Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0038 → TA-9-2024-0117

From
A-9-2023-0038 Plenary report of 3 Mar 2023
To
TA-9-2024-0117 Adopted text of 29 Feb 2024
Changes
Not comparable
Paragraphs
+19 added · −631 removed · 0 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
Title (to)
European Digital Identity Framework

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 5 of 12: Paragraphs 241–300

Removed(f) the technical architecture of the European Digital Identity Wallet shall prevent the issuer of ▌European Digital Identity Wallets, Member State or any other parties from collecting or obtaining electronic identification means, attributes, electronic documents contained in a European Digital Identity Wallet and information about the use of the European Digital Identity Wallet by the user, except where requested by the user using devices in the user’s control and he exchange of information via the European Digital Identity Wallet shall not allow providers of electronic attestations of attributes to track, link, correlate or otherwise obtain knowledge of transactions or user behaviour;

Removed(g) unique and persistent identifiers shall not be accessible to relying parties in cases other than when identification of the user is required by Union or national law;

Removed(h) Member States shall ensure that relevant information on the European Digital Identity Wallet is publicly available;

Removed(i) personal data relating to the provision of European Digital Identity Wallets shall be kept physically and logically separate from any other data held;

Removed(j) if the European Digital Identity Wallet is provided by private parties in accordance to paragraph 1 (b) and (c), the provisions of Article 45f(4) shall apply mutatis mutandis;

Removed(k) where attestation of attributes does not require the identification of the user, zero knowledge proof shall be performed;

Removed(l) the issuer of the European Digital Identity Wallet shall be the controller for the purposes of Regulation (EU) 2016/679 regarding the processing of personal data in the European Digital Identity Wallet;

Removed(m) the European Digital Identity Wallet shall provide a complaint mechanism to enable users to inform the supervisory body under this Regulation and the supervisory authorities established under Regulation (EU) 2016/679 directly where a relying party requests a disproportionate amount of data which is not in line with the registered intended use of that data.

Removed7a. The use of the European Digital Identity Wallet shall be voluntary. Access to public and private services, access to labour market and freedom to conduct business shall not in any way be restricted or made disadvantageous for natural or legal persons not using European Digital Identity Wallets. It shall remain possible to access public and private services by other existing identification and authentication means.

Removed▌

Removed9. Article 24(2), points (b), (d), (e), (f), (fa), (fb), (g), and (h) shall apply mutatis mutandis to Member States directly issuing and managing the European Digital Identity Wallets.

Removed10. The European Digital Identity Wallet shall be made accessible for persons with disabilities in accordance with the accessibility requirements of Annex I to Directive (EU) 2019/882 and the United Nations Convention on the Rights of Persons with Disabilities, as well as to persons with special needs, including older people and persons with limited access to digital technologies or with insufficient digital literacy.

Removed11. By … [6 months after the date of entry into force of this amending Regulation], the Commission shall ▌ reference standards for the requirements referred to in this Article by means of an implementing act on the implementation of the European Digital Identity Wallet. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Removed11a. By ... [6 months after the date of entry into force of this amending Regulation], the Commission shall adopt a delegated act in accordance with Article 47 supplementing this Regulation by establishing technical and operational specifications for the requirements referred to in this Article.

RemovedEuropean Digital Identity Wallets Relying Parties

Removed1. Where a relying party intends to rely upon European Digital Identity Wallets for the provision of public or private services it shall register in to the Member State where the relying party is established. The relying party’s registration shall include information about the data that it intends to request with regard to each different service provided, the intended use of the data requested and the reasons for the request. The relying party shall notify the Member State about any change to the information notified with undue delay.

Removed1a. Relying parties that intend to process special categories of personal data, such as health or biometric data as referred to in Article 9 of the Regulation (EU) 2016/679 shall require prior approval from the competent authorities in the Member State in which they intend to provide their services. Relying parties that are granted the approval shall ensure that processing of personal information is carried out in accordance with Article 6(1) of the Regulation (EU) 2016/679.

