EU's Digital Identity Wallet Faces Technical and Privacy Shortfalls Ahead of 2026 Deadline

EU’s Digital Identity Wallet Faces Technical and Privacy Shortfalls Ahead of 2026 Deadline

A Single Wallet for 27 Nations

Every European Union member state must, by law, offer its citizens a European Digital Identity Wallet before the end of 2026 — a smartphone application designed to consolidate government identification, driving licences, academic diplomas, and other verified credentials into a single portable instrument recognised across all 27 member states. The ambition is considerable: to create a seamless, interoperable identity infrastructure for nearly half a billion people. Digital rights organisations, however, are warning that the underlying technology is incomplete, the privacy safeguards remain untested at scale, and the system risks becoming precisely the surveillance mechanism it was conceived to prevent.

Thomas Lohninger, executive director of the Austrian digital rights organisation epicenter.works and a board member of European Digital Rights (EDRi), places current technical readiness at “maybe 50 to 60 per cent of the standards needed to build this wallet.” The remaining share, he argues, does not merely require refinement — it does not yet exist. That assessment carries weight at a moment when implementing regulations are still being drafted and national governments are already committing resources to deployment.

The Concentration Risk

Consolidating identity, health data, financial credentials, and travel documents onto a single device dramatically raises the consequences of any single security failure. A stolen handset, a compromised application, or a cloud-side breach could expose the full profile of an individual simultaneously, rather than one siloed credential at a time. Critically, a stolen digital credential carries a cryptographic signature of authenticity, making fraudulent misuse substantially more damaging than a leaked password, which can be reset without the attacker possessing a government-endorsed proof of identity.

Lohninger describes the wallet as “critical infrastructure” linking the public and private sectors in a manner unprecedented in Europe, and a target not merely for opportunistic cybercriminals but for state-level actors. The failure scenarios he sketches are mundane in origin but severe in consequence: a few hours of downtime or a successful hack could lock individuals out of public transport, social media accounts, and the physical driving licence they no longer carry separately. The regulation does mandate technical defences — tamper-resistant cryptographic hardware, device-bound credentials, authenticated data requests, and a 24-hour notification requirement for revoked credentials — and the European Data Protection Supervisor has identified secure hardware elements as a key safeguard. Nevertheless, EU auditors acknowledge that wallet recovery procedures remain only partially tested.

Privacy by Design — or Surveillance by Default?

The wallet’s central privacy proposition rests on selective disclosure: a user proving they are over 18 should be able to share only that binary fact, not their name, address, or identification number. The EDPS frames this as “authorisation without identification,” an advance over the physical identity card, which necessarily discloses far more than any given transaction requires. In principle, the architecture is sound; in practice, Lohninger warns of what he terms “over-identification.”

At present, verifying identity online is slow and costly — banks and mobile carriers pay to perform it under anti-money-laundering obligations. A widely available, frictionless wallet could make identification so cheap and rapid that services currently content with anonymous sign-ups would face a strong commercial incentive to demand it. The result would be a systematic erosion of the residual anonymity that still exists on social networks and in routine email registration. EDRi has further raised the spectre of a “panopticon” effect: because the same wallet would serve taxes, healthcare, banking, public transport, and social-media login, previously separate behavioural trails could become linkable through a single system. Draft implementing rules, EDRi argues, currently weaken the legal principle of unobservability that was intended to prevent wallet providers or platform operators from monitoring user activity — while simultaneously introducing mandatory biometric facial checks not foreseen in the original legislation.

Cryptography That Does Not Yet Exist

The technical gap is most acute in the cryptographic layer. Zero-knowledge proofs — mathematical techniques that allow a user to demonstrate a fact, such as majority age, without exposing the underlying data — represent, in Lohninger’s words, “the frontier of cryptographic science.” They are not yet mature enough for deployment at the scale and reliability a continent-wide identity system demands. Lohninger characterises the challenge as a triangle between privacy, security, and usability, noting that it is “very hard to get all three to 100 per cent” and that the wallet “certainly will cut some corners.”

The question of which corner yields first is not merely technical. A credential system can be cryptographically robust — strong keys, valid signatures, no obvious vulnerability — and still leak behavioural information if the same identifier is reused across services. In that scenario, different verifiers can link separate transactions to the same individual without ever knowing their name, constructing a detailed profile through pattern alone. Whether the implementing standards adequately address this linkability risk remains, at present, unresolved.

The Cross-Border Weak Link

Mutual recognition is the architectural premise of the wallet: a bank in Portugal must trust an identity enrolled and certified in Finland, and vice versa. That trust is only as durable as the least rigorous national deployment. Lohninger does not expect uniform standards to be in place by the deadline, noting that even well-resourced member states such as France and Germany “will not make it completely to the finish line.” The implication is a system designed for 27 equally robust implementations that will, in practice, be anchored by the slowest incident-response capability and the least stringent enrolment process among its members.

His counsel is deliberate restraint. He calls on citizens and policymakers to resist early adoption, and urges independent academic and civil-society audits of national implementations before the public commits to the system in earnest. To support that watchdog function, epicenter.works is developing an open-data platform called “Who Identifies Me,” intended to allow journalists and civil-society organisations to track which companies and border agencies request citizens’ data once the wallet is live.

Rising Political Stakes

The technical debate is acquiring sharper political edges as governments across France, Denmark, Greece, and Austria advance age-verification legislation for social media, with an EU-wide announcement from Commission President Ursula von der Leyen anticipated in the near term. The wallet is being positioned as the enforcement instrument for these measures, pairing a high-value identity infrastructure with, as Lohninger puts it, “the most dubious companies that we interact with on a daily basis.” That pairing concentrates risk: the credibility of a government-backed identity system becomes contingent on the security practices of commercial platforms over which member states have limited control.

Lohninger’s closing warning is grounded in comparative evidence. “The public’s trust is really the scarcest resource in all of this,” he says. “We have seen in regions around the world, when these big government digital identity systems are rolled out and they have problems, people run away.” For a project whose utility depends entirely on mass adoption, the cost of a visible early failure could prove more consequential than any single technical shortcoming — and harder to recover from than a compromised credential.