Privacy vs Progress: July 2025 Digital Identity Developments Across Europe

July 2025 delivered critical digital identity milestones across Europe and the UK, from EUDI Wallet cross-border demonstrations to Online Safety Act enforcement. This post examines the regulatory developments, privacy concerns, and technical readiness challenges that will shape enterprise digital identity strategies through 2026. Essential reading for organizations preparing for eIDAS 2.0 compliance and the UK Digital Identity Wallet acceptance.
Published on
August 6, 2025

July 2025 marked a critical juncture for digital identity across Europe and the UK. As the EU races toward its 2026 EUDI Wallet deployment deadline and the UK enforces new Online Safety Act requirements, both regions achieved significant technical milestones while confronting implementation challenges that will shape the future of digital credentials.

This post examines the key developments from both sides of the Channel, their implications for enterprises, and what they mean for the broader digital identity landscape.

EU Digital Identity: Technical Progress Meets Privacy Concerns

Cross-Border Capabilities Take Center Stage

The POTENTIAL consortium's demonstration at the Global Digital Collaboration Conference showcased real-world EUDI Wallet implementations across six critical sectors - banking, telecommunications, healthcare, digital signatures, and prescriptions. This wasn't just another proof of concept; it demonstrated actual cross-border functionality that enterprises will need to support within 18 months.

For organizations preparing for EUDI compliance, this demonstration proves the technical feasibility of multi-sector, cross-border digital identity operations. However, it also highlights the complexity of implementation across diverse regulatory environments.

Privacy-Preserving Age Verification: A Double-Edged Development

The European Commission's age verification blueprint represents both progress and concern. The "mini wallet" solution, developed by the T-Scy consortium, allows users to prove they're over 18 without revealing personal information - a significant step toward privacy-preserving verification.

However, privacy advocates raised serious red flags about the implementation. Denis Roio from Dyne.org Foundation published a detailed critique highlighting insufficient "sandboxing" of zero-knowledge proof components and warnings that mobile operating system APIs could enable surveillance of credential presentations.

At Vidos, we believe privacy preservation must remain a first-class pillar throughout digital identity implementation. These concerns underscore why enterprises need verification solutions that prioritize cryptographic security and process isolation - core principles built into our verification infrastructure.

Member State Implementation Disparities

July revealed stark differences in EU member state readiness:

  • Italy leads with 11.8 million active users on its IO App and 5.2 million wallet activations since December 2024
  • Germany struggles with only 35% of adults having activated their eID function, planning gradual rollout by 2027
  • Nine countries have digital ID wallets in production
  • Four countries (Bulgaria, Croatia, Malta, Romania) haven't started development

This disparity raises serious questions about meeting the 2026 deadline while maintaining interoperability standards across all member states.

Regulatory Framework Expansion

The adoption of seven new implementing regulations in late July formalized crucial technical specifications, enabling Member States to develop secure, privacy-enhancing, interoperable wallets. These regulations establish common technical standards for uniform implementation across the EU.

For enterprises operating across borders, this standardization is essential. However, the ongoing disputes between major member states (Germany, France, Netherlands, and Spain) and the European Commission over privacy and interoperability requirements could delay implementation timelines.

UK Digital Identity: Framework Maturation and Enforcement Reality

DIATF Gamma Framework Implementation

The UK Digital Identity and Attributes Trust Framework Gamma (0.4) came into force on July 1, representing a significant maturation of the UK's certification approach. The framework introduces:

  • Component service certification for specialized services like biometric liveness detection
  • Enhanced accessibility requirements addressing inclusion concerns
  • Modular certification pathways that reduce costs and implementation time

This modular approach addresses a key challenge we've observed in enterprise implementations - the ability to certify individual components rather than entire systems reduces complexity and accelerates deployment.

Online Safety Act Enforcement Begins

"AV Day" on July 25 marked the beginning of full enforcement of age verification requirements under the Online Safety Act. With penalties reaching £18 million or 10% of global turnover, platforms scrambled to implement approved verification methods including:

  • Facial age estimation
  • Open banking verification  
  • Digital ID services and wallets
  • Credit card age checks
  • Mobile network operator verification

The enforcement deadline created immediate demand for reliable age verification solutions, highlighting how regulatory requirements drive digital identity adoption.

Market Maturation and Inclusion Progress

The Digital Identity Inclusion Monitoring Report 2025 revealed measurable improvements:

  • 60% of services now meet WCAG 2.0 (AA) accessibility standards (up from 54%)
  • 73% offer accessibility features (up from 65%)
  • 40% provide services in more than 5 languages (up from 33%)

These statistics demonstrate the UK market's growing maturity and commitment to inclusive design - essential factors for widespread adoption.

The UK digital identity sector now generates £2.1 billion in revenue with projections reaching £4 billion by 2030, supported by 266 firms employing over 10,000 people.

Enterprise Implications and Technical Readiness

Infrastructure Complexity Challenges

Both regions face architecture complexity issues in early interoperability testing. The multi-layered systems required for secure, privacy-preserving digital identity create integration challenges for enterprises.

Device compatibility remains problematic, with Secure Element technology available on only 50-60% of devices. This requires alternative security approaches for the majority of users - a critical consideration for enterprise deployment strategies.

Regulatory Compliance Requirements

The convergence of eIDAS 2.0 preparation, UK DIATF certification, and cross-border interoperability requirements creates a complex compliance landscape for enterprises. Organizations need verification solutions that can adapt to evolving regulatory requirements while maintaining security standards.

Our experience working with enterprises on compliance readiness shows that organizations benefit from verification infrastructure that supports multiple credential formats and standards - exactly the kind of interoperability challenge our Universal Resolver and Verifier services were designed to address.

Security and Standards Evolution

The month highlighted ongoing tension between regulatory enforcement objectives and privacy-first principles. As we've enhanced our own security posture - completing our ISO 27001 surveillance audit with no nonconformities in July - we recognize that enterprise-grade security requires continuous vigilance and improvement.

Looking Ahead: Key Considerations for Enterprise Leaders

Preparation Priorities

  1. Multi-standard support: Ensure your verification infrastructure can handle diverse credential formats and evolving standards
  2. Cross-border compatibility: Plan for EU-UK interoperability requirements in your digital identity strategy  
  3. Privacy-first architecture: Implement verification solutions with built-in privacy protections and process isolation
  4. Accessibility compliance: Design inclusive systems that meet evolving accessibility requirements

Implementation Readiness

The technical demonstrations in July prove that cross-border, multi-sector digital identity verification is achievable. However, the privacy concerns raised and implementation disparities revealed show that success requires careful attention to security architecture and standards compliance.

Organizations that begin preparing now - with the right technical infrastructure and compliance frameworks - will be best positioned to capitalize on the digital identity transformation accelerating across Europe and the UK.

Ready to Navigate the Digital Identity Landscape?

The developments in July 2025 demonstrate both the promise and complexity of implementing secure, privacy-preserving digital identity at scale. As regulatory requirements evolve and technical standards mature, enterprises need verification partners who understand both the technical challenges and compliance requirements.

Vidos provides the enterprise-grade infrastructure and expertise to help organizations navigate this complex landscape. Our standards-based approach supports the diverse credential formats and regulatory requirements emerging across Europe and the UK.

Ready to discuss your digital identity compliance strategy? Contact our team to learn how our verification infrastructure can support your organization's digital transformation while meeting evolving regulatory requirements.

Weekly newsletter
No spam. Just the latest releases, interesting articles, and exclusive developments in the world of Digital Identity delivered to your inbox.

Want to learn more?
Download our guide:

Dashboard mockup