Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ITRE-PR-732707 → A-9-2023-0038
- From
- ITRE-PR-732707 report parliamentary committee draft of 31 May 2022
- To
- A-9-2023-0038 Plenary report of 3 Mar 2023
- Changes
- Not comparable
- Paragraphs
- +625 added · −254 removed · 4 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 1 of 15: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
7 unchanged paragraphs
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
(COM(2021)0281 – C90200/2021 – 2021/0136(COD))
(Ordinary legislative procedure: first reading)
The European Parliament,
– having regard to the Commission proposal to Parliament and the Council (COM(2021)0281),
– having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90200/2021),
– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,
Removed– having regard to the reasoned opinions submitted, within the framework of Protocol No 2 on the application of the principles of subsidiarity and proportionality, by the Czech Senate, the Spanish Parliament, the Netherlands Senate and the Portuguese Parliament, asserting that the draft legislative act does not comply with the principle of subsidiarity,
4 unchanged paragraphs
– having regard to the opinion of the European Economic and Social Committee of 20 October 2021,
– having regard to the opinion of the Committee of the Regions of 13 October 2021,
– having regard to Rule 59 of its Rules of Procedure,
– having regard to the opinions of the Committee on the Internal Market and Consumer Protection, the Committee on Legal Affairs and the Committee on Civil Liberties, Justice and Home Affairs,
Changed– having regard to the report of the Committee on Industry, Research and Energy (A90000/2022),(A9-0038/2023),
1. Adopts its position at first reading hereinafter set out;
2. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.
Change 1
RemovedRecital 3 a (new): (3a) The Commission Declaration of 26 January 2022 entitled “European Declaration on Digital rights and Principles for the Digital Decade”1a highlights that everyone should have access to digital technologies, products and services that are safe, secure, and privacy-protective by design and undertakes to protecting the interests of people, businesses and public institutions against cybercrime, data breaches and cyberattacks, including protecting digital identity from identity theft or manipulation. / 1a COM(2022)0028.
AddedAMENDMENTS BY THE EUROPEAN PARLIAMENT*
RemovedRecital 3 b (new): (3b) All Union citizens have the inalienable right to a digital identity that is under their sole control and that enables them to exercise their rights as citizens in the digital environment and to participate in the digital economy. A European digital identity should be legally recognised throughout in the Union.
Addedto the Commission proposal
RemovedRecital 3 c (new): (3c) In the context of this Regulation, natural and legal persons can have a digital identity. The implementing technologies and standards developed in the application of this Regulation could be extended to establish digital identities for connected objects in order to develop a trust layer for the development of Internet of Things.
Added---------------------------------------------------------
RemovedRecital 4: (4) A more harmonised approach to digital identification should reduce the risks and costs of the current fragmentation due to the use of divergent national solutions and will strengthen the Single Market by allowing citizens, other residents as defined by national law and businesses to identify and to authenticate online and offline in a convenient and uniform way across the Union. Everyone should be able to securely access public and private services relying on an improved ecosystem for trust services and on verified proofs of identity and attestations of attributes, such as a university degree legally recognised and accepted everywhere in the Union. The framework for a European Digital Identity aims to complement national digital identity solutions by building a true internal market for the cross-border provision of electronic attestations of attributes that are legally recognised and accepted throughout in the Union. Providers of electronic attestations of attributes should benefit from a clear and uniform set of rules and public administrations should be able to rely on electronic documents in a given format.
Added2021/0136 (COD)
RemovedRecital 5: (5) To support the competitiveness of European businesses, online service providers should be able to rely on digital identity solutions recognised across the Union, irrespective of the Member State in which they have been issued, thus benefiting from a harmonised European approach to trust, security and interoperability. Users and service providers alike should be able to benefit from the same legal value provided to electronic attestations of attributes across the Union. Harmonised digital identity framework has the potential to significantly reduce operational costs linked to identification procedures, for example during the on-boarding of new customers, and to reduce expenditures or damages related to cybercrimes, such as data theft and online fraud, to support innovation and competitiveness, and to promote digital transformation of the Union’s small and medium sized enterprises (SMEs).
AddedProposal for a
RemovedRecital 5 a (new): (5a) A fully harmonised digital identity framework can enable economic value creation for individuals and businesses by fostering increased inclusion, which provides greater access to goods and services, by increasing formalisation, which helps reduce fraud, protects rights, and increases transparency, by reducing operational costs, which supports innovation and competitiveness, and by promoting digitisation, which drives efficiencies and ease of use.
AddedREGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL
RemovedRecital 5 b (new): (5b) In order to encourage digitalisation of the Member States’ public sector services and to ensure wide up-take of the European digital identity framework and the European Digital Identity Wallets, this Regulation should support the use of the ‘once only’ principle in order to reduce administrative burden, to support cross-border mobility of citizens and businesses, and to foster development of interoperable e-government services across the Union. The cross-border application of the ‘once only’ principle should result in citizens and businesses not having to supply the same data to public authorities more than once, and that it should also be possible to use those data at the request of the user for the purposes of completing cross-border online procedures.
Addedamending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
RemovedRecital 6: (6) Regulation (EU) No 2016/67919 applies to the processing of personal data in the implementation of this Regulation. Therefore, this Regulation should complement Regulation (EU) No 2016/679 by laying down specific safeguards to prevent providers of electronic identification means and electronic attestation of attributes from combining personal data from other services with the personal data relating to the services falling within the scope of this Regulation and to eliminate or reduce to the minimum citizens' digital footprint when using the internet by using the European Digital Identity Wallet. Specific rules of this Regulation should not be regarded as lex specialis to the Regulation (EU) 2016/679.
AddedTHE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,
RemovedRecital 6 a (new): (6a) The European Digital Identity Wallet should have the function of transaction history embedded into the design. Such a function should allow the user to track all transactions executed through the wallet, with at least the following data: the time and date of the transaction, the counterpart identification, the data requested and the data shared. That information should be stored even if the transaction was not concluded. The information contained in the transaction history should be non-repudiable for any legal purpose. Such a function should be active by default.
AddedHaving regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,
RemovedRecital 6 b (new): (6b) Zero Knowledge Proof (ZKP) allows verification of a claim without revealing the data that proves it, based on cryptographic algorithms. The European Digital Identity Wallet should allow for verification of claims inferred from personal data identification or attestation of attributes without having to provide the source data, to preserve the privacy of the user of the European Digital Identity Wallet, while presenting a proof with legal effect. Such approach would allow the holder to demonstrate, for example, that he or she is an adult or where he or she is located if that information is needed to access a certain service. In addition, ZKP could help fight against bots and disinformation attacks, as platforms could verify that an action on their platform (content, vote, comment, etc.) is executed by a real person located in the Union, while preserving the right to anonymity.
AddedHaving regard to the proposal from the European Commission,
RemovedRecital 7: (7) It is necessary to set out the harmonised conditions for the establishment of a framework for European Digital Identity Wallets to be issued by Member States, which should empower all Union citizens and other residents as defined by national law to share securely data related to their identity under the sole control of the user and to receive securely the data in a user-friendly way. Technologies used to achieve those objectives should be developed aiming towards the highest level of security, user convenience and wide usability. Member States should ensure equal access to digital identification to all their nationals and residents.
AddedAfter transmission of the draft legislative act to the national parliaments,
RemovedRecital 7 a (new): (7a) The Commission should, when adopting implementing acts, take due account of the open standards and standards and technical specifications drawn up by European and international standardisation organisations and bodies, in particular the European Committee for Standardisation (CEN), the European Telecommunications Standards Institute (ETSI), the International Organisation for Standardisation (ISO) and the International Telecommunication Union (ITU), as well as of the security standards referred to in Article 32 of Regulation (EU) 2016/679 and Article 22 of Regulation (EU) 2018/1725.
AddedHaving regard to the opinion of the European Economic and Social Committee1,
RemovedRecital 7 b (new): (7b) In order to help bridge the digital divide and in order to promote social inclusion, civic participation, access to education and the labour market, Member States should ensure equal access to electronic identification means to all their nationals and residents, including vulnerable persons, such as persons with disabilities, older people, socioeconomically disadvantaged groups and individuals, refugees and persons with limited access to the internet infrastructure and the digital skills.
