Sittings · Compare
What changed
SHORT JUSTIFICATION
With this draft opinion, several concerns with regard to the Commission proposal are raised, particularly for addressing the data protection and privacy aspects, which fall in the remit of the Committee on Civil Liberties, Justice and Home Affairs (LIBE). Some of these concerns were already shared by the European Data Protection Supervisor, as well as by the stakeholders consulted during the preparation of the draft opinion. The rapporteur for opinion would like to highlight them, based on the written inputs received from different experts in the field.
The current proposal is of very technical nature and it touches upon critical aspects of fundamental rights, such as data protection and privacy. If the Parliament fails to come up with a coherent framework and a technically proof piece of legislation, the citizens will lose any control over their private data, which will become a commodity. Unfortunately, the technical options for the implementation of the proposal are to be adopted by the Commission via subsequent, non-legislative acts. This is a dangerous approach, as one technical option might be more intrusive than another, at the expense of the fundamental rights of the citizens.
More specific concerns could be raised regarding the unclear relation between eIDAS and GDPR; the respect of core data protection elements, such as data minimisation and selective disclosure; privacy by design and the use of unique identifiers; the lack of openness and transparency in developing the eIDAS Wallet security specifications and of the involvement of civil society or academics; dependence on big tech companies; the weakening of browser security.
Through the proposed amendments, the LIBE rapporteur for opinion aims at correcting the issues mentioned above, which fall under the competence of LIBE. To protect the privacy of individuals and not deter the privacy standard for users of the European Digital Identity Wallet, the rapporteur of opinion takes into consideration the fact that the use of pseudonyms has to be an option in all cases where full identification is not legally mandated. Moreover, references to the relationship between eIDAS and the European Data Protection Legislation back to the existing 2014 level of protections are reinserted.
The need for unlinkability and non-traceability has been broadly acknowledged by experts in the field. User transactions reveal large amounts of data, including data of highly personal nature, such as information of the individuals’ economic situation or information about the medical situation, travel history, consumption patterns and social interactions of citizens. Therefore, the architecture that is being considered should protect this data about a wide-range of online and offline user behaviour from centralised surveillance.
Last but not least, a unique, persistent identifier for natural persons would in some Member States be illegal or even unconstitutional (e.g. in Germany, the use of unique persistent identifiers is prohibited under the Census Act Ruling of 1983). The risk of a unique, life-long identifier cannot be deemed the least intrusive method for the purpose of uniquely identifying an individual. Article 11a is also not needed, as the existing interoperability framework of identification schemes according to the original Article 12 (4) (d) already entails a unique representation of an individual for cross-border cases and therefore it was proposed for deletion.
Nevertheless, the proposal has many loopholes outside of LIBE committee remit, which is why, in order to safeguard the Europeans’ fundamental rights, the entire proposal should be sent back to the Commission for a complete redesign. As this proposal is envisioned, it would lead to the Chinafication of Europe, allowing for the creation of a like social-credit system that would determine the mass surveillance and control of all Europeans, which must not be accepted. EU was envisioned as an “area of freedom” and efforts must be continued to keep it as such.
AMENDMENTS
The Committee on LegalCivil Liberties, Justice and Home Affairs calls on the Committee on Industry, Research and Energy, as the committee responsible, to take into account the following amendments:
Amendment 1
Proposal for a regulation
Recital 16
Or. en
Amendment 2
Proposal for a regulation
Recital 4
Amendment 3
Proposal for a regulation
Recital 7
Amendment 4
Proposal for a regulation
Recital 9
Amendment 5
Proposal for a regulation
Recital 10
Amendment 6
Proposal for a regulation
Recital 11
Amendment 7
Or. en
Proposal for a regulation
Recital 12
Amendment 8
Proposal for a regulation
Recital 17
Amendment 9
Proposal for a regulation
Recital 18
Amendment 10
Proposal for a regulation
Recital 18 a (new)
Amendment 11
Proposal for a regulation
Recital 20
Amendment 12
Proposal for a regulation
Recital 21
Amendment 13
Proposal for a regulation
Recital 26
Amendment 14
Proposal for a regulation
Recital 27
Amendment 15
Proposal for a regulation
Recital 28
Amendment 16
Proposal for a regulation
Recital 32
Justification
(linked to deletion of amendment to Article 45)Out of scope - archiving has nothing to do with identification. There is no EU harmonisation on safe deposit boxes either.
