What Is eIDAS? European Digital Identity Explained

This is some text inside of a div block.
6
September 21, 2026

Table of contents

Key takeaways

  • eIDAS establishes a common framework to secure electronic identification and trust services across the European Union and give them legal recognition.
  • The regulation covers electronic signatures and seals, time stamps and the other services used to secure digital transactions.
  • eIDAS 2.0 extends this framework with the European Digital Identity Wallet, designed to make identification and the sharing of credentials easier across the EU.
  • Interoperability at European level should make it easier to use one digital identity to access services in different Member States.
  • Businesses should prepare for these changes by reviewing their identification and authentication processes, their trust services and their security and data protection measures.

eIDAS is a regulation created by the European Union to establish a common framework for securing digital interactions and giving them legal recognition beyond national borders. The framework evolved again in 2024 with eIDAS 2.0 and the creation of a European framework for digital identity. This change introduces the European Digital Identity Wallet across the whole European Union.

For businesses, this transformation concerns electronic signatures, but also authentication, identity management, trust services, data protection and access to certain digital services. This guide explains what is involved.

What Is eIDAS?

Regulation (EU) No 910/2014 (eIDAS) establishes a European legal framework for electronic identification and the trust services used in electronic transactions. Its aim is to strengthen trust in digital exchanges and to allow citizens, businesses and public authorities located in different Member States to interact electronically in a secure environment.

The framework covers the full range of digital transactions, including electronic identification, electronic signatures and seals, time stamps and various trust services. The original framework was amended by Regulation (EU) 2024/1183 of 11 April 2024 (eIDAS 2.0).

How Does the eIDAS Regulation Work?

The eIDAS regulation rests on two main pillars, electronic identification and trust services. It sets out common rules that determine the conditions under which certain electronic processes can be used and recognised in the EU, including the following mechanisms.

Electronic identification

Electronic identification means using data in electronic form to establish the identity of a natural or legal person. This technique allows a user to prove who they are when logging in to an online service, whether public or private.

Electronic signatures

The electronic signature, for its part, allows a natural person to sign data or documents in digital form.

The European framework distinguishes between two types of signature, the electronic signature and the qualified signature. The qualified electronic signature benefits from the highest level of legal recognition and has a legal effect equivalent to that of a handwritten signature.

Electronic seals

The electronic seal is intended for legal persons and guarantees the origin and integrity of data or documents. A company can, for example, use an electronic seal to secure documents generated by its information system. A qualified electronic seal benefits from a presumption of the integrity of the data and the correctness of its origin.

Electronic time stamps

An electronic time stamp adds temporal proof to data by linking it to a specific date and time. This is a very useful function for businesses that need to keep proof of the chronology of a transaction or process.

Trust services

The eIDAS framework also regulates the services designed to strengthen trust in digital transactions. These include the creation and validation of electronic signatures and seals, the issuing of certificates, time stamping, electronic registered delivery, electronic attestations of attributes, and electronic archiving and electronic ledgers. These services can be qualified or non-qualified, with qualified services subject to stricter requirements.

eIDAS 2.0 and the European Digital Identity

With eIDAS 2.0, the European Union is updating this framework to reflect today's digital usage and make electronic identification easier at European level. The changes affect both citizens and the businesses that serve them.

What is eIDAS 2.0?

Regulation (EU) 2024/1183 amends the original framework to anchor digital identity in a broader European framework. Its objective is to give citizens, residents and businesses a secure means of electronic identification designed to be used throughout the European Union.

This change takes into account new digital usage and the increase in remote access, which needs to be properly secured.

European Digital Identity Wallet

This new framework introduces a central innovation, the European Digital Identity Wallet. Under this framework, each EU Member State must provide at least one wallet that complies with European specifications by the end of 2026.

The wallet allows users to identify and authenticate themselves online or offline, and to store, present and share digital documents or attributes. European users can, for example, use it to store identity credentials, diplomas or certificates.

Digital identity wallet use cases

The digital wallet can be used in both the public and private sectors. It allows users to:

  • Access certain public services.
  • Prove their identity during an online procedure.
  • Present a diploma or professional qualification.
  • Provide proof of age.
  • Open certain financial or banking services.
  • Present a digital driving licence.
  • Sign documents electronically.
  • Share certain attributes required for a transaction.

This last possibility strengthens data protection, because it makes it possible to provide only the proof requested rather than the full data (for example, proof that the user is over a certain age without having to share their full date of birth).

Cross-border digital identity

One of the main objectives of the European framework is to prevent digital identity from remaining confined within a single country's borders. To support this, the wallets rely on common standards and specifications that ensure their interoperability. The goal is to be able to use a means of identification issued in one Member State to access services in another.

eIDAS Authentication and Electronic Identification

To regulate electronic identification, eIDAS defines the means used, the authentication rules, the assurance levels and the conditions for recognition between Member States. Each of these elements is covered below.

Electronic identification means

An electronic identification means is a material or immaterial unit that contains the data needed to identify a person when accessing a service. Depending on the systems involved, it can be an electronic identity card, an application or another digital solution.

Authentication under eIDAS

Identification answers the question "who are you?", while authentication consists of verifying that the person using the identity is who they claim to be.

eIDAS authentication must offer a level of trust suited to the risk associated with the service, which sometimes requires advanced security mechanisms depending on the data involved.