AddedActing in accordance with the ordinary legislative procedure,
RemovedRecital 9: (9) All European Digital Identity Wallets should allow users to electronically identify and authenticate online and offline across borders for accessing a wide range of public and private services. Without prejudice to Member States’ prerogatives as regards the identification of their nationals and residents, Wallets can also serve the institutional needs of public administrations, international organisations and the Union’s institutions, bodies, offices and agencies. Offline use would be important in many sectors, including in the health sector where services are often provided through face-to-face interaction and ePrescriptions should be able to rely on QR-codes or similar technologies to verify authenticity. Relying on the level of assurance “high”, the European Digital Identity Wallets should benefit from the potential offered by tamper-proof solutions such as secure elements and state of the art encryption, to comply with the security requirements under this Regulation. The European Digital Identity Wallets should also allow users to create and use qualified electronic signatures and seals which are accepted across the EU. To achieve simplification and cost reduction benefits to persons and businesses across the EU, including by enabling powers of representation and e-mandates, Member States should issue European Digital Identity Wallets relying on common standards and technical specifications to ensure seamless interoperability and to adequately increase the level of IT…
AddedWhereas:
RemovedRecital 11: (11) European Digital Identity Wallets should ensure the highest level of security for the personal data used for identification and authentication, irrespective of whether such data is stored locally or on cloud-based solutions, and taking into account the different levels of risk. Using biometrics to identify and authenticate should not be a precondition for using European Digital Identity Wallet, notwithstanding the requirement for strong user authentication. Biometric data used for the purpose to identify and authenticate a natural person in the context of this Regulation should not be stored in the cloud. Using biometrics is one of the identifications methods providing a high level of confidence, in particular when used in combination with other elements of authentication. Since biometrics represents a unique characteristic of a person, the use of biometrics requires organisational and security measures, commensurate to the risk that such processing may entail to the rights and freedoms of natural persons and in accordance with Regulation 2016/679. Storing information from the European Digital Identity Wallet in the cloud should be an optional feature only active after the user has given explicit consent. Where the European Digital Identity Wallet is provided on the smartphone of the user its cryptographic material should be, when available, stored in the secure elements of the device.
Added(1) The Commission Communication of 19 February 2020, entitled “Shaping Europe’s Digital Future”2 announces a revision of Regulation (EU) No 910/2014 of the European Parliament and of the Council with the aim of improving its effectiveness, extend its benefits to the private sector and promote trusted digital identities for all Europeans.
RemovedRecital 17 a (new): (17a) When accessing public and private services cross-borders, authentication and identification of a user of the Wallet should be possible. The receiving Member States should be able to unequivocally identify the user upon their request in those cases where identification of the user is required by law. In order to ensure high-level of trust and security of personal data, different technical solutions should be considered, including the use or combination of various cryptographic techniques, such as cryptographically verifiable identifiers, unique user-generated digital pseudonyms, self-sovereign identities and domain specific identifiers using state of the art encryption technology.
Added(2) In its conclusions of 1-2 October 20203, the European Council called on the Commission to propose the development of a Union-wide framework for secure public electronic identification, including interoperable digital signatures, to provide people with control over their online identity and data as well as to enable access to public, private and cross-border digital services.
RemovedRecital 19: (19) This Regulation should not cover aspects related to the conclusion and validity of contracts or other legal obligations where there are requirements as regards to forms laid down by national or Union law.
Added(2a) The Digital Decade Policy Programme 2030 sets the objective and digital target of a Union framework which, by 2030, leads to wide deployment of a trusted, voluntary, user-controlled digital identity, that will be recognised throughout the Union and allow each user to control their data and presence in online interactions.
RemovedRecital 21 a (new): (21a) This Regulation seeks to facilitate creation, choice and switching between different European Digital Identity Wallets. In order to avoid lock-in effects, the issuers of the European Digital Identity Wallets should at the request of the user of the Wallet, provide for effective portability of data, including provisions of continuous and real-time access to services, and not be allowed to use contractual, economic or technical barriers to prevent or to discourage effective switching between different European Digital Identity Wallets.
Added▌
RemovedRecital 23: (23) Due consideration should be given to ensure effective cooperation between the NIS and eIDAS authorities. In cases where the national competent authority under this Regulation is different from the competent authorities designated under Directive XXXX/XXXX [NIS2], those authorities should cooperate closely, in a timely manner by exchanging the relevant information in order to ensure effective supervision and compliance of trust service providers with the requirements set out in this Regulation and Directive XXXX/XXXX [NIS2]. In particular, the national competent authorities under this Regulation should be entitled to request the competent authority under Directive XXXXX/XXXX [NIS2] to provide the relevant information needed to grant the qualified status and to carry out supervisory actions to verify compliance of the trust service providers with the relevant requirements under NIS 2 or require them to remedy non-compliance.
Added(3a) The Commission Declaration of 26 January 2022 entitled "European Declaration on Digital Rights and Principles for the Digital Decade" underlines every citizen’s right to access digital technologies, products and services that are safe, secure, and privacy-protective by design. This includes ensuring that all people living in the Union are offered an accessible, secure and trusted digital identity that enables access to a broad range of online and offline services, protected against all cyberthreats, including identity theft or manipulation. The Commission Declaration also states that everyone has the right to the protection of their personal data online. That right encompasses the control on how the data is used and with whom it is shared.