Removed1b. Paragraphs 1 and 1a shall be without prejudice to ex-ante approval requirements set out in Union law or national law for the provision of specific services.

Removed1c. Member States shall make the information referred to in paragraph 1 publicly available online, together with the identity of each relying party and their contact details.

Removed1d. Member States shall establish ex-post controls to verify that data requests are proportionate and commensurate with the declared intent and that the principle of data minimisation is respected.

Removed1e. The European Digital Identity Framework Board established pursuant to Article 46c or any Member State shall revoke the authorisation of relying parties in the case of illegal or fraudulent use of the European Digital Identity Wallet, or suspend such authorisation until identified irregularities have been remedied.

Removed2. Member States shall implement a common mechanism for the identification and authentication of relying parties and the verification of the notified data sets referred in Article 6a(4), points (ca) and (cb).

Removed2a. Where relying parties intend to rely upon European Digital Identity Wallets issued in accordance with this Regulation, they shall authenticate and identify themselves to the user of the European Digital Identity Wallet, before any other form of transaction can take place.

Removed3. Relying parties shall be responsible for carrying out the procedure for authenticating and validating person identification data and electronic attestation of attributes originating from European Digital Identity Wallets. Relying parties shall accept the use of pseudonyms, unless the identification of the user is required by Union or national law.

Removed3a. Intermediaries acting on behalf of relying parties are to be considered relying parties and shall not obtain data about the content of the transaction.

Removed4. By ...[6 months after the date of entry into force of this amending Regulation], the Commission shall adopt delegated acts in accordance with Article 47, supplementing this Regulation by establishing technical and operational specifications for the requirements referred to in this Article, in accordance with Article 6a(11a).

RemovedCertification of the European Digital Identity Wallets

Removed1. European Digital Identity Wallets that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to be compliant with the cybersecurity relevant requirements set out in Article 6a of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements. When relevant European cybersecurity certification schemes are available, the European Digital Identity Wallet, or parts thereof, shall be certified in accordance with such schemes.

Removed2. Compliance with the requirements set out in ▌Article 6a(3), (4) and (5) related to the personal data processing operations carried out by the issuer of the European Digital Identity Wallets shall be certified pursuant to Regulation (EU) 2016/679.

Removed2a. Where relevant European functionality and interoperability certification schemes are available, the European Digital Identity Wallet, or parts thereof, shall be certified in accordance with such schemes. Those certification schemes shall provide a presumption of conformity to the functionality and interoperability requirements set out in Article 6a. In the absence of certification schemes for functionality and interoperability, the standards referred to in Article 6a(11) shall apply.

Removed3. The conformity of European Digital Identity Wallets with the requirements laid down in Article 6a of this Regulation shall be certified by conformity assessment bodies in accordance with Article 60 of Regulation (EU) 2019/881 for cybersecurity requirements and by certification bodies in accordance with Article 43 of Regulation (EU) 2016/679 for personal data processing operations.

Removed3a. For the purposes of this Article, European Digital Identity Wallets shall not be subject to the requirements referred to in Articles 7 and 9.

Removed4. By ... [6 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of standards, technical specifications, procedures and available Union and national cybersecurity certification schemes pursuant to Regulation (EU) 2019/881 necessary for the certification of the European Digital Identity Wallets referred to in paragraphs 2a and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2) of this Regulation.

Removed5. Member States shall communicate to the Commission the names and addresses of the conformity assessment bodies and certification bodies referred to in paragraph 3. The Commission shall make that information available to all Member States.

Removed6. The Commission shall be empowered to adopt delegated acts in accordance with Article 47, supplementing this Regulation by establishing the specific criteria ▌ referred to in paragraph 3 of this Article.

RemovedPublication of a list of certified European Digital Identity Wallets

Removed1. Member States shall inform the Commission without undue delay of the European Digital Identity Wallets that have been issued pursuant to Article 6a and certified by the bodies referred to in Article 6c(3). They shall also inform the Commission, without undue delay, in the event that certification is cancelled and the reasons for such cancellation.

Removed2. On the basis of the information received, the Commission shall establish, publish and maintain an up-to-date, machine readable list of certified European Digital Identity Wallets.

