Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ITRE-PR-732707 → A-9-2023-0038

From
ITRE-PR-732707 report parliamentary committee draft of 31 May 2022
To
A-9-2023-0038 Plenary report of 3 Mar 2023
Changes
Not comparable
Paragraphs
+625 added · −254 removed · 4 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
Title (to)
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 9 of 15: Paragraphs 481–540

Added1. European Digital Identity Wallets that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to be compliant with the cybersecurity relevant requirements set out in Article 6a of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements. When relevant European cybersecurity certification schemes are available, the European Digital Identity Wallet, or parts thereof, shall be certified in accordance with such schemes.

RemovedArticle 1 – paragraph 1 – point 39, Article 45f – paragraph 4: deleted

Added2. Compliance with the requirements set out in ▌Article 6a(3), (4) and (5) related to the personal data processing operations carried out by the issuer of the European Digital Identity Wallets shall be certified pursuant to Regulation (EU) 2016/679.

RemovedRegulation (EU) No 910/2014

Added2a. Where relevant European functionality and interoperability certification schemes are available, the European Digital Identity Wallet, or parts thereof, shall be certified in accordance with such schemes. Those certification schemes shall provide a presumption of conformity to the functionality and interoperability requirements set out in Article 6a. In the absence of certification schemes for functionality and interoperability, the standards referred to in Article 6a(11) shall apply.

RemovedArticle 1 – paragraph 1 – point 39, Article 45f – paragraph 4 a (new): 4a. Providers of qualified electronic attestation of attributes’ service shall ensure that personal data, including anonymised or cryptographically protected data, are stored and processed only in the territory of the Union and that only Union and national law and applies to those personal data. Providers of qualified electronic attestation of attribute’s services shall keep at the disposal of the Member States and the Commission the proof of the technical and organisational means that they put in place to ensure that only Union and national law applies to those personal data.

Added3. The conformity of European Digital Identity Wallets with the requirements laid down in Article 6a of this Regulation shall be certified by conformity assessment bodies in accordance with Article 60 of Regulation (EU) 2019/881 for cybersecurity requirements and by certification bodies in accordance with Article 43 of Regulation (EU) 2016/679 for personal data processing operations.

RemovedRegulation (EU) No 910/2014

Added3a. For the purposes of this Article, European Digital Identity Wallets shall not be subject to the requirements referred to in Articles 7 and 9.

RemovedArticle 1 – paragraph 1 – point 39, Article 45i – paragraph 1 – point a: (a) they are created or maintained by one or more qualified trust service provider or providers;

Added4. By ... [6 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of standards, technical specifications, procedures and available Union and national cybersecurity certification schemes pursuant to Regulation (EU) 2019/881 necessary for the certification of the European Digital Identity Wallets referred to in paragraphs 2a and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2) of this Regulation.

RemovedRegulation (EU) No 910/2014

Added5. Member States shall communicate to the Commission the names and addresses of the conformity assessment bodies and certification bodies referred to in paragraph 3. The Commission shall make that information available to all Member States.

RemovedArticle 1 – paragraph 1 – point 39 a (new), Chapter IV a (new): (39a) the following chapter is inserted: / ' CHAPTER IVa / GOVERNANCE / Article 46a / National competent authority and single point of contact / 1. Each Member State shall establish one or more new national competent authorities to carry out the tasks assigned to them under Article 46b or designate and existing body for that purpose. / 2. Each Member State shall designate one national single point of contact on European digital identity framework (single point of contact). Where a Member State designates only one competent authority, that competent authority shall also be the single point of contact for that Member State. / 3. Each single point of contact shall exercise a liaison function to ensure cross-border cooperation of its Member State’s authorities with the relevant authorities in other Member States, and, where appropriate, the Commission and ENISA, as well as to ensure cross-sectorial cooperation with other national competent authorities within its Member State. / 4. Member States shall ensure that the competent authorities referred to in paragraph 1 have the necessary powers and adequate resources to carry out, in an effective and efficient manner, the tasks assigned to them and thereby to fulfil the objectives of this Regulation. Member States shall ensure effective, efficient and secure cooperation of the designated representatives in the European Digital Identity Board referred to in Article 46c. / 5. Each Member State shall notify to the Commission, without und…

Added6. The Commission shall be empowered to adopt delegated acts in accordance with Article 47, supplementing this Regulation by establishing the specific criteria ▌ referred to in paragraph 3 of this Article.

