Politics Business Culture Technology Environment Travel World
Home Technology Feature
Technology · Exclusive

EU digital ID wallet: privacy promise meets unfinished tech

EU digital ID wallet: privacy promise meets unfinished tech
Technology · 2026
Photo · Kai Lindgren for European Pulse
By Kai Lindgren Technology Editor Sep 17, 2026 5 min read

By the end of 2026, every EU member state is legally required to offer citizens a European Digital Identity Wallet—a smartphone app designed to hold government IDs, driving licences, diplomas, and other verified documents in one place, usable across all 27 countries. But as the deadline approaches, digital rights groups warn that the technology and its safeguards are far from ready, and that a system meant to protect privacy could instead become a powerful surveillance tool.

A fragile foundation

Thomas Lohninger, executive director of the Austrian digital rights group epicenter.works and a board member of European Digital Rights (EDRi), estimates that only 50-60% of the technical standards needed to build the wallet exist. "The other 40% are not there yet. They do not exist," he says. This gap is particularly concerning given the wallet's role as "critical infrastructure" connecting public and private services "like we've never done in Europe."

The centralisation of identity, health data, driving licences, and financial credentials on a single device creates what Lohninger calls a "honeypot" problem. A single security failure—a stolen phone, a malicious app, or a cloud breach—could expose everything at once. Unlike a leaked password, a compromised credential carries a cryptographic signature of authenticity, making misuse far more damaging. "If you put all your eggs in one basket, then that basket hopefully never fails," he says. "Imagine if this little wallet gets hacked or has downtime of just a few hours or a week. People would be locked out of their social media. They couldn't use public transport. Their driver licence would no longer be with them."

The regulation mandates technical defences: tamper-resistant cryptographic hardware for keys, credentials bound to a specific device, authentication for any organisation requesting data, and a 24-hour notification rule for revoked credentials. The European Data Protection Supervisor points to secure hardware elements as a key safeguard. But losing a phone still means a race to freeze and recover the wallet before a criminal exploits it, and EU auditors note that recovery procedures remain only partly tested.

The privacy paradox

The wallet's core privacy pledge is selective disclosure: someone proving they are over 18 should be able to share only that fact, not their name, address, or ID number. The EDPS calls this "authorisation without identification," a defence against tracking that a physical ID card cannot offer. But Lohninger warns of "over-identification." Verifying identity online is currently slow and costly; banks and mobile carriers pay to do it under anti-money-laundering rules. The wallet could make identification fast, cheap, and widely available, creating an incentive to strip away the anonymity that currently exists on social networks or email sign-ups.

EDRi also raises the "panopticon" risk. The same wallet could be used for taxes, healthcare, public transport, banking, and logging into Facebook, linking previously separate areas of life through one system. "These areas of life could become connected," Lohninger says. "There's this big risk of a panopticon where you can really see everything from everyone." EDRi has pushed for a legal principle called unobservability, intended to stop wallet providers, governments, or even Google from seeing what users do inside the system. Draft implementing rules, EDRi argues, currently weaken this safeguard while pushing mandatory biometric facial checks not foreseen in the original law.

Unfinished cryptography

Much of the technology meant to make the wallet both secure and private does not exist yet. Zero-knowledge proofs—cryptographic techniques that let someone prove a fact, such as being over 18, without revealing the underlying data—are "the frontier of cryptographic science," Lohninger says. "There is a triangle between privacy, security, and usability. It's very hard to get all three to 100%. The wallet certainly will cut some corners here."

The question is which corner gets cut first. A credential system can be cryptographically secure, with strong keys and valid signatures, yet still leak information about a person's behaviour if the same identifier or attribute is reused across services, letting verifiers link separate transactions to the same individual even without a name attached.

Cross-border weak link

Because the wallet relies on mutual recognition, a bank or government office in one country must trust identity checks carried out under another country's enrolment, certification, and security standards. Lohninger does not expect most national systems to be equally robust by the deadline. "Even countries that spend a lot of money on this, like France and Germany, are not ready," he says. "They will not make it completely to the finish line." That unevenness is itself a security risk: a system built for 27 mutually trusting implementations is only as strong as its weakest national deployment, slowest incident response, and least rigorous enrolment process.

Lohninger's advice is caution for now. "Let's wait and not be early adopters here. I want an audit, an independent academic and civil-society investigation into what the governments bring us before we jump on these systems."

Why the stakes are rising

The security debate is intensifying as governments across Europe, including France, Denmark, Greece, and Austria, push new age-verification laws for social media, with an EU-wide announcement expected soon from Commission President Ursula von der Leyen. The wallet is being positioned as the enforcement tool, pairing a high-value identity system with, as Lohninger puts it, "the most dubious companies that we interact with on a daily basis."

As the rollout lags—24 of 27 states have missed the initial deadline—the gap between ambition and reality becomes clearer. The EU's proposed digital pass for cross-border work recognition shows the direction of travel, but the underlying infrastructure remains a work in progress. For now, the wallet's fate hinges on whether the cryptographic and legal safeguards can catch up with the political timetable, and whether Europeans will trust a system that promises privacy but has yet to prove it.

More from this story

Next article · Don't miss

Gaza's bicycle couriers endure danger and meagre pay to keep deliveries moving

Between 40 and 50 couriers at one Gaza delivery firm have been killed in the war, yet hundreds still ride. With 74% of roads destroyed and fuel scarce, bicycles are the only way to move goods—and repairs can eat nearly all of a day's pay.

Read the story →
Gaza's bicycle couriers endure danger and meagre pay to keep deliveries moving