Removed3. By ... [6 months after the date of entry into force of this amending Regulation], the Commission shall define formats and procedures applicable for the purposes of paragraph 1 of this Article by means of an implementing act on the implementation of the European Digital Identity Wallets as referred to in Article 6a(11). That implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Removed(8) the following heading is inserted before Article 7:

Removed‘SECTION II

RemovedELECTRONIC IDENTIFICATION SCHEMES;’;

Removed(9) the introductory sentence of Article 7 is replaced by the following:

Removed‘Pursuant to Article 9(1) Member States shall notify, by ... [12 months after the entry into force of this Regulation] at least one electronic identification scheme including at least one electronic identification means with assurance level 'high' meeting all the following conditions:’;

Removed(10) in Article 9, paragraphs 2 and 3 are replaced by the following:

Removed‘2. The Commission shall, without undue delay, publish in the Official Journal of the European Union a list of the electronic identification schemes which were notified pursuant to paragraph 1 of this Article and the basic information thereon.

Removed3. The Commission shall publish in the Official Journal of the European Union the amendments to the list referred to in paragraph 2 within one month from the date of receipt of that notification.’;

Removed(10a) in Article 10, the title is replaced by the following:

Removed"Security breach of electronic identification schemes for cross-border authentication";

Removed(11) the following Article ▌ is inserted:

Removed‘Article 10a

RemovedSecurity breach of the European Digital Identity Wallets

Removed1. Where European Digital Identity Wallets issued pursuant to Article 6a and the validation mechanisms referred to in Article 6a(5) points (a), (b) and (c) are breached or partly compromised in a manner that affects their reliability or the confidentiality, integrity or availability of user data, or the reliability of the other European Digital Identity Wallets, the issuing Member State shall, without delay, suspend the issuance and revoke the validity of the European Digital Identity Wallet and inform the affected users, the single point of contact designated pursuant to Article 46a, the relying parties, the other Member States and the Commission accordingly.

Removed1a. After notification of the security breach of the European Digital Identity Wallet, the single point of contact designated pursuant to Article 46a shall liaise with the relevant national competent authorities and, where necessary, with the European Digital Identity Framework Board established pursuant to Article 46c, the European Data Protection Board, the Commission and ENISA.

Removed2. Where the breach or compromise referred to in paragraph 1 is remedied, the issuing Member State shall re-establish the issuance and the use of the European Digital Identity Wallet and inform the national competent authorities of the other Member States, the affected users and relying parties, the single point of contact designated pursuant to Article 46a and the Commission without undue delay.

Removed3. If no attempt or insufficient progress is made to remedy the breach or compromise referred to in paragraph 1 ▌ within three months of the suspension or revocation, the Member State concerned shall withdraw the European Digital Identity Wallet concerned and inform the affected users, the single point of contact designated pursuant to Article 46a, the relying parties the other Member States and the Commission on the withdrawal accordingly. Where it is justified by the severity of the breach, the European Digital Identity Wallet concerned shall be withdrawn without delay and the relevant decision should be reasoned and communicated to the Commission.

Removed4. The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list referred to in Article 6d without undue delay.

Removed5. By ... [6 months after the date of entry into force of this amending Regulation], the Commission shall adopt a delegated act in accordance with Article 47, supplementing this Regulation by further specifying the measures referred to in paragraphs 1 and 3 of this Article. ’;

Removed(12) the following Article ▌ is inserted:

Removed‘Article 11a

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2024). “Changes between A-9-2023-0038 and TA-9-2024-0117”. Text, 29 February 2024. from A-9-2023-0038, to TA-9-2024-0117. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0038/compare/TA-9-2024-0117?all=1&part=5 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-02-29,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0038 and TA-9-2024-0117}},
  year = {2024},
  date = {2024-02-29},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0038/compare/TA-9-2024-0117?all=1&part=5}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0038/compare/TA-9-2024-0117?all=1&part=5},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0038, to TA-9-2024-0117. Data: European Parliament Open Data (CC BY 4.0)}
}