Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ITRE-PR-732707 → A-9-2023-0038

From
ITRE-PR-732707 report parliamentary committee draft of 31 May 2022
To
A-9-2023-0038 Plenary report of 3 Mar 2023
Changes
Not comparable
Paragraphs
+625 added · −254 removed · 4 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
Title (to)
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 14 of 15: Paragraphs 781–840

Added(l) to inform the body responsible for the national trusted list referred to in Article 22(3) about its decisions to grant or to withdraw qualified status, unless that body is also the national competent authority;

Added(m) to verify the existence and correct application of provisions on termination plans in cases where the qualified trust service provider ceases its activities, including how information is kept accessible in accordance with Article 24(2), point (h);

Added(n) to require that trust service providers and issuers of European Digital Identity Wallet’s remedy any failure to fulfil the requirements laid down in this Regulation;

Added(o) to cooperate with other national competent authorities and provide them with assistance in accordance with Article 46c.

Added2. By 31 March each year, each national competent authority shall submit to the Commission a report on its main activities during the previous calendar year.

Added3. The Commission shall make the annual reports referred to in paragraph 2 available to the European Parliament and the Council and make them public.

Added4. By … [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, define the formats and procedures for the report referred to in paragraph 1, point (h) of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Added5. By … [12 months after the date of entry into force of this amending Regulation], the Commission shall adopt a delegated act in accordance with Article 47, supplementing this Regulation by further specifying the tasks of the national competent authorities referred to in paragraph 1.

AddedThe European Digital Identity Framework Board

Added1. The European Digital Identity Framework Board (the ‘EDIFB’) shall be established.

Added2. The EDIFB shall be composed of representatives of national competent authorities and the Commission.

Added3. Stakeholders and all relevant third parties may be invited to attend meetings of the EDIFB and to participate in its work.

Added4. ENISA shall be invited when issues regarding cyber threats, notification of breaches, cybersecurity certificates or standards or other issues pertaining to the security are discussed.

Added5. The EDIFB shall have the following tasks:

Added(a) assist the Commission in the preparation of legislative proposals and policy initiatives in the field of digital wallets, electronic identification means and trust services;

Added(b) assist and cooperate with the Commission on the preparation of implementing and delegated acts pursuant to this Regulation;

Added(c) support the consistent application of this Regulation, among other for the purpose of:

Added(i) exchanging good practices and information regarding the application of the provisions of this Regulation;

Added(ii) examining the relevant developments in the European Digital Identity Wallet, electronic identification and trust services sectors;

Added(iii) organising regular joint meetings with relevant interested parties from across the Union to discuss activities carried out by the EDIFB and gather input on emerging policy challenges;

Added(iv) issuing common guidelines on the implementation of the Regulation;

Added(v) with the support of ENISA, exchanging information, experience and good practice as regards to all cybersecurity aspects of the European Digital Identity Wallet, the electronic identification schemes and trust services;

Added(vi) national competent authorities under this Regulation and national competent authorities under Directive (EU) XXXX/XXXX of the European Parliament and of the Council [NIS2] shall cooperate to ensure the continuation of current practices and to build on the knowledge and experience gained in the application of the eIDAS Regulation. In addition, they shall collaborate as to ensure a coherent implementation of the Directive (EU) XXXX/XXXX of the European Parliament and of the Council [NIS2];

Added(vii) providing guidance in relation to the development and implementation of policies on notification of breaches, coordinated vulnerability disclosure and common measures as referred to in Articles 10 and 10a;

Added(viii) exchanging best practices and information in relation to the cybersecurity measures of this Regulation and on Directive (EU) XXXX/XXXX of the European Parliament and of the Council [NIS2] as regards to trust services, in relation to cyber threats, incidents, vulnerabilities, awareness raising initiatives, trainings, exercises and skills, capacity building, standards and technical specifications capacity as well as standards and technical specifications;

Added(ix) carrying out coordinated security risk assessments in cooperation with ENISA;

Added(x) peer review of notified electronic identification schemes falling under this Regulation.

Added6. In the framework of the EDIFB, Member States may seek mutual assistance:

Added(a) upon receipt of a reasoned request from a national competent authority, EDIFB shall provide that national competent authority with assistance so that it can be carried out in a consistent manner, which may cover, in particular, information requests and supervisory measures, such as requests to carry out inspections related to the conformity assessment reports as referred to in Articles 20 and 21 regarding the provision of trust services;

Added(b) where appropriate, Member States may authorise their respective national competent authorities to carry out joint investigations in which staff from other Member States’ competent national authority is involved. The arrangements and procedures for such joint actions shall be agreed upon and established by the Member States concerned in accordance with their national law.

