REGULATORY INSIGHT
The EU Digital Identity Wallet — relying party registration begins on 24 December 2026
A business that wants to receive a user's attributes from an EU Digital Identity Wallet must first be registered as a relying party. Commission Implementing Regulation (EU) 2025/848, which sets out that registration framework, applies from 24 December 2026. That is four months away.
What begins
Implementing Regulation (EU) 2025/848 was adopted on 6 May 2025 and published in the Official Journal on 30 July 2025. Member States are required to establish national registers of wallet relying parties.
A registered business carries the following obligations.
- To be formally registered as a relying party.
- To keep the registered information accurate and up to date.
- To operate only within the purpose and the permissions it has declared.
The third is the one that bites in practice. What you may ask a wallet user for is tied to what you declared at registration. Asking for more attributes than that is treated as a breach.
It reaches businesses outside the EU
If you serve users in the EU and intend to use the wallet for identity or attribute verification, you can fall within the registration requirement wherever your business is established. “We have no entity in the EU” does not settle the question.
The businesses likely to be affected include online services that accept customers in the EU, businesses that need age verification, finance and payments, and cross-border e-commerce. The starting point is simply whether there is any moment at which you ask a user in the EU to prove who they are, or to prove something about themselves.
The registers are built Member State by Member State
Each Member State establishes its own register. If you operate in several countries, there are several registers to consult.
What needs attention here is that the registers will not necessarily be implemented alike. Some Member States may publish the information in machine-readable form and others may not. The handling of registration certificates is not uniform either. When you go to check another party's registration, how easily you can do it will depend on where that party registered.
Is the other party registered, and does the attribute you are asking for fall within what they registered for? How hard that is to establish depends on which country they registered in.
“Refuse when in doubt” does not settle it either
Stopping a transaction whenever verification fails looks like the safe rule. But whether the failure lies with the other party, with the register, or with your own implementation changes what you ought to do about it. Stop everything without distinguishing the cause and you will turn away legitimate users.
Let it through without recording that the check failed, on the other hand, and you keep nothing to answer with if you are later told that you were asking for attributes beyond what you declared.
Worth checking now
- Whether there is any point at which you ask a user in the EU to prove identity or an attribute.
- If there is, whether you have listed the attributes you ask for, and narrowed them to what you actually need.
- Whether you plan to operate in more than one Member State, and if so whose registers you will be consulting.
- Whether you have decided how a failed check is handled, distinguished by cause.
- Whether you can be ready to register before 24 December 2026.
Carry it by hand, or build it in
Checking against the registered scope by hand works where the countries are few and the volume is limited. But in a procedure where the registers differ by country, and where the answer can change depending on when you looked, nothing can be verified afterwards unless the record of each check is complete.
We research and develop technology that carries conformity with regulation as a mechanism rather than as manual routine, and we hold the results as patent applications. We have filed in this area as well.
Whether you fall within the registration requirement, and what to prepare if you do. Four months remain before it applies. This is a good question to bring us before you have answered it — working out whether it applies is our job, not yours.
Get in touchSources
Commission Implementing Regulation (EU) 2025/848 (adopted 6 May 2025, published in the Official Journal 30 July 2025, applies from 24 December 2026)
https://eur-lex.europa.eu/eli/reg_impl/2025/848/oj
Regulation (EU) No 910/2014 (eIDAS Regulation), as amended by Regulation (EU) 2024/1183
European Commission, EU Digital Identity Wallet implementing regulations
https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/
This note reflects publicly available material as of 22 August 2026 and is not legal advice. Please confirm the application to your own circumstances with a qualified adviser.
We follow these rules as they come into force. Updates are available by RSS.