eIDAS is the European Union regulation that decides when an electronic signature counts as a signature, when a digital identity issued in one member state must be accepted in another, and which companies may vouch for either. The acronym stands for electronic identification, authentication and trust services. Its formal name is Regulation (EU) No 910/2014, adopted on 23 July 2014 and applicable since 1 July 2016. It exists because a document signed in Lisbon and a login issued in Helsinki had no guaranteed legal standing elsewhere in the single market.

Two pillars: identity and trust services

The regulation splits into two halves, often conflated.

The first governs electronic identification. Member states may notify their national eID schemes to the Commission, and once a scheme is listed, other member states must accept it for cross-border access to public online services. Article 8 grades schemes at three assurance levels, low, substantial and high, by how rigorously identity was proven and how well the credential resists misuse. Recognition binds only where the notified scheme meets or exceeds the level the receiving authority already requires.

The second governs trust services, the commercial layer. A trust service is an electronic service, normally paid for, that issues or validates the cryptographic artefacts underpinning digital transactions. Article 3(16) now lists fourteen such activities, from issuing certificates to operating electronic ledgers. Non-qualified providers carry baseline risk-management and 24-hour breach-notification duties. Qualified providers submit to audit by a conformity assessment body every 24 months, obtain qualified status from a national supervisory body, and appear on a published national trusted list. Only after that listing may they trade or display the EU trust mark.

Signatures sit in three tiers. A plain electronic signature cannot be denied admissibility in court merely for being electronic. An advanced electronic signature must be uniquely linked to the signatory, capable of identifying them, created under their sole control and tamper-evident. A qualified electronic signature adds a qualified certificate and a certified creation device, and under Article 25(2) carries the legal effect of a handwritten signature across the Union. That tier is not theoretical: submissions under the Commission's draft procedural rules for investigating AI model providers must be signed with a qualified electronic signature.

The wallet, and what it changes

The 2024 amendment bolted a consumer product onto that framework. Regulation (EU) 2024/1183 of 11 April 2024, in force since 20 May 2024, inserted Articles 5a to 5f and created the European Digital Identity Wallet.

Each member state must provide at least one wallet within 24 months of the core implementing acts entering into force, a clock expiring on 24 December 2026. Issuance, use and revocation are free for natural persons. Use is voluntary, and Article 5a(15) forbids making access to services, employment or business disadvantageous for those who decline. Wallets run at assurance level high, and their application software components must be open-source licensed.

A wallet holds two payloads: person identification data issued by or for the state, and electronic attestations of attributes issued by public or private parties. Attributes are the operative unit. A wallet can prove its holder is over 18 without disclosing a birth date, because selective disclosure is a mandated capability rather than a vendor feature. Qualified electronic signatures come free by default, subject to member states limiting that to non-professional use.

The receiving side is where the regulation bites hardest on data businesses. Anyone accepting wallet credentials must register as a relying party in the member state where it is established, declaring in advance which data it intends to request; Article 5b(3) then prohibits requesting anything beyond that declaration. Relying parties must identify themselves before asking, cannot refuse pseudonyms where identification is not legally required, and intermediaries acting for them count as relying parties and may not store transaction content. Article 5a(16) requires the technical framework to prevent attestation issuers or any other party from obtaining data allowing transactions or behaviour to be tracked, linked or correlated without explicit user authorisation. Article 5a(14) separately bars wallet providers from combining identity data with personal data from their other services.

Acceptance becomes compulsory in stages. Public bodies requiring electronic authentication must accept wallets. Private relying parties obliged to use strong user authentication, across transport, energy, banking, financial services, social security, health, digital infrastructure, education and telecommunications, must accept them within 36 months of the same implementing acts; microenterprises and small enterprises are exempt. Very large online platforms designated under Article 33 of the Digital Services Act must accept and facilitate wallet authentication on voluntary user request, limited to the minimum data necessary. Article 12b obliges Digital Markets Act gatekeepers to grant wallet providers free interoperability with operating system, hardware and software features.

Origin and evolution

The lineage runs back to the eSignature Directive 1999/93/EC, repealed by the 2014 regulation. A directive required national transposition and produced divergence; a regulation applies directly, which was the point.

The Commission proposed the overhaul on 3 June 2021, framing it around a wallet that would sit on every phone and handle identity, documents and age verification on websites and platforms. Four large-scale pilots began in 2023. Political agreement came in November 2023, with Parliament adopting the text on 29 February 2024 and the Council on 26 March 2024.

Roughly forty implementing and delegated acts followed, the first published on 4 December 2024. Implementing Regulation (EU) 2025/2527 of 16 December 2025 set reference standards for qualified website authentication certificates, pointing at ETSI EN 319 411-2 and its QNCP-w, QNCP-w-gen and QEVCP-w certificate policies. Implementing Regulation (EU) 2026/798, published on 8 April 2026, covers wallet enrolment.

Why it matters for advertisers and publishers

The commercial significance is not the signature law. It is that a state-issued, cryptographically verifiable attribute layer is being installed across 27 markets just as cookies and device identifiers fail.

Age assurance is the first live use case. The Commission's age verification blueprint, built on wallet specifications, became feature-ready on 15 April 2026, and a recommendation adopted on 29 April 2026 asked member states to deploy by 31 December 2026, though the instrument is non-binding. Reddit began EU age checks on 24 June 2026, switching teen accounts to restrictive defaults and removing ad personalization for accounts aged 13 to 15. Google announced at Money 20/20 Europe on 4 June 2026 that it would carry EU digital IDs and an age credential in Google Wallet, extending a Sparkasse partnership from 1 July 2025 that used zero-knowledge proofs to confirm age without exposing identity.