In order to ensure that users are in control of their data in the European Digital Identity Wallets, the envisaged system should not depend on a cloud-based infrastructure.
Amendment 173
Proposal for a regulation
Recital 36
Amendment 18
Proposal for a regulation
Recital 37
Amendment 19
Proposal for a regulation
Article 1 – paragraph 1 – point 1
Regulation (EU) No 910/2014
Article 1 – paragraph 1 – introductory part
Amendment 20
Proposal for a regulation
Article 1 – paragraph 1 – point 2 – point a
Regulation (EU) No 910/2014
Article 2 – paragraph 1
Amendment 21
Proposal for a regulation
Article 1 – paragraph 1 – point 2 – point b
Regulation (EU) No 910/2014
Article 2 – paragraph 3
Amendment 22
Proposal for a regulation
Article 1 – paragraph 1 – point 2 – point b
Regulation (EU) No 910/2014
Article 2 – paragraph 3 – point a (new)
Amendment 23
Proposal for a regulation
Article 1 – paragraph 1 – point 2 – point b
Regulation (EU) No 910/2014
Article 2 – paragraph 3 – point b (new)
Amendment 24
Proposal for a regulation
Article 1 – paragraph 1 – point 3 – point a
Regulation (EU) No 910/2014
Article 3 – paragraph 1 – point 2
Amendment 25
Proposal for a regulation
Article 1 – paragraph 1 – point 3 – point g
Regulation (EU) No 910/2014
Article 3 – paragraph 1 – point 29
Amendment 26
Proposal for a regulation
Article 1 – paragraph 1 – point 3 – point i
Regulation (EU) No 910/2014
Article 3 – paragraph 1 – point 42
Amendment 27
Proposal for a regulation
Article 1 – paragraph 1 – point 3 – point i
Recital 29
Regulation (EU) No 910/2014
Or. en
Article 3 – paragraph 1 – point 46
Justification
Amendment 28
Essential functions of the Wallet have to be implemented in a privacy-preserving manner as to limit the potential for automated tracking of the user in cases where they are choosing to cancel an already initiated information sharing request from a relying party, only choosing to selectively disclose individual attributes about them (e.g. age verification in a liquor store) or using the Wallet to log into a service without being subsequently tracked by them. The last feature is offered by Apple’s “Sign in with Apple” functionality, which the wallet seeks to replace.
Amendment 4
Proposal for a regulation
Article 3 – paragraph 1 – point 47
Amendment 29
Or. en
Proposal for a regulation
Amendment 5
Article 1 – paragraph 1 – point 3 – point i
Regulation (EU) No 910/2014
Article 3 – paragraph 1 – point 55
Amendment 30
Proposal for a regulation
Article 1 – paragraph 1 – point 3 – point i
Regulation (EU) No 910/2014
Article 3 – paragraph 1 – point 55 a (new)
Amendment 31
Proposal for a regulation
Article 1 – paragraph 1 – point 3 – point i
Regulation (EU) No 910/2014
Article 3 – paragraph 1 – point 55 b (new)
Amendment 32
Proposal for a regulation
Article 1 – paragraph 1 – point 4
Regulation (EU) No 910/2014
Article 5 – title
Amendment 33
Proposal for a regulation
Article 1 – paragraph 1 – point 4
Regulation (EU) No 910/2014
Article 5 – paragraph -1 (new)
Amendment 34
Proposal for a regulation
Article 5 – paragraph 1
Amendment 35
Or. en
Proposal for a regulation
Justification
Article 1 – paragraph 1 – point 7
To protect the privacy of individuals and not deter the privacy standard for users of the European Digital Identity Wallet, the use of pseudonyms has to be an option in all cases where full identification is not legally mandated. Restore references to the relationship between eIDAS and the European Data Protection Legislation back to the existing 2014 level of protections. The original eIDAS Regulation offered a higher standard of data protection than afforded by Directive 95/46/EC by mandating the facilitation of privacy by design in Article 12(3)(c).