RemovedRegulation (EU) No 910/2014

AddedPublication of a list of certified European Digital Identity Wallets

RemovedArticle 1 – paragraph 1 – point 40, Article 48a – paragraph 2 – point (b): (b) the type and number of services accepting the use of the European Digital Wallet, including the number of rejected applications and their reasoning;

Added1. Member States shall inform the Commission without undue delay of the European Digital Identity Wallets that have been issued pursuant to Article 6a and certified by the bodies referred to in Article 6c(3). They shall also inform the Commission, without undue delay, in the event that certification is cancelled and the reasons for such cancellation.

RemovedRegulation (EU) No 910/2014

Added2. On the basis of the information received, the Commission shall establish, publish and maintain an up-to-date, machine readable list of certified European Digital Identity Wallets.

Change 6

ChangedArticle3. 1By –... paragraph[6 1months –after pointthe 42,date Articleof 51entry –into paragraphforce 2of athis (new):amending 2a.Regulation], Fromthe Commission shall define formats and procedures applicable for the datepurposes of entryparagraph into1 forceof this Article by means of thean implementing actsact pursuanton tothe Articleimplementation 20(4),of qualifiedthe trustEuropean serviceDigital providersIdentity shallWallets continueas referred to bein consideredArticle to6a(11). beThat qualifiedimplementing trustacts serviceshall providersbe untiladopted thein renewalaccordance ofwith theirthe auditexamination asprocedure setreferred outto in Article 20(1).48(2).’;

Change 7

RemovedRegulation (EU) No 910/2014

Added(8) the following heading is inserted before Article 7:

RemovedAnnex V – paragraph 1 – point g, Annex V – paragraph 1 – point g: (g) the qualified electronic signature or qualified electronic seal of the issuing qualified trust service provider;

Added‘SECTION II

RemovedRegulation (EU) No 910/2014

AddedELECTRONIC IDENTIFICATION SCHEMES;’;

RemovedAnnex VI – paragraph 1 – point 2, Annex VI – paragraph 1 – point 2: 2. Date of birth;

Added(9) the introductory sentence of Article 7 is replaced by the following:

RemovedRegulation (EU) No 910/2014

Added‘Pursuant to Article 9(1) Member States shall notify, by ... [12 months after the entry into force of this Regulation] at least one electronic identification scheme including at least one electronic identification means with assurance level 'high' meeting all the following conditions:’;

RemovedAnnex VI – paragraph 1 – point 6, Annex VI – paragraph 1 – point 6: 6. Nationalities;

Added(10) in Article 9, paragraphs 2 and 3 are replaced by the following:

RemovedRegulation (EU) No 910/2014

Added‘2. The Commission shall, without undue delay, publish in the Official Journal of the European Union a list of the electronic identification schemes which were notified pursuant to paragraph 1 of this Article and the basic information thereon.

RemovedAnnex VI – paragraph 1 – point 10, Annex VI – paragraph 1 – point 10: 10. Company data.

Added3. The Commission shall publish in the Official Journal of the European Union the amendments to the list referred to in paragraph 2 within one month from the date of receipt of that notification.’;

RemovedRegulation (EU) No 910/2014

Added(10a) in Article 10, the title is replaced by the following:

RemovedAnnex VI – paragraph 1 – point 10 a (new), Annex VI – paragraph 1 – point 10 a (new): 10a. Identity photo;

Added"Security breach of electronic identification schemes for cross-border authentication";

RemovedRegulation (EU) No 910/2014

Added(11) the following Article ▌ is inserted:

RemovedAnnex VI – paragraph 1 – point 10 b (new), Annex VI – paragraph 1 – point 10 b (new): 10b. E-mail address.