The standards overlap matters too. The wallet's architecture references the W3C Verifiable Credentials family, which pulls decentralized identifier work into the advertising stack. Consent infrastructure has brushed against the wallet as well: the Council compromise text on the Digital Omnibus contemplated privacy signals carried in a browser or in the wallet before the provision was removed on 18 June 2026.

Limitations and disputes

The longest-running fight concerned Article 45 and qualified website authentication certificates. The 2021 draft would have compelled browsers to trust certificate authorities approved by member states, bypassing the root store programmes they operate. An open letter published on 2 November 2023 by ten organisations including Mozilla, Cloudflare, Fastly and the Linux Foundation warned the provision was likely to weaken internet security generally; a parallel academic letter attracted more than 500 signatories. Parliament inserted Article 45a, which permits browsers to take precautionary measures against specific certificates where security concerns are substantiated. Mozilla treated the 17 December 2025 publication of the implementing act as vindication, though how "substantiated" is read in practice remains untested.

Delivery is the second problem. Analyst assessments through 2026 concluded that a uniform launch on 24 December 2026 is unlikely, with member states clustering into readiness tiers and several offering limited functionality. The obligation is to have one certified wallet notified, not a working cross-border ecosystem.

Dependency is the third. The EU age verification application drew criticism for relying on Google's Android certification infrastructure, which would reject users of alternative Android distributions, an awkward result for a project justified partly by digital sovereignty. Penalties look modest beside adjacent regimes: Article 16(2) sets a floor of EUR 5 million or 1% of worldwide annual turnover for trust service provider infringements, against 4% under the GDPR and 6% under the Digital Services Act.

Adjacent terms

GDPR governs whether personal data may be processed at all. eIDAS governs whether an identity assertion or signature is legally valid; Article 2(4) states it applies without prejudice to the GDPR.

eID refers to a national electronic identity scheme, several of which predate the wallet and continue alongside it.

EUDI Wallet and commercial wallets are distinct. Google Wallet carrying an EU digital ID is a container built by a private company, not a certified European Digital Identity Wallet.

QWACs and TLS certificates overlap but do not coincide. A qualified website authentication certificate attests the legal identity behind a domain. The certificates browsers require for encrypted connections attest control of the domain. Vetting for one does not establish fitness for the other.

Recent developments

The identity verification market is absorbing enforcement risk. Yoti, one of the vendors platforms rely on for age checks, said today that it will pull its Digital ID app from Spanish app stores on 10 September 2026 after a EUR 950,000 fine from the Spanish data protection authority, pending its appeal. The case illustrates what eIDAS is meant to resolve: private verifiers carry compliance risk that state-issued attestations shift elsewhere. Whether wallets displace those vendors or merely add a layer depends on adoption the regulation cannot compel. The Digital Decade target is 80% of citizens using a digital identity solution by 2030.

Timeline

  • 13 December 1999: eSignature Directive 1999/93/EC adopted
  • 23 July 2014: Regulation (EU) No 910/2014 adopted; published in the Official Journal on 28 August 2014
  • 17 September 2014: eIDAS enters into force
  • 1 July 2016: eIDAS becomes applicable; the 1999 directive is repealed
  • 3 June 2021: Commission proposes the European Digital Identity framework
  • 2 November 2023: Ten organisations publish an open letter opposing the Article 45 browser provisions
  • November 2023: Parliament and Council reach political agreement
  • 29 February 2024: European Parliament adopts the amending regulation
  • 26 March 2024: Council adopts the text
  • 11 April 2024: Regulation (EU) 2024/1183 signed; published on 30 April 2024
  • 20 May 2024: Amending regulation enters into force
  • 4 December 2024: First core implementing acts published
  • 1 July 2025: Sparkasse and Google announce wallet-based age verification in Germany
  • 16 December 2025: Implementing Regulation (EU) 2025/2527 sets QWAC reference standards; published 17 December 2025
  • 8 April 2026: Implementing Regulation (EU) 2026/798 on wallet enrolment published
  • 15 April 2026: EU age verification blueprint becomes feature-ready
  • 29 April 2026: Commission recommends member states deploy age verification by 31 December 2026
  • 4 June 2026: Google announces EU digital IDs for Google Wallet at Money 20/20 Europe
  • 24 June 2026: Reddit begins EU age checks
  • 24 December 2026: Deadline for every member state to provide at least one certified wallet
  • December 2027: Deadline for obligated private relying parties to accept wallets
  • 2030: Digital Decade target of 80% of citizens using a digital identity solution

Summary

Who: The European Commission and 27 member states operate the framework. Qualified trust service providers, national supervisory bodies and conformity assessment bodies form the supply side. Relying parties, including banks, telecoms operators, public authorities and very large online platforms, sit on the consuming side.

What: Regulation (EU) No 910/2014, amended by Regulation (EU) 2024/1183, establishing mutual recognition of national electronic identity schemes, a licensing regime for fourteen categories of trust service, three legal tiers of electronic signature, and the European Digital Identity Wallet with selective disclosure, mandatory relying party registration and unlinkability requirements.

When: Adopted 23 July 2014, applicable since 1 July 2016. Amended on 11 April 2024, in force since 20 May 2024. Member states must provide a certified wallet by 24 December 2026, with obligated private relying parties accepting wallets twelve months later.

Where: The European Union, extending to the European Economic Area on a later timetable. Trust services from third countries can be recognised through implementing acts or international agreements.

Why: Cross-border electronic transactions lacked a common legal basis, leaving signatures and identity credentials valid in one state and worthless in another. The 2024 amendment added a further objective: giving citizens a state-backed identity layer that does not depend on private platform accounts, and giving them selective disclosure so that proving one attribute does not require surrendering all of them.