Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ITRE-PR-732707 → A-9-2023-0038

From
ITRE-PR-732707 report parliamentary committee draft of 31 May 2022
To
A-9-2023-0038 Plenary report of 3 Mar 2023
Changes
Not comparable
Paragraphs
+625 added · −254 removed · 4 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
Title (to)
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 3 of 15: Paragraphs 121–180

Added(21a) This Regulation aims to facilitate the creation of, the choice between and the possibility of switching between EDIWs. In order to avoid lock-in effects, the issuers of EDIWs should, at the request of EDIW users, ensure the effective portability of data, including continuous and real-time access to services, and should not be allowed to use contractual, economic or technical barriers to prevent or to discourage effective switching between different EDIWs.

RemovedArticle 1 – paragraph 1 – point 4 a (new), Article 1 – paragraph 5a (new): (4a) the following article is inserted: / 'Article 5a / Protection of personal data / 1. Processing of personal data shall be carried out in accordance with Regulation (EU) 2016/679, in particular by implementing principle of privacy by design and by default. / 2. Attributes and person identification data relating to natural persons are personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679.'

Added(22) In order to streamline the cybersecurity obligations imposed on trust service providers, as well as to enable these providers and their respective competent authorities to benefit from the legal framework established by Directive XXXX/XXXX (NIS2 Directive), trust services are required to take appropriate technical and organisational measures pursuant to Directive XXXX/XXXX (NIS2 Directive), such as measures addressing system failures, human error, malicious actions or natural phenomena in order to manage the risks posed to the security of network and information systems which those providers use in the provision of their services as well as to notify significant incidents and cyber threats in accordance with Directive XXXX/XXXX (NIS2 Directive). With regard to the reporting of incidents, trust service providers should notify any incidents having a significant impact on the provision of their services, including such caused by theft or loss of devices, network cable damages or incidents occurred in the context of identification of persons. The cybersecurity risk management requirements and reporting obligations under Directive XXXXXX [NIS2] should be considered complementary to the requirements imposed on trust service providers under this Regulation. Where appropriate, established national practices or guidance in relation to the implementation of security and reporting requirements and supervision of compliance with such requirements under Regulation (EU) No 910/2014 should continue to be applied by the competent authorities designated under Directive XXXX/XXXX (NIS2 Directive). Any requirements pursuant to this Regulation do not affect the obligation to notify personal data breaches under Regulation (EU) 2016/679.

RemovedRegulation (EU) No 910/2014

Added(23) Due consideration should be given to ensure effective cooperation between the NIS and eIDAS authorities. In cases where the supervisory body under this Regulation is different from the competent authorities designated under Directive XXXX/XXXX [NIS2], those authorities should cooperate closely, in a timely manner by exchanging the relevant information in order to ensure effective supervision and compliance of trust service providers with the requirements set out in this Regulation and Directive XXXX/XXXX [NIS2]. In particular, the supervisory bodies under this Regulation should be entitled to request the competent authority under Directive XXXXX/XXXX [NIS2] to provide the relevant information needed to grant the qualified status and to carry out supervisory actions to verify compliance of the trust service providers with the relevant requirements under NIS 2 or require them to remedy non-compliance.

RemovedArticle 1 – paragraph 1 – point 7, Article 6a – paragraph 1: 1. For the purpose of ensuring that all natural and legal persons in the Union have secure, trusted and seamless access to cross-border public and private services, each Member State shall issue at least one European Digital Identity Wallet by … [12 months after the entry into force of this amending Regulation].

Added(24) It is essential to provide for a legal framework to facilitate cross-border recognition between existing national legal systems related to electronic registered delivery services. That framework could also open new market opportunities for Union trust service providers to offer new pan-European electronic registered delivery services and ensure that the identification of the recipients is ensured with a higher level of confidence than the identification of the sender.

RemovedRegulation (EU) No 910/2014

Added▌

RemovedArticle 1 – paragraph 1 – point 7, Article 6a – paragraph 2 – point c: (c) by an organisation established in the Union.

Added(26) It should be possible to issue and handle trustworthy digital attributes and contribute to reducing administrative burden, empowering citizens and other residents to use them in their private and public transactions. Citizens and other residents should be able, for instance, to demonstrate ownership of a valid driving license issued by an authority in one Member State, which can be verified and relied upon by the relevant authorities in other Member States, to rely on their social security credentials or on future digital travel documents in a cross border context.