Regulation (EU) No 910/2014
Amendment 6
Article 6a – paragraph 3 – introductory part
Amendment 36
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 3 – point a
Amendment 37
Proposal for a regulation
Regulation (EU) No 910/2014
Article 6a – paragraph 34 – point a – point 2 a (new)
Amendment 38
Or. en
Justification
The Common Interface should include this safeguard to prevent unapproved or unidentified relying parties to request information exceeding their use case. The eIDAS expert group organised by the European Commission acknowledged the need of “sharing policies” that restrict what information a relying party can ask from the user and prevent excessive information requests (See chapter 4.6.1 and footnote 22 of the final Outline from February 17th 2022).
Amendment 7
Proposal for a regulation
Regulation (EU) No 910/2014
Article 6a – paragraph 34 – point a – point 2 b (new)
Amendment 39
Or. en
Justification
The Common Interface should ensure that proxies acting as intermediaries between relying parties and users of the European Digital Identity Wallet cannot have access to the content of the transaction they convey. Such technical protections are commonplace and don’t limit the functioning of the system. The existence of such proxies has been acknowledged in the eIDAS Expert Group (See chapter 4.8.3 of the final Outline from February 17th 2022).
Amendment 8
Proposal for a regulation
Regulation (EU) No 910/2014
Article 6a – paragraph 4 – point da – point 3
Amendment 40
Or. en
Justification
The success of the European Digital Identity Wallet depends on citizens making informed decisions on the information they share with relying parties. Similar guidance about mandatory information on the purpose of the processing by the relying party, as well as the possibility of the use to refuse information requests has been given by the eIDAS Expert Group that is currently developing the Toolbox. (see chapter 4.6.1 of the final Outline from February 17th 2022).
Amendment 9
Proposal for a regulation
Regulation (EU) No 910/2014
Article 6a – paragraph 4 – point d a (new)b
Amendment 41
Or. en
Justification
This amendment extends the safeguards to protect user behaviour from being tacked. Examples of providers of non-qualified attribute attestation are private companies, membership clubs or universities. With this change in the text an existing technical safeguard of the European Digital Identity Wallet is simply extended to more stakeholders.
Amendment 10
Proposal for a regulation
Article 6a – paragraph 4 – point e
Amendment 42
Or. en
Proposal for a regulation
Justification
Article 1 – paragraph 1 – point 7
The need for unlinkability and non-traceability was acknowledged by the eIDAS Expert Group (see page 26 in chapter 5 of the final Outline from February 17th 2022. User transactions will reveal large amounts of data, including data of highly personal nature, such as information of the individuals' economic situation or information about the medical situation, travel history, consumption patterns and social interactions of citizens.
Regulation (EU) No 910/2014
Amendment 11
Article 6a – paragraph 4 – point e a (new)
Amendment 43
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 4 – point e b (new)
Amendment 44
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 4 – point e c(new)
Amendment 45
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 6
Amendment 46
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 6 a (new)
Amendment 47
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 7 a (new)
Amendment 48
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 10 a (new)
Amendment 49
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 11
Amendment 50
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6b – pargraph 1
Amendment 51
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6b – pargraph 2
Amendment 52
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6b – pargraph 4
Amendment 53
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6c – paragraph 4
Amendment 54
Proposal for a regulation
Regulation (EU) No 910/2014
Article 6d6a – paragraph 37
Amendment 55
Or. en
Proposal for a regulation
Justification
Article 1 – paragraph 1 – point 8
Only an architecture that protects data like the medical situation, travel history, consumption patterns and social interactions of citizens which goes about a wide-range of online and offline user behaviour from centralised surveillance is an electronic identity system deserving citizens' trust. The issuer is the controller as it determines the means of processing of personal data by determining the concrete system, i.e. the means of processing, irrespective whether that system is executed or not on a device under their control (see C-40/17 and C-25/17).