Added7. By … [6 months after the date of entry into force of this amending Regulation] and every two years thereafter, the EDIFB shall establish a work programme in respect of actions to be undertaken to implement its objectives and tasks.

Added8. The Commission may adopt implementing acts laying down procedural arrangements necessary for the functioning of the EDIFB. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Added(39b) Article 47 is amended as follows:

Added(a) paragraphs 2 and 3 are replaced by the following:

Added‘2. The power to adopt delegated acts referred to in Article 6a(11a), Article 6c(6), Article 24(1a) and 24(6), Article 30(4) and Article 46b(5) shall be conferred on the Commission for an indeterminate period of time from 17 September 2014.

Added3. The delegation of power referred to in Article 6a(11a), Article 6c(6), Article 24(1a) and (6), Article 30(4) and Article 46b(5) may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.’;

Added(b) paragraph 5 is replaced by the following:

Added‘5. A delegated act adopted pursuant to Article 6a(11a), Article 6c(6), Article 24(1a) or (6), Article 30(4) or Article 46b(5) shall enter into force only if no objection has been expressed either by the European Parliament or the Council within a period of two months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by two months at the initiative of the European Parliament or of the Council.’;

Added(40) The following Article ▌ is inserted:

Added‘Article 48a

AddedReporting requirements

Added1. Member States shall ensure the collection of statistics in relation to the functioning of the European Digital Identity Wallets and the qualified trust services.

Added2. The statistics collected in accordance with paragraph 1, shall include the following:

Added(a) the number of natural and legal persons having a valid European Digital Identity Wallet;

Added(b) the type and number of services accepting the use of the European Digital Identity Wallet and the number of and reasons for the rejection of application of service providers aiming to become a relying party;

Added(ba) the number of user complaints and consumer protection or data protection incidents relating to relying parties and qualified trust services;

Added(c) the type and number of incidents and down time of the infrastructure at national level preventing the use of European Digital Identity Wallets ▌ ;

Added(ca) the type and number of security incidents, suspected data breaches and affected users of European Digital Identity Wallets or qualified trust service;

Added3. The statistics referred to in paragraph 2 shall be made available to the public in an open and commonly used, machine-readable format.

Added4. By March each year, Member States shall submit to the Commission a report on the statistics collected in accordance with paragraph 2.’;

Added(41) Article 49 is replaced by the following:

Added‘Article 49

AddedReview

Added1. The Commission shall review the application of this Regulation and shall report to the European Parliament and to the Council by ... [24 months after the date of entry into force of this amending Regulation]. The Commission shall evaluate in particular whether it is appropriate to modify the scope of this Regulation or its specific provisions taking into account the experience gained in the application of this Regulation, as well as technological, market and legal developments. Where necessary, that report shall be accompanied by a proposal for amendment of this Regulation.

Added2. The evaluation report shall include an assessment of the availability, security and usability of the identification means including European Digital Identity Wallets in scope of this Regulation and assess whether all online private service providers relying on third party electronic identification services for users authentication, shall be mandated to accept the use of notified electronic identification means and European Digital Identity Wallet.

Added3. In addition, the Commission shall submit a report to the European Parliament and the Council every four years after the report referred to in the first paragraph on the progress towards achieving the objectives of this Regulation.’;

Added(42) Article 51 is replaced by the following:

Added‘Article 51

AddedTransitional measures

Added1. Secure signature creation devices of which the conformity has been determined in accordance with Article 3(4) of Directive 1999/93/EC shall continue to be considered as qualified electronic signature creation devices under this Regulation until [date – OJ please insert period of four years following the entry into force of this Regulation].

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
30 September 2026

Cite as

European Parliament (2023). “Changes between ITRE-PR-732707 and A-9-2023-0038”. Text, 3 March 2023. from ITRE-PR-732707, to A-9-2023-0038. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=14 (retrieved 30 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-03-03,
  author = {{European Parliament}},
  title = {{Changes between ITRE-PR-732707 and A-9-2023-0038}},
  year = {2023},
  date = {2023-03-03},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=14}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=14},
  urldate = {2026-09-30},
  publisher = {EU Parl Watch Research},
  note = {Text. from ITRE-PR-732707, to A-9-2023-0038. Data: European Parliament Open Data (CC BY 4.0)}
}