The internet was not originally designed to have an identity layer built-in. Consequently, individuals have very little control over their personal data and there is an uneven distribution of power to the large online platforms. Moreover, identity theft and fraud have become even more prevalent with the rise of AI. Decentralized identity seeks to correct these problems and the European Union with its new eID law or “eIDAS2” regulation is spearheading this change. The new law will effectively require the adoption of decentralized identity and identity wallets throughout Europe, which is one of the biggest trading blocks in the world.
In this post, we’ll take a broad view of eIDAS2 and what it means for governments and enterprises in various industries. Let’s dive in.
eIDAS (electronic Identification, Authentication and Trust Services) law is the EU legal framework adopted to establish a secure and uniform system of electronic transactions and interactions between public and private sector entities across European member states. eIDAS was implemented in July 2016 and guarantees the lawful binding and reliability of electronic identification (eID) and electronic signatures to be recognized across borders. It supports trusted digital identities and electronic signatures and seeks to establish a secure digital domain for enterprises, citizens and public administrations within the EU, as well as enable cross-border online services and e-commerce.
The original eIDAS law faces three main shortfalls:
For the first time ever, a global regulation will mandate digital identity wallets for citizens and organisations, empowering them with exclusive control of their personal data. This game-changing regulation will revolutionise the digital world and is already impacting similar global initiatives, which means it directly affects even non-European organisations.
The main goals are to ensure that citizens and organisations have secure, private and citizen-controlled digital identities, minimizing fraudulent activities and allowing frictionless digital cross-border transactions between public and business sectors. eIDAS2 will:
Why does eIDAS2 matter? The European Parliament approved eIDAS2 on February 29, 2024. Since then, governments and most businesses have been planning and taking actions to adapt to the new regulation.
Both eIDAS2 and decentralized identity use identity wallets, empowering users to take control of their data and centralizing their digital relationships.
From an economical point of view, eIDAS2 will jumpstart the decentralized identity market by forcing member states to offer digital identity credentials and wallets to all citizens and to force the private sector to consume these credentials. This regulation will solve the “cold start problem” for the industry. By creating a framework and legal predictability for massive adoption, identity wallet and credential verification solutions will find a home in the EU and beyond.
Technically, eIDAS2 integrates the same concepts, technologies and standards (e.g. W3C Verifiable Credentials, IETF SD-JWTs, ISO mobile driver’s license, OpenID Connect) used by the decentralized identity industry. In fact, eIDAS2 will force the adoption of mobile digital identity in accordance with global and industry standards.
Stay tuned for part two of our blog post, delving into the effects of eIDAS2 on individuals, businesses and governments.