Added‘Article 10a

AddedSecurity breach of the European Digital Identity Wallets

Added1. Where European Digital Identity Wallets issued pursuant to Article 6a and the validation mechanisms referred to in Article 6a(5) points (a), (b) and (c) are breached or partly compromised in a manner that affects their reliability or the confidentiality, integrity or availability of user data, or the reliability of the other European Digital Identity Wallets, the issuing Member State shall, without delay, suspend the issuance and revoke the validity of the European Digital Identity Wallet and inform the affected users, the single point of contact designated pursuant to Article 46a, the relying parties, the other Member States and the Commission accordingly.

Added1a. After notification of the security breach of the European Digital Identity Wallet, the single point of contact designated pursuant to Article 46a shall liaise with the relevant national competent authorities and, where necessary, with the European Digital Identity Framework Board established pursuant to Article 46c, the European Data Protection Board, the Commission and ENISA.

Added2. Where the breach or compromise referred to in paragraph 1 is remedied, the issuing Member State shall re-establish the issuance and the use of the European Digital Identity Wallet and inform the national competent authorities of the other Member States, the affected users and relying parties, the single point of contact designated pursuant to Article 46a and the Commission without undue delay.

Added3. If no attempt or insufficient progress is made to remedy the breach or compromise referred to in paragraph 1 ▌ within three months of the suspension or revocation, the Member State concerned shall withdraw the European Digital Identity Wallet concerned and inform the affected users, the single point of contact designated pursuant to Article 46a, the relying parties the other Member States and the Commission on the withdrawal accordingly. Where it is justified by the severity of the breach, the European Digital Identity Wallet concerned shall be withdrawn without delay and the relevant decision should be reasoned and communicated to the Commission.

Added4. The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list referred to in Article 6d without undue delay.

Added5. By ... [6 months after the date of entry into force of this amending Regulation], the Commission shall adopt a delegated act in accordance with Article 47, supplementing this Regulation by further specifying the measures referred to in paragraphs 1 and 3 of this Article. ’;

Added(12) the following Article ▌ is inserted:

Added‘Article 11a

AddedCross-border user identification

Added1. When accessing cross-border public services that requires identification of the user by Union or national law, Member States shall ensure unequivocal identity matching for natural persons using notified electronic identification means or European Digital Identity Wallets. Member States shall provide for technical and organisational measures to ensure the protection of personal data and prevent profiling of users.

Added2. In order to identify natural persons upon their request for accessing services as described in paragraph 1, Member States shall provide a minimum set of person identification data referred to in Article 12.4.(d). Member States that have at least one unique identifier shall, at the request of the user, issue unique and persistent identifiers for cross-border use. Those identifiers may be specific to particular sectors or relying parties, provided that they uniquely identify the user across the Union.

Added2a. Member States shall provide a single unique and persistent identifier for legal persons using electronic identification means or European Digital Identity Wallets.

Added3. By … [6 months after the date of entry into force of this amending Regulation], the Commission shall adopt an implementing act on the implementation of the European Digital Identity Wallets as referred to in Article 6a(11), laying down further technical specifications that are privacy enhancing and that will ensure trustworthy, secure and interoperable cross-border authentication and identification of users. That implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
30 September 2026

Cite as

European Parliament (2023). “Changes between ITRE-PR-732707 and A-9-2023-0038”. Text, 3 March 2023. from ITRE-PR-732707, to A-9-2023-0038. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=9 (retrieved 30 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-03-03,
  author = {{European Parliament}},
  title = {{Changes between ITRE-PR-732707 and A-9-2023-0038}},
  year = {2023},
  date = {2023-03-03},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=9}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-732707/compare/A-9-2023-0038?all=1&part=9},
  urldate = {2026-09-30},
  publisher = {EU Parl Watch Research},
  note = {Text. from ITRE-PR-732707, to A-9-2023-0038. Data: European Parliament Open Data (CC BY 4.0)}
}