Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0038 → TA-9-2024-0117

From
A-9-2023-0038 Plenary report of 3 Mar 2023
To
TA-9-2024-0117 Adopted text of 29 Feb 2024
Changes
Not comparable
Paragraphs
+19 added · −631 removed · 0 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
Title (to)
European Digital Identity Framework

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 7 of 12: Paragraphs 361–420

Removed(20) Articles 17, 18 and 19 are deleted.

Removed▌

Removed(22) Article 20 is amended as follows:

Removed(a) paragraph 1 is replaced by the following

Removed‘1. Qualified trust service providers shall be audited at their own expense at least every 24 months by a conformity assessment body. The audit shall confirm that the qualified trust service providers and the qualified trust services provided by them fulfil the requirements laid down in this Regulation and in Article 18 of Directive (EU) XXXX/XXXX [NIS2]. Where components of trust services have been separately certified in accordance with this regulation, the conformity assessment body responsible for certifying the trust service shall not conduct additional audits of these components. Instead, conformity assessment bodies shall ensure that the interactions between the various components do not impede the trust service's compliance with the requirements laid down in this paragraph. Qualified trust service providers shall submit the resulting conformity assessment report to the supervisory body within three working days of receipt.’;

Removed(b) in paragraph 2, the last sentence is replaced by the following

Removed‘Without prejudice to any further obligations on data controllers or processors arising from Regulation (EU) 2016/679, where there is any reason to believe that data protection rules could have been breached, the supervisory body shall inform the supervisory authorities under Regulation (EU) 2016/679, the issuer and the controller of the European Digital Identity Wallet without undue delay and shall provide the results of its audits as soon as they are available.’;

Removed(c) paragraphs 3 and 4 are replaced by the following:

Removed‘3. Where the qualified trust service provider fails to fulfil any of the requirements set out by this Regulation, the supervisory body shall require it to provide a remedy within a set time limit, if applicable.

Removedwhere that provider does not provide a remedy and, where applicable within the time limit set by the supervisory body, the supervisory body, taking into account in particular, the extent, duration and consequences of that failure, shall withdraw the qualified status of that provider or of the service concerned which it provides and, request it, where applicable within a set time limit, to comply with the requirements of Directive XXXX/XXXX[NIS2]. The supervisory body shall inform the body referred to in Article 22(3) for the purposes of updating the trusted lists referred to in Article 22(1).

RemovedThe supervisory body shall inform the qualified trust service provider of the withdrawal of its qualified status or of the qualified status of the service concerned.

Removed4. By ... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish reference number for the following standards:

Removed(a) the accreditation of the conformity assessment bodies and for the conformity assessment report referred to in paragraph 1;

Removed(b) the auditing requirements for the conformity assessment bodies to carry out their conformity assessment of the qualified trust service providers as referred to in paragraph 1, carried out by the conformity assessment bodies;

Removed(c) the conformity assessment schemes for carrying out the conformity assessment of the qualified trust service providers by the conformity assessment bodies and for the provision of the conformity assessment report referred to in paragraph 1.

RemovedThose implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Removed(23) Article 21 is amended as follows:

Removed(a) paragraph 2 is replaced by the following:

Removed‘2. The supervisory body shall verify whether the trust service provider and the trust services provided by it comply with the requirements laid down in this Regulation, and in particular, with the requirements for qualified trust service providers and for the qualified trust services they provide.

RemovedIn order to verify the compliance of the trust service provider with the requirements laid down in Article 18 of Dir XXXX [NIS2], the supervisory body shall request the competent authorities referred to in Dir XXXX [NIS2] to carry out supervisory actions in that regard and to provide information about the outcome within three days from their completion.

RemovedWhere the supervisory body concludes that the trust service provider and the trust services provided by it comply with the requirements referred to in the first subparagraph, the supervisory body shall grant qualified status to the trust service provider and the trust services it provides and inform the body referred to in Article 22(3) for the purposes of updating the trusted lists referred to in Article 22(1), not later than three months after notification in accordance with paragraph 1 of this Article.

RemovedWhere the verification is not concluded within three months of notification, the supervisory body shall inform the trust service provider specifying the reasons for the delay and the period within which the verification is to be concluded.’;

Removed(b) paragraph 4 is replaced by the following:

Removed‘4. By ... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, define the formats and procedures of the notification and verification for the purposes of paragraphs 1 and 2 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Removed(23a) Article 22 is amended as follows:

Removed(a) paragraph 1 is replaced by the following:

Removed‘1. Each Member State shall establish, maintain, regularly update and publish trusted lists, including information related to the qualified trust service providers for which it is responsible, together with information related to the qualified trust services provided by them.’;

Removed(b) the following paragraph is inserted:

Removed‘3a. The Commission in coordination with Member States and where relevant ENISA shall develop a harmonised reporting mechanism for qualified trust service providers as well as other interested third parties to appeal in a transparent and duly reasoned manner the decision of a Member State in respect to inclusion and removal of a qualified trust service provider from the trust list.’;

Removed(c) the following paragraph is added:

Removed‘5a. By ... [6 months after the date of entry into force of this amending Regulation] the Commission shall, by means of implemented acts lay down further details on the process referred to in paragraph 3a of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Removed(24) in Article 23 the following paragraph 2a is added:

Removed‘2a. Paragraph 1 and 2 shall also apply to trust service providers established in third countries and to the services they provide, provided that they have been recognised in the Union in accordance with Article 14.’;

Removed(25) Article 24 is amended as follows:

Removed(a) paragraph 1 is replaced by the following:

Removed‘1. When issuing a qualified certificate or a qualified electronic attestation of attributes for a trust service, a qualified trust service provider shall verify the identity and, if applicable, any specific attributes of the natural or legal person to whom the qualified certificate or the qualified electronic attestation of attribute is issued.

RemovedThe information referred to in the first subparagraph shall be verified by the qualified trust service provider, either directly or by relying on a third party, in any of the following ways:

Removed(a) by means of a notified electronic identification means which meets the requirements set out in Article 8 with regard to the assurance level ‘high’;

Removed(b) by means of ▌ a certificate of a qualified electronic signature or of a qualified electronic seal issued in accordance with point (a), (c) or (d);

Removed(c) by using other identification methods which ensure the identification of the natural person with a high level of confidence, the conformity of which shall be confirmed by a conformity assessment body;

Removed(d) through the physical presence of the natural person or of an authorised representative of the legal person by appropriate procedures and in accordance with national laws if other means are not available.’;

Removed(b) the following paragraph ▌ is inserted:

Removed‘1a. By ... [12 months after the date of entry into force of this Regulation], the Commission shall adopt delegated acts in accordance with Article 47, supplementing this Regulation by setting out minimum technical specifications, standards and procedures with respect to the verification of identity and attributes in accordance with paragraph 1, point c of this Article.’;

Removed(c) paragraph 2 is amended as follows:

Removed(1) point (d) is replaced by the following:

Removed‘(d) before entering into a contractual relationship, inform, in a clear, comprehensive and easily accessible manner, in a publicly accessible space and individually any person seeking to use a qualified trust service of the precise terms and conditions regarding the use of that service, including any limitations on its use;’;

Removed(2) the new points (fa) and (fb) are inserted:

Removed‘(fa) have appropriate policies and take corresponding measures to manage legal, business, operational and other direct or indirect risks to the provision of the qualified trust service. Notwithstanding the provisions of Article 18 of Directive EU XXXX/XXX [NIS2], those measures shall include at least the following:

Removed(i) measures related to registration and on-boarding procedures to a service;

Removed(ii) measures related to procedural or administrative checks;

Removed(iii) measures related to the management and implementation of services.

Removed(fb) notify the supervisory body and, where applicable, other relevant bodies of any linked breaches or disruptions in the implementation of the measures referred to in paragraph (fa), points (i), (ii) and, (iii) that has a significant impact on the trust service provided or on the personal data maintained therein.’;

Removed(3) point (g) and (h) are replaced by the following:

Removed‘(g) take appropriate measures against forgery, theft or misappropriation of data or, without right, deleting, altering or rendering data inaccessible;

Removed(h) record and keep accessible for as long as necessary after the activities of the qualified trust service provider have ceased, all relevant information concerning data issued and received by the qualified trust service provider, for the purpose of providing evidence in legal proceedings and for the purpose of ensuring continuity of the service. Such recording may be done electronically;’;

Removed(4) point (j) is deleted;

Removed(d) the following paragraph 4a is inserted:

Removed‘4a. Paragraph 3 and 4 shall apply accordingly to the revocation of electronic attestations of attributes.’;

Removed(e) paragraph 5 is replaced by the following:

Removed‘5. By ... [12 months after the date of entry into force of this amending Regulation, the Commission shall, by means of implementing acts, establish reference numbers of standards for the requirements referred to in paragraph 2 of this Article. compliance with the requirements laid down in this Article shall be presumed, where trustworthy systems and products meet those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2024). “Changes between A-9-2023-0038 and TA-9-2024-0117”. Text, 29 February 2024. from A-9-2023-0038, to TA-9-2024-0117. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0038/compare/TA-9-2024-0117?all=1&part=7 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-02-29,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0038 and TA-9-2024-0117}},
  year = {2024},
  date = {2024-02-29},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0038/compare/TA-9-2024-0117?all=1&part=7}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0038/compare/TA-9-2024-0117?all=1&part=7},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0038, to TA-9-2024-0117. Data: European Parliament Open Data (CC BY 4.0)}
}