RemovedRegulation (EU) No 910/2014

Added(27) Any entity that collects, creates and issues attested attributes such as diplomas, licences, certificates of birth should be able to become a provider of electronic attestation of attributes and should be responsible for revoking the attestation in the event of falsification, identity theft, or any issuance based on an abusive request. Relying parties should use the electronic attestations of attributes as equivalent to attestations in paper format. Nevertheless, lawfully issued attestations of attributes in paper form should continue to be accepted by relying parties as an alternative to electronic attestations of attributes. An electronic attestation of attributes should not be denied legal effect solely on the grounds that it is in an electronic form or that it does not meet the requirements of the qualified electronic attestation of attributes. To that effect, general requirements should be laid down to ensure that a qualified electronic attestation of attributes has the equivalent legal effect of lawfully issued attestations in paper form. However, those requirements should apply without prejudice to Union or national law defining additional sector specific requirements as regards form with underlying legal effects and, in particular, the cross-border recognition of qualified electronic attestation of attributes, where appropriate. The Commission and the Member States should involve professional organisations in laying down the attributes that concern them.

RemovedArticle 1 – paragraph 1 – point 7, Article 6a – paragraph 3 – point a: (a) securely request and obtain, validate, store, select, issue, combine, share and exchange, in a manner that is transparent to and traceable by the user, the electronic attestation of attributes, including person identification data, and to securely authenticate and identify online and offline in order to use online public and private services;

Added(28) The wide availability and usability of EDIWs require their acceptance and trust by both private individuals and private service providers. Private relying parties providing services such as in the areas of transport, energy, banking and financial services, social security, health, drinking water, postal services, digital infrastructure, ▌telecommunications or education should accept the use of ▌EDIWs for the provision of services where strong user authentication for online identification is required by Union or national ▌law. Information requested from the user via the EDIW should be necessary and proportionate for the intended use case of the relying party and should be in line with the principle of data minimisation, ensuring transparency over which data is shared and for what purposes. Where very large online platforms as defined in Article 25.1. of Regulation (EU) 2022/2065 require users to authenticate to access online services, those platforms should be mandated to accept the use of EDIWs upon the voluntary request of the user. Users should be under no obligation to use EDIWs to access private services and should not be restricted or hindered on the grounds that they do not use an EDIW, but if users wish to do so, very large online platforms should accept EDIWs for this purpose while respecting the principle of data minimisation and the right of the users to use freely chosen pseudonyms. Given the importance of very large online platforms, due to their reach, in particular as expressed in number of recipients of the service and economic transactions this is necessary to increase the protection of users from fraud and secure a high level of data protection. Self-regulatory codes of conduct at Union level (‘codes of conduct’) should be developed in order to contribute to wide availability and usability of electronic identification means including EDIWs within the scope of this Regulation. The codes of conduct should facilitate wide acceptance of electronic identification means including EDIWs by those service providers which do not qualify as very large platforms and which rely on third party electronic identification services for user authentication. They should be developed within 12 months of the adoption of this Regulation. ▌

RemovedRegulation (EU) No 910/2014

Added(29) EDIWs should technically enable the selective disclosure of attributes to relying parties in a secure and user-friendly manner as one of its key features and advantages. They should also ensure that no attributes are disclosed to parties that are not registered to receive such attributes. This feature should become a basic design feature thereby reinforcing convenience and personal data protection including minimisation of processing of personal data in particular privacy by design and by default. Mechanisms for the validation of EDIWs, the selective disclosure and authentication of users to access online services should be privacy-preserving thereby preventing the tracking of the user and respecting the principle of purpose limitation, which implies a right to pseudonymity to ensure the user cannot be linked across several relying parties. The technical architecture and implementation of EDIWs should be in full compliance with Regulation (EU) 2016/679. In addition, the decentralised nature of EDIWs should enable self-signing and revocability of attributes and identifiers.

RemovedArticle 1 – paragraph 1 – point 7, Article 6a– paragraph 3 – point a a (new): (aa) securely authenticate, identify, receive and exchange electronic attestations of attributes directly from other European Digital Identity Wallets;

Added(29a) Unless specific rules of Union or national law require users to identify themselves, the use of services under a pseudonym should be allowed and should not be restricted by Member States, for example by imposing a general obligation on service providers to limit the pseudonymous use of their services.