RemovedRecital 28: (28) Wide availability and usability of the European Digital Identity Wallets require their acceptance by private service providers. Private relying parties providing services in the areas of transport, energy, banking and financial services, social security, health, drinking water, postal services, digital infrastructure, education or telecommunications should accept the use of European Digital Identity Wallets for the provision of services where strong user authentication for online identification is required by national or Union law or by contractual obligation. The information requested from the user via the European Digital Identity Wallet should be necessary and proportionate for the intended use case of the relying party and follow the principle of data minimisation. Where very large online platforms as defined in Article 25.1. of Regulation [reference DSA Regulation] require users to identify or to authenticate to access online services, those platforms should be mandated to accept the use of European Digital Identity Wallets upon voluntary request of the user. Users should be under no obligation to use the wallet to access private services, but if they wish to do so, large online platforms should accept the European Digital Identity Wallet for this purpose while respecting the principle of data minimisation. Given the importance of very large online platforms, due to their reach, in particular as expressed in number of recipients of the service and economic transacti…
Added(3b) Union citizens should have the right to a digital identity that is under their sole control and that enables them to exercise their rights as citizens in the digital environment and to participate in the digital economy. A European digital identity should be legally recognised throughout the Union.
RemovedRecital 29: (29) The design of the European Digital Identity Wallet should technically enable the selective disclosure of attributes to relying parties. Privacy by design should become a standard design feature of the European Digital Identity Wallet, thereby reinforcing user control, convenience and personal data protection including minimisation of processing of personal data. In general, insofar as personal data are concerned, the processing of such data should rely upon the grounds for processing provided in Article 5(1), point (c), of Regulation (EU) 2016/679.
Added(4) A more harmonised approach to digital identification should reduce the risks and costs of the current fragmentation due to the use of divergent national solutions or, in some Member States, the absence of solutions, and will strengthen the Single Market by allowing citizens, other residents as defined by national law and legal entities to identify and authenticate online and offline in a safe, trustworthy, user friendly, convenient, accessible and harmonised way, across the Union. Everyone should be able to securely access public and private services relying on an improved ecosystem for trust services and on verified proofs of identity and electronic attestations of attributes, such as academic qualifications, university degrees or other educational or professional attainments legally recognised and accepted everywhere in the Union, or a license or a mandate to represent a company, while creating a uniform set of rules for providers of electronic attestations that ensures a level playing field. The framework for a European Digital Identity aims to achieve a shift from the reliance on national digital identity solutions only, to the provision of electronic attestations of attributes valid and legally recognised across the Union. Providers of electronic attestations of attributes should benefit from a clear and uniform set of rules and public administrations should be able to rely on electronic documents that are highly secured and accepted across the Union. With regard to electronic identification for public services with very high security identification requirements, it should be possible for Member States to enable notaries and other professionals entrusted with special powers in the public interest to rely on additional remote identity controls, set out in accordance with the principle of proportionality through national legislation.
RemovedRecital 30 a (new): (30a) Authentic sources that are users of a European Digital Identity Wallets should be able to issue non-qualified electronic attestation of attributes directly using the European Digital Identity Wallets. Alternatively, they should be able to use any trust service provider compliant with the technical specifications and standards of the European Digital Identity Wallets framework to issue electronic attestation of attributes on their behalf. Non-qualified attestations of attributes do not receive the same assumption of high level of assurance as the qualified electronic attestation of attributes, but they nevertheless provide the potential for many use cases (e.g. fidelity credentials, club membership credentials, coupon credentials, etc.) providing for the necessary flexibility and anticipating future evolution of the framework, including increasing the overall usability of the framework for the users of the European Digital Identity Wallets.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 26 September 2026
Cite as
European Parliament (2023). “Changes between ITRE-PR-732707 and A-9-2023-0038”. Text, 3 March 2023. from ITRE-PR-732707, to A-9-2023-0038. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-03-03,
author = {{European Parliament}},
title = {{Changes between ITRE-PR-732707 and A-9-2023-0038}},
year = {2023},
date = {2023-03-03},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1},
urldate = {2026-09-26},
publisher = {EU Parl Watch Research},
note = {Text. from ITRE-PR-732707, to A-9-2023-0038. Data: European Parliament Open Data (CC BY 4.0)}
}