Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ITRE-PR-732707 → A-9-2023-0038
- From
- ITRE-PR-732707 report parliamentary committee draft of 31 May 2022
- To
- A-9-2023-0038 Plenary report of 3 Mar 2023
- Changes
- Not comparable
- Paragraphs
- +625 added · −254 removed · 4 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 10 of 15: Paragraphs 541–600
Added(13) Article 12 is amended as follows:
Added(-a) the title is replaced by the following:
Added‘▌Interoperability’;
Added(a) in paragraph 3, points (c) and (d) are replaced by the following:
Added‘(c) it facilitates the implementation of data protection and security by design;
Added(d) it ensures that personal data is processed in accordance with Regulation (EU) 2016/679.’;
Added(b) in paragraph 4, point (d) is replaced by the following:
Added‘(d) a reference to a minimum set of person identification data necessary to unequivocally represent a natural or legal person available from electronic identification schemes. In general, insofar as personal data are concerned, the risks to the rights of individuals shall be assessed based on Article 25(1) of Regulation (EU) 2016/679;’;
Added(ba) paragraph 5 is deleted;
Added(c) paragraph 6 is deleted;
Added(ca) paragraph 7 is deleted;
Added(cb) paragraph 9 is replaced by the following:
Added‘9. The implementing acts referred to paragraph 8 of this Article shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;
Added(14) the following Article ▌ is inserted:
Added‘Article 12a
AddedCertification of electronic identification schemes
Added1. Conformity of notified electronic identification schemes with the requirements laid down in Articles ▌ 8 and ▌ 10 may be certified by conformity bodies designated by Member States.
Added2. The peer-review of electronic identification schemes referred to in Article46b(5), point (c) of this Regulation shall not apply to electronic identification schemes or part of such schemes certified in accordance with paragraph 1. Member States may use a certificate or a Union statement of conformity issued in accordance with a relevant European cybersecurity certification scheme established pursuant to Regulation (EU) 2019/881 to demonstrate full or partial compliance of such schemes or parts of such schemes with the requirements set out in Article 8(2) of this Regulation regarding the assurance levels of electronic identification schemes.
Added2a. The certification scheme used to demonstrate conformity pursuant to paragraph 1 shall include a two-year vulnerability assessment of the certified product and a continuous threat monitoring, unless such a certification scheme has been established pursuant to Regulation (EU) 2019/881.
Added3. Member States shall notify to the Commission with the names and addresses of the conformity assessment bodies referred to in paragraph 1. The Commission shall make that information available to all Member States.’;
Added(15) the following heading is inserted after Article 12a:
Added‘SECTION III
AddedCROSS-BORDER RELIANCE ON ELECTRONIC IDENTIFICATION MEANS’;
Added(16) the following Articles ▌are inserted:
Added‘Article 12b
AddedCross-border reliance on European Digital Identity Wallets
Added1. Where Member States require an electronic identification using an electronic identification means and authentication under national law or by administrative practice to access an online service provided by a public sector body, they shall also accept European Digital Identity Wallets issued in accordance with this Regulation for the purpose of electronic identification and authentication and shall clearly communicate such acceptance to potential users of the service.
Added2. Where private relying parties providing services are required, by Union or national ▌law, to use strong user authentication for online identification, ▌ , including in the areas of transport, energy, banking and financial services, social security, health, drinking water, postal services, digital infrastructure, telecommunications or education in particular with regard to the recognition of educational and professional qualifications, private relying parties shall also offer and accept the use of European Digital Identity Wallets and notified electronic identification means with assurance level ‘high’ issued in accordance with this Regulation for identification and authentication.
Added3. Where very large online platforms as defined in Article 25(1) Regulation (EU) 2022/2065. require users to authenticate to access online services, they shall also accept, though not exclusively, and facilitate the use of European Digital Identity Wallets issued in accordance with Article 6a strictly upon voluntary request of the user and in respect of the right to pseudonyms provided for in this Regulation. In this case, user generated pseudonyms shall be used in connection to a European Digital Identity Wallet. Very large online platforms shall clearly indicate this possibility to users of the service. The combination of person identification data and any other personal data and identifiers linked to the European Digital Identity Wallets with personal or non-personal data from any other services which are not necessary for the provision of the authentication or use of core services, is prohibited unless expressly requested by the user.
Added4. The Commission shall, in cooperation with the Member States, industry and the relevant stakeholders, including civil society, encourage and facilitate the development of self-regulatory codes of conduct at Union level (‘codes of conduct’), in order to contribute to wide availability and usability of European Digital Identity Wallets within the scope of this Regulation. These codes of conduct shall ensure acceptance of electronic identification means including European Digital Identity Wallets within the scope of this Regulation in particular by service providers relying on third party electronic identification services for user authentication. The Commission will facilitate the development of such codes of conduct in close cooperation with all relevant stakeholders and encourage service providers to complete the development of codes of conduct within 12 months of the adoption of this Regulation and effectively implement them within 18 months of the adoption of the Regulation.