RemovedRegulation (EU) No 910/2014

Added(30) Attributes provided by the qualified trust service providers as part of the qualified attestation of attributes should be verified against the authentic sources either directly by the qualified trust service provider or via designated intermediaries recognised at national level in accordance with Union or national ▌law for the purpose of secure exchange of attested attributes between identity or attestation of attributes’ service providers and relying parties.

RemovedArticle 1 – paragraph 1 – point 7, Article 6a– paragraph 3 – point a b (new): (ab) easily report to the competent national authority where a relying party is established if an unlawful or inappropriate request of data is received;

Added(31) Secure electronic identification and the provision of attestation of attributes should offer additional flexibility and solutions for the financial services sector to allow identification of customers and the exchange of specific attributes necessary to comply with, for example, customer due diligence requirements under the Anti Money Laundering Regulation, [reference to be added after the adoption of the proposal], with suitability requirements stemming from investor protection legislation, or to support the fulfilment of strong customer authentication requirements for account login and for initiation of transactions in the field of payment services.

RemovedRegulation (EU) No 910/2014

Added(31a) This Regulation should establish the principle that the legal effect of an electronic signature cannot be challenged on the grounds that it is in an electronic form or that it does not meet the requirements of the qualified electronic signature. However, it is for national law to define the legal effect of electronic signatures, except for the requirements provided for in this Regulation according to which the legal effect of a qualified electronic signature is to be equivalent to that of a handwritten signature. In determining the legal effects of electronic signatures Member States should take into account the principle of proportionality between the judicial value of a document to be signed and level of security and cost that an electronic signature requires. To increase the accessibility and use of electronic signatures, Member States are encouraged to consider the use of advanced electronic signatures in the day-to-day transactions for which they provide a sufficient level of security and confidence. The use of qualified electronic signatures should be mandated only when the highest level of security and confidence is required.

RemovedArticle 1 – paragraph 1 – point 7, Article 6a– paragraph 3 – point a c (new): (ac) sign and validate qualified electronic signatures;

Added(32) Website authentication services provide users with a high level of assurance of the identity of the entity standing behind the website. Those services contribute to the building of trust and confidence in conducting business online, as users will have confidence in a website that has been authenticated. The use of website authentication services by websites is voluntary. However, in order for website authentication to become a means to increasing trust, providing a better experience for the user and furthering growth in the internal market, this Regulation lays down minimal security and liability obligations for the providers of website authentication services and their services. To that end, web-browsers should ensure support and interoperability with qualified certificates for website authentication pursuant to Regulation (EU) No 910/2014. They should recognise and display qualified certificates for website authentication to provide a high level of assurance, allowing website owners to assert their identity as owners of a website and users to identify the website owners with a high degree of certainty. To further promote their usage, public authorities in Member States should consider incorporating qualified certificates for website authentication in their websites. In the case of a security breach, web browsers should be able to take measures that are proportional to their risk. Web browsers should notify the Commission immediately of any security breach as well as the measures taken to remedy such breaches with regard to a single certificate or to a set of certificates.

RemovedRegulation (EU) No 910/2014

Added(33) Many Member States have introduced national requirements for services providing secure and trustworthy digital archiving in order to allow for the long term preservation of electronic documents and associated trust services. To ensure legal certainty and trust, it is essential to provide a legal framework to facilitate the cross border recognition of qualified electronic archiving services. That framework could also open new market opportunities for Union trust service providers.

RemovedArticle 1 – paragraph 1 – point 7, Article 6a– paragraph 3 – point a d (new): (ad) create and validate qualified electronic seals;

Added▌

RemovedRegulation (EU) No 910/2014

Added(36) In order to avoid fragmentation and barriers, due to diverging standards and technical restrictions, and to ensure a coordinated process to avoid endangering the implementation of the future European digital identity framework, a process for close and structured cooperation between the Commission, Member States, civil society, academics and the private sector is needed. To achieve this objective, Member States should cooperate. The Member States should agree on a comprehensive technical architecture and reference framework, a set of common standards and technical references including recognised existing standards, and a set of guidelines and descriptions of best practices covering at least all aspects of the functionalities and interoperability of the EDIWs including eSignatures and of the qualified trust service providers for attestation of attributes as laid out in this regulation. In this context, Member States should also reach agreement on common elements of a business model and fee structure of EDIWs, to facilitate take up, in particular by SMEs in a cross-border context. ▌

RemovedArticle 1 – paragraph 1 – point 7, Article 6a– paragraph 3 – point a e (new): (ae) transfer own electronic attestation of attributes and configurations to another European Digital Identity Wallet belonging to the same user.