Assurance levels for electronic identification

The European framework distinguishes three assurance levels, low, substantial and high. These levels correspond to the degree of confidence a service places in the identity claimed by the user. The classification depends on how the user was registered, how the identification means is managed and the mechanisms used during eIDAS authentication.

Mutual recognition across EU Member States

Cross-border recognition is one of the foundations of the framework. It aims to promote access to digital services across the Union. For organisations operating in several European countries, this interoperability can help simplify user identification and harmonise certain digital journeys.

Benefits of eIDAS Compliance

The benefits of eIDAS compliance range from more secure transactions to greater legal certainty for electronic documents. Each is explained below.

Secure digital transactions

Compliance with the European framework helps strengthen trust in digital exchanges. Signatures, seals, certificates and time stamps can provide the evidence needed to verify the identity, origin or integrity of data.

Cross-border digital services

By creating common rules, the framework makes it easier to develop services that are accessible in several European countries. A company operating at European level can rely on identification mechanisms and trust services built on a common framework, which simplifies exchanges.

Improved digital identity management

eIDAS 2.0 should also change the way organisations verify and use identity information. The European wallet encourages an approach in which the user shares only the attributes needed for an operation, rather than a full set of personal information.

Legal recognition of electronic transactions

The European framework also provides greater legal certainty for certain paperless operations. It ensures the legal recognition of electronic signatures and gives qualified electronic signatures a legal effect equal to that of a handwritten signature.

This recognition makes it easier to digitise many contractual and administrative processes.

How Businesses Can Prepare for eIDAS 2.0

The rollout of the European Digital Identity Wallet creates new obligations and new opportunities for organisations. To prepare for its integration, the first step is to determine which business processes involve digital identity. This may include account creation, customer authentication, contract signing or the transmission of supporting documents.

Businesses then need to identify the technical and organisational changes required, while building in data protection by design and taking into account their eIDAS and cybersecurity obligations alongside data protection rules such as the GDPR and the Data Act.

eIDAS Compliance Checklist

To assess their eIDAS compliance, businesses can review four key areas. Each one is set out below.

Review electronic identification processes

Start by mapping the situations in which your organisation needs to identify or authenticate people. For each process, determine what information is required, what level of trust must be achieved and which solutions are currently in use.

Assess electronic signature and seal practices

List the types of documents that are signed or sealed electronically and the technologies used. At this stage, determine the level of signature required according to the legal context and the risk associated with the transaction.

Verify trust service provider requirements

If your business relies on an external provider, you will also need to verify its status and the exact nature of its services. To make this step easier, Member States publish trusted lists that bring together qualified providers and their services.

Review security and data protection controls

Finally, review the data collected and shared during identification, access rights, retention procedures, authentication mechanisms and the associated cybersecurity measures, to make sure your overall framework is coherent. This review also helps keep eIDAS aligned with the other key data compliance regulations your organisation must follow.

Get Expert Support for eIDAS Compliance With DPO Consulting

Changes to the eIDAS framework can have legal, technical and organisational consequences. For a business, the challenge is not only to select a new identification or electronic signature solution, but to determine how it fits into its existing regulatory environment.

DPO Consulting supports organisations in analysing their obligations in terms of digital compliance and data protection. Our services give you comprehensive support that covers mapping the processing activities and processes concerned, identifying risks, assessing existing practices and preparing for the changes needed to integrate new digital identity mechanisms.

Anticipating these changes helps simplify certain digital journeys while strengthening the security, trust and control of your data.

Find out more about DPO Consulting's digital transformation services, or request a quote to discuss your eIDAS compliance needs.

FAQs

Is eIDAS mandatory for businesses?

The eIDAS regulation applies across the European Union, but not every business has to use all of the mechanisms it provides for. The specific obligations depend on the organisation's activity, the services it provides and its use of identification means or trust services.

What is the difference between eIDAS and eIDAS 2.0?

The original framework under Regulation (EU) No 910/2014 focused on electronic identification and trust services for electronic transactions. Regulation (EU) 2024/1183 amended this framework to establish a European framework for digital identity. This change introduces the European Digital Identity Wallet and extends the framework that applies to certain trust services.

What is a qualified electronic signature under eIDAS?

It is an advanced electronic signature created by a qualified electronic signature creation device and based on a qualified certificate for electronic signatures. It has a legal effect equivalent to that of a handwritten signature throughout the European Union.

Who can provide eIDAS trust services?

To obtain qualified trust service provider status, businesses must meet the requirements set out in the European framework and obtain the corresponding status from the competent supervisory body.

What is the European Digital Identity Wallet used for?

It is designed to allow citizens, residents and businesses to identify and authenticate themselves, and to store and share certain digital documents or attributes securely. It can be used, for example, to prove identity or age, or to sign certain documents electronically.

Does eIDAS apply outside the European Union?

eIDAS is a European Union regulation, so its legal recognition and interoperability framework applies within the EU. However, a business established outside the EU may be affected when it provides certain services on the European market or needs to interact with European organisations and users.

Are electronic signatures legally valid under eIDAS?

Yes. An electronic signature cannot be denied legal effect solely because it is in electronic form or does not meet the requirements of a qualified electronic signature. The qualified electronic signature does, however, have a special status because it produces the same legal effect as a handwritten signature.

How does eIDAS support cross-border digital identification?

The European framework establishes common electronic identification rules and provides for the recognition of certain identification means across Member States. The European Digital Identity Wallet makes it easier to use a digital identity to access public and private services in other EU countries.

References

Read this next

See all