Home Technology One wallet, 27 systems: can the EU build an untraceable...
Technology

One wallet, 27 systems: can the EU build an untraceable Digital ID?

Key Points

The EU wants every citizen to have a digital identity wallet by the end of 2026. Digital rights groups warn that the safeguards aren’t ready and that a system designed to protect privacy could instead make Europeans easier to track. By the end of 2026, every EU country must legally offer citizens a European Digital Identity Wallet.

The EU wants every citizen to have a digital identity wallet by the end of 2026. Digital rights groups warn that the safeguards aren’t ready and that a system designed to protect privacy could instead make Europeans easier to track. By the end of 2026, every EU country must legally offer citizens a European Digital Identity Wallet. This smartphone app holds a person’s government ID, driving licence, diploma, and other verified documents in one place and is designed to work across all 27 EU countries. Digital rights groups warn the technology and the safeguards meant to protect it are not ready and that the wallet could become exactly the kind of surveillance tool it was designed to prevent. “We are at maybe 50-60% of the technical standards that are needed to build this wallet,” says Thomas Lohninger, executive director of Austrian digital rights group epicenter.works and a board member of European Digital Rights (EDRi). “The other 40% are not there yet. They do not exist.” The “honeypot” problem Centralising a person’s identity, health data, driving licence, and financial credentials on one device raises the cost of a single security failure. A stolen phone, malicious app, or cloud breach could expose everything at once. Unlike a leaked password, a compromised credential carries a cryptographic signature of authenticity, making misuse far more damaging. “If you put all your eggs in one basket, then that basket hopefully never fails,” Lohninger says. “Imagine if this little wallet gets hacked or has downtime of just a few hours or a week. People would be locked out of their social media. They couldn’t use public transport. Their driver licence would no longer be with them.” He calls the wallet “critical infrastructure” connecting the public and private sector “like we’ve never done in Europe” and a target not just for cybercriminals but state-level actors. The regulation mandates technical defences: tamper-resistant cryptographic hardware to store keys, credentials bound to a specific device so they can’t be copied, authentication for any organisation requesting data, and a rule requiring users to be notified within 24 hours of a revoked credential. The European Data Protection Supervisor points to secure hardware elements as a key safeguard against theft. But losing a phone still means a race to freeze and recover a wallet before a criminal exploits it. EU auditors note that recovery remains only partly tested. Tracking by design The wallet’s core privacy pledge is selective disclosure: someone proving they are over 18 should be able to share only that fact, not their name, address or ID number. The EDPS calls this “authorisation without identification”, a defence against tracking and profiling that a physical ID card can’t offer. Lohninger frames the risk as “over-identification.” Verifying someone’s identity online is currently slow and costly; banks and mobile carriers pay to do it under anti-money-laundering rules. The wallet could make identification very fast, cheap, and widely available, he warns. This creates an incentive to strip away anonymity that currently exists on social networks or in email sign-ups. He also raises what EDRi calls the “panopticon” risk. The same wallet could be used for taxes, healthcare, public transport, banking and logging into Facebook; previously separate areas of life could become linkable through one system. “These areas of life could become connected,” he says. “There’s this big risk of a panopticon where you can really see everything from everyone.” EDRi has pushed for a legal principle called unobservability, intended to stop wallet providers, governments, or potentially Google, from seeing what users do inside the system. Draft implementing rules, EDRi argues, currently weaken exactly this safeguard, while pushing mandatory biometric facial checks not foreseen in the original law. Unfinished cryptography Much of the technology meant to make the wallet both secure and private doesn’t exist yet, Lohninger says. Zero-knowledge proofs, cryptographic techniques that let someone prove a fact, such as being over 18, without revealing the underlying data, are “the frontier of cryptographic science.” “There is a triangle between privacy, security, and usability,” he says. “It’s very hard to get all three to 100%. The wallet certainly will cut some corners here.” That leaves an open question over which corner gets cut first. A credential system can be cryptographically secure, with strong keys, valid signatures, no obvious hack, and still leak information about a person’s behaviour if the same identifier or attribute is reused across services, letting verifiers link separate transactions to the same individual even without a name attached. The cross-border weak link Because the wallet relies on mutual recognition, a bank or government office in one country must trust identity checks carried out under another country’s enrolment, certification, and security standards. Lohninger doesn’t expect most national systems to be equally robust by the deadline. “Even countries that spend a lot of money on this, like France and Germany, are not ready,” he says. “They will not make it completely to the finish line.” That unevenness is itself a security risk: a system built for 27 mutually trusting implementations is only as strong as its weakest national deployment, slowest incident response, and least rigorous enrolment process. Lohninger’s advice is caution for now. “Let’s wait and not be early adopters here. I want an audit, an independent academic and civil-society investigation into what the governments bring us before we jump on these systems.” Why the stakes are rising The security debate is intensifying as governments across Europe, including France, Denmark, Greece and Austria, push new age-verification laws for social media, with an EU-wide announcement expected soon from Commission President Ursula von der Leyen. The wallet is being positioned as the enforcement tool, pairing a high-value identity system with, as Lohninger puts it, “the most dubious companies that we interact with on a daily basis.” To monitor how the system is used once live, epicenter.works is building an open-data platform called “Who Identifies Me,” designed to let journalists and civil-society groups track which companies and border agencies requests people’s data, a watchdog function Lohninger sees as essential once real security incidents begin. “The public’s trust is really the scarcest resource in all of this,” he says. “We have seen in regions around the world, when these big government digital identity systems are rolled out and they have problems, people run away.”
EU (ORG) Digital (ORG) Europeans (ORG) European (ORG) Thomas Lohninger (PERSON) Austrian (ORG) European Digital Rights (ORG) Lohninger (PERSON) Europe (LOCATION) The European Data Protection Supervisor (ORG)
Originally published by Euronews Read original →