Added(36a) In order to ensure wide usability and availability, additional financial support measures should be envisaged to support Member States in issuing and managing EDIWs. To that end, the Commission should asses the availability of additional Union funds to be made available for the Member States that would request support in the development, deployment and management of EDIWs.

RemovedRegulation (EU) No 910/2014

Added(36b) In order to ensure a wider use and applicability of EDIWs across the Union, the Commission should build on and leverage the framework of this Regulation when developing sectoral Union instruments, such as the European Social Security Pass and the common European data spaces. The coordination with the European Social Security Pass should enable the digital portability of citizens’ social security rights across borders and the verification of their entitlements and validity of documents. For the common European data space, EDIWs should enable a higher degree of transparency and control of the users over their data.

RemovedArticle 1 – paragraph 1 – point 7, Article 6a – paragraph 3 – point b: deleted

Added(37) The European Data Protection Supervisor has been consulted pursuant to Article 42(1) of Regulation (EU) 2018/1525 of the European Parliament and of the Council12.

Change 2

Changed(38) Regulation (EU) No 910/2014 should therefore be amended accordingly,

Change 3

RemovedArticle 1 – paragraph 1 – point 7, Article 6a – paragraph 4 – introductory part: 4. European Digital Identity Wallets shall, in particular:

AddedHAVE ADOPTED THIS REGULATION:

Change 4

ChangedRegulation (EU) No 910/2014 is amended as follows:

Change 5

RemovedArticle 1 – paragraph 1 – point 7, Article 6a – paragraph 4 – point a – point 1: (1) for users to obtain electronic attestations of attributes;

Added(1) Article 1 is replaced by the following:

RemovedRegulation (EU) No 910/2014

Added‘This Regulation aims to contribute towards ensuring the proper functioning of the internal market ▌ providing an adequate level of security of electronic identification means and trust services used across the Union. For these purposes, this Regulation:

RemovedArticle 1 – paragraph 1 – point 7, Article 6a – paragraph 4 – point a – point 2: (2) for relying parties to request and validate electronic attestation of attributes, including person identification data, or zero knowledge proof inferred from them;

Added(a) lays down the conditions under which Member States shall provide and recognise electronic identification means of natural and legal persons, falling under a notified electronic identification scheme of another Member State;

RemovedRegulation (EU) No 910/2014

Added(b) lays down rules for trust services, in particular for electronic transactions;

RemovedArticle 1 – paragraph 1 – point 7, Article 6a – paragraph 4 – point a – point 3: (3) for users to present electronic attestation of attributes to relying parties;

Added(c) establishes a legal framework for electronic signatures, electronic seals, electronic time stamps, electronic documents, non-qualified electronic delivery services, qualified electronic registered delivery services, certificate services for website authentication, ▌ electronic attestation of attributes and the management of remote electronic signature and seal creation devices ▌ ;

RemovedRegulation (EU) No 910/2014

Added(d) lays down the conditions for the issuing, managing and recognition of European Digital Identity Wallets by Member States and for ensuring their interoperability and their cross-border use in the Union;

RemovedArticle 1 – paragraph 1 – point 7, Article 6a – paragraph 4 – point a – point 3 a (new): (3a) for users to transfer his or her own electronic attestation of attributes and configurations to another European Digital Identity Wallet belonging to the same user;

Added(da) enables the exercise of the right to safely participate in the digital society and facilitates unrestricted access to online public services throughout the Union for any natural or legal person.’;

RemovedRegulation (EU) No 910/2014

Added(2) Article 2 is amended as follows:

RemovedArticle 1 – paragraph 1 – point 7, Article 6a – paragraph 4 – point a – point 3 b (new): (3b) for users to authenticate, identify and to receive electronic attestations of attributes directly from other European Digital Identity Wallets;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
28 September 2026

Cite as

European Parliament (2023). “Changes between ITRE-PR-732707 and A-9-2023-0038”. Text, 3 March 2023. from ITRE-PR-732707, to A-9-2023-0038. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=3 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-03-03,
  author = {{European Parliament}},
  title = {{Changes between ITRE-PR-732707 and A-9-2023-0038}},
  year = {2023},
  date = {2023-03-03},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=3}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=3},
  urldate = {2026-09-28},
  publisher = {EU Parl Watch Research},
  note = {Text. from ITRE-PR-732707, to A-9-2023-0038. Data: European Parliament Open Data (CC BY 4.0)}
}