Added▌
AddedMutual recognition of other electronic identification means
Added1. Where electronic identification using an electronic identification means and authentication is required under national law or by administrative practice to access an online service provided by a public sector body in a Member State, the electronic identification means, issued in another Member State shall be recognised in the first Member State for the purposes of cross-border authentication for that online service, and ensuring mutual recognition provided that the following conditions are met:
Added(a) the electronic identification means is issued under an electronic identification scheme that is included in the list referred to in Article 9;
Added(b) the assurance level of the electronic identification means corresponds to an assurance level equal to or higher than the assurance level required by the relevant public sector body to access that online service in the Member State concerned, and in any case not lower than an assurance level ‘substantial’;
Added(c) the relevant public sector body in the Member State concerned uses the assurance level ‘substantial’ or ‘high’ in relation to accessing that online service.
AddedSuch recognition shall take place no later than 6 months after the Commission publishes the list referred to in point (a) of the first subparagraph.
Added2. An electronic identification means which is issued within the scope of an electronic identification scheme included in the list referred to in Article 9 and which corresponds to the assurance level ‘low’ may be recognised by public sector bodies for the purposes of cross-border authentication for the online service provided by those bodies.’;
Added(17) In Article 13, paragraph 1 is replaced by the following:
Added‘1. Notwithstanding paragraph 2 of this Article, trust service providers shall be liable for damage caused intentionally or negligently to any natural or legal person due to a failure to comply with the obligations under this Regulation and with the cybersecurity risk management obligations under Article 18 of the Directive XXXX/XXXX [NIS2].’;
Added(18) Article 14 is replaced by the following:
Added‘Article 14
AddedInternational aspects
Added1. The Commission may adopt delegated acts, in accordance with Article 47, supplementing this Regulation by setting out the conditions under which the requirements of a third country applicable to the trust service providers established in its territory and to the trust services they provide can be considered equivalent to the requirements applicable to qualified trust service providers established in the Union and to the qualified trust services they provide.
Added2. Where the Commission has adopted a delegated act pursuant to paragraph 1 or concluded an international agreement on the mutual recognition of trust services in accordance with Article 218 of the Treaty, trust services provided by providers established in the third country concerned shall be considered equivalent to qualified trust services provided by qualified trust service providers established in the Union.’;
Added(19) Article 15 is replaced by the following:
Added‘Article 15
AddedAccessibility to persons with disabilities and special needs
AddedThe provision of trust services and end-user products used in the provision of those services shall be made available in plain and intelligible language and accessible for persons with disabilities or to persons who experience functional limitations, such as older people, and persons with limited access to digital technologies, in accordance with the accessibility requirements of Annex I of Directive (EU) 2019/882 on the accessibility requirements for products and services and the United Nations Convention on the Rights of Persons with Disabilities.’;
Added(19a) Article 16 is replaced by the following:
Added"Article 16
AddedPenalties
Added1. Without prejudice to Article 31 of the Directive (EU) XXXX/XXXX [NIS2], Member States shall lay down the rules on penalties applicable to infringements of this Regulation. The penalties provided for shall be effective, proportionate and dissuasive, in particular where the infringing party is an SME.
Added2. Member States shall ensure that infringements by qualified trust service providers of the obligations laid down in this Regulation be subject to administrative fines of a maximum of at least EUR 10 000 000 or 2 % of the total worldwide annual turnover of the undertaking to which the qualified trust service provider belonged in the preceding financial year, whichever is higher.
Added3. Member States shall ensure that infringement by non-qualified trust service providers of the obligations laid down in this Regulation be subject to administrative fines of a maximum of at least EUR 7 000 000 or 1,4 % of the total worldwide annual turnover of the undertaking to which the non-qualified trust service provider belongs in the preceding financial year, whichever is higher.";
Added(20) Articles 17, 18 and 19 are deleted.
Added▌
Added(22) Article 20 is amended as follows:
Added(a) paragraph 1 is replaced by the following
Added‘1. Qualified trust service providers shall be audited at their own expense at least every 24 months by a conformity assessment body. The audit shall confirm that the qualified trust service providers and the qualified trust services provided by them fulfil the requirements laid down in this Regulation and in Article 18 of Directive (EU) XXXX/XXXX [NIS2]. Where components of trust services have been separately certified in accordance with this regulation, the conformity assessment body responsible for certifying the trust service shall not conduct additional audits of these components. Instead, conformity assessment bodies shall ensure that the interactions between the various components do not impede the trust service's compliance with the requirements laid down in this paragraph. Qualified trust service providers shall submit the resulting conformity assessment report to the supervisory body within three working days of receipt.’;
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=10
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 30 September 2026
Cite as
European Parliament (2023). “Changes between ITRE-PR-732707 and A-9-2023-0038”. Text, 3 March 2023. from ITRE-PR-732707, to A-9-2023-0038. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=10 (retrieved 30 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-03-03,
author = {{European Parliament}},
title = {{Changes between ITRE-PR-732707 and A-9-2023-0038}},
year = {2023},
date = {2023-03-03},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=10}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=10},
urldate = {2026-09-30},
publisher = {EU Parl Watch Research},
note = {Text. from ITRE-PR-732707, to A-9-2023-0038. Data: European Parliament Open Data (CC BY 4.0)}
}