Regulation (EU) No 910/2014
Amendment 12
Section 2 – title
Amendment 56
Proposal for a regulation
Article 1 – paragraph 1 – point 9
Regulation (EU) No 910/2014
Article 7 – paragraph 1 – introductory part
Amendment 57
Proposal for a regulation
Article 1 – paragraph 1 – point 9
Regulation (EU) No 910/2014
Article 7 – pargraph 1 a (new)
Amendment 58
Proposal for a regulation
Article 1 – paragraph 1 – point 10
Regulation (EU) No 910/2014
Article 9 – paragraph 3
Amendment 59
Proposal for a regulation
Article 1 – paragraph 1 – point 11
Regulation (EU) No 910/2014
Article 10a – paragraph 5
Amendment 60
Proposal for a regulation
Article 1 – paragraph 1 – point 12
Regulation (EU) No 910/2014
Article 11a – title
Amendment 61
Proposal for a regulation
Article 1 – paragraph 1 – point 12
Regulation (EU) No 910/2014
Article 11a – paragraph 1
Amendment 62
Proposal for a regulation
Article 1 – paragraph 1 – point 12
Regulation (EU) No 910/2014
Article 11a – paragraph 2
Amendment 63
Proposal for a regulation
Article 1 – paragraph 1 – point 12
Regulation (EU) No 910/2014
Article 11a – paragraph 2 a (new)
Amendment 64
Proposal for a regulation
Regulation (EU) No 910/2014
Article 11a – paragraph 3
Amendment 65
Or. en
Justification
A unique, persistent identifier for natural persons would in some Member States be illegal or even unconstitutional (In Germany, the use of unique persistent identifiers is prohibited under the Census Act Ruling of 1983. The risk of a unique, life-long identifier cannot be deemed the least intrusive method for the purpose of uniquely identifying an individual. Article 11a is also not needed as the existing interoperability framework of identification schemes according to the original Article 12 (4) (d) already entails a unique representation of an individual for cross-border cases.
Amendment 13
Proposal for a regulation
Article 12 – paragraph 4 – point d
Amendment 66
Or. en
Proposal for a regulation
Justification
Article 1 – paragraph 1 – point 13 – point c
The Commission proposal would require a unique and persistent identification independent from a particular electronic identification scheme. In effect, this seemingly technical change of the interoperability framework would have the same effect as Article 11a.
Regulation (EU) No 910/2014
Amendment 14
Article 12 – paragraph 6 – point a
Amendment 67
Proposal for a regulation
Article 1 – paragraph 1 – point 16
Regulation (EU) No 910/2014
Article 12b – paragraph 2
Amendment 68
Proposal for a regulation
Article 1 – paragraph 1 – point 16
Regulation (EU) No 910/2014
Article 12b – paragraph 3
Amendment 69
Proposal for a regulation
Article 1 – paragraph 1 – point 16
Regulation (EU) No 910/2014
Article 12b – paragraph 5
Amendment 70
Proposal for a regulation
Article 1 – paragraph 1 – point 16
Regulation (EU) No 910/2014
Article 12b – paragraph 6
Amendment 71
Proposal for a regulation
Article 1 – paragraph 1 – point 20 – point c
Regulation (EU) No 910/2014
Article 17 – paragraph 8
Amendment 72
Proposal for a regulation
Article 1 – paragraph 1 – point 20 – point c
Regulation (EU) No 910/2014
Article 17 – paragraph 8 a (new)
Amendment 73
Proposal for a regulation
Article 1 – paragraph 1 – point 21 – point b
Regulation (EU) No 910/2014
Article 18 – paragraph 1
Amendment 74
Proposal for a regulation
Article 1 – paragraph 1 – point 21 – point c
Regulation (EU) No 910/2014
Article 18 – paragraph 5
Amendment 75
Proposal for a regulation
Article 1 – paragraph 1 – point 22 – point c
Regulation (EU) No 910/2014
Article 20 – paragraph 3 – subparagraph 2
Amendment 76
Proposal for a regulation
Article 1 – paragraph 1 – point 22 – point c
Regulation (EU) No 910/2014
Article 20 – paragraph 3 – subparagraph 2 a (new)
Amendment 77
Proposal for a regulation
Article 1 – paragraph 1 – point 23 – point a
Regulation (EU) No 910/2014
Article 21 – paragraph 2 – subparagraph 3
Amendment 78
Proposal for a regulation
Article 1 – paragraph 1 – point 25 – point a a (new)
Regulation (EU) No 910/2014
Article 24 – paragraph 1 a (new)
Amendment 79
Proposal for a regulation
Article 1 – paragraph 1 – point 25 – point b – introductory part
Regulation (EU) No 910/2014
Article 24 – paragraph 1a
Amendment 80
Proposal for a regulation
Article 1