The European Digital Identity Wallet is an electronic identification means that lets users store, manage, validate, and present person identification data and electronic attestations of attributes to relying parties, and sign or seal through qualified electronic signatures or seals. A relying party is the person or organization relying on electronic identification, a wallet, another eID means, or a trust service.
Article 5b requires a wallet relying party to register in the Member State where it is established when it intends to rely on wallets for public or private services by digital interaction. The registration information includes the intended use of wallets and the data the relying party intends to request from users.
The harmonised registration process in Commission Implementing Regulation (EU) 2025/848, as amended by Commission Implementing Regulation (EU) 2026/1730, applies from 24 December 2026. Until then, teams should treat Article 5b as the controlling duty but verify whether the relevant Member State has opened its register and issued national procedures. The ARF describes the operational model in which wallet units compare requested attributes with registration information and warn the user about requests outside that scope.
The Commission describes the wallet rollout as an end-of-2026 milestone, but that does not make acceptance mandatory for every private service. Article 5f ties private-sector acceptance to Union, national, or contractual strong-authentication requirements, excludes microenterprises and small enterprises, and applies only when the user voluntarily requests wallet use.
Can an EUDI Wallet relying party request any attribute it wants from a user?
No. The relying party should align wallet requests with its registered intended use and registered attributes. The ARF describes wallet checks that compare requested attributes with the relying party registration and inform the user if a request goes beyond what was registered.
What evidence should a wallet relying party keep under eIDAS?
Keep the relying-party registration, intended use, requested attribute list, user-facing request text, privacy-policy URL, user approval record where appropriate, and logs showing whether the wallet request matched the registered attributes. Under the harmonised rules applying from 24 December 2026, also keep the access certificate and automatically issued registration certificate evidence.
Must every private online service accept the EUDI Wallet?
No. Article 5f applies the private-sector acceptance duty where Union or national law or a contract requires strong user authentication for online identification. It excludes microenterprises and small enterprises and makes wallet acceptance conditional on the user's voluntary request. A service should document the legal or contractual trigger instead of relying on the end-of-2026 wallet rollout date alone.