decide upon disclosure, and the portrait against unintended or unauthorised request for disclosure the architectural design of the European Digital Identity Wallets should provide for warning mechanisms and logging all transactions related to the use of the portrait. To ensure that the wallet user is aware of sharing biometric data, the warnings should indicate that the request involves the sharing of biometric data and specifically require the user to confirm disclosure. Where a relying party processes the portrait for the purpose of uniquely identifying a natural person or for confirming that person’s claimed identity, Article 6 and 9 of Regulation (EU) 2016/679 of the European Parliament and of the Council (7) apply as well as all other requirements of that Regulation, including that the processing of the portrait by relying parties should be limited to what is necessary for intended use. The intended use should be communicated to the wallet user, together with the request for disclosure, in clear and intelligible language. To duly consider the sensitivity of biometric data, the wallet user should explicitly and specifically confirm the disclosure of the portrait. Silence or pre-ticked boxes should not be considered as confirmation by the wallet user. The explicit confirmation of the wallet user should be a technical safeguard and not in itself provide a legal ground for processing. As set out in paragraph 4 of Article 9 of Regulation (EU) 2016/679 Member States may maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health.
(3) To give Member States sufficient time to adapt their national procedures, the wallet user’s portrait may be part of the mandatory person identification data for the natural person only as of 11 August 2028. Where these images are sourced from existing identity documents, such as identity cards or passports, the relevant requirements laid down in Council Regulations (EU) 2025/1208 (8) or (EC) No 2252/2004 (9) respectively apply.
(4) Regulation (EU) No 910/2014 requires that wallets are capable of displaying an EU Digital Identity Wallet Trust Mark, as a verifiable, simple, and recognisable indication that a wallet has been provided in accordance with the Regulation. The use of such a Trust Mark will support the effective functioning of the internal market, guarantee fair competition and protect consumer interests. To enable the use of such a Trust Mark, the visual and technical characteristics of the Trust Mark should be established.
(5) As set out in Article 12b of Regulation (EU) No 910/2014, gatekeepers are to allow providers of European Digital Identity Wallets and issuers of notified electronic identification means effective interoperability with, and, for the purposes of interoperability, access to, the same operating system, hardware or software features. Such effective interoperability and access are to be provided free of charge and irrespective of whether those hardware or software features form part of the operating system, are available to, or are used by, that gatekeeper when providing such services. As all wallet solutions should support a common set of protocols and interfaces in order to ensure usability, security and interoperability across Member States, gatekeepers should enable the operating system, hardware or software features necessary to implement the protocols and interfaces set out in Annex XII to this Regulation. In this context, in online cross-device flows, for both the physical proximity check and data transfer between the two devices, a local communication channel as enabled by the Client To Authenticator Protocol (CTAP) specification version 2.3 (10) should be preferred by gatekeepers to using CTAP Hybrid tunnel services.
(6) To give Member States, providers of wallet-relying party registration certificates and wallet providers sufficient time to enable wallet units to authenticate and validate wallet-relying party registration certificates, this requirement should only apply as of 11 August 2028.
(7) Regulation (EU) 2016/679 and, where relevant, Directive 2002/58/EC of the European Parliament and of the Council (11) apply to all personal data processing activities under this Regulation.
(8) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council (12) and delivered its opinion on 17 April 2026 (13).
(9) The measures provided for in this Regulation are in accordance with the opinion of the committee established by Article 48 of Regulation (EU) No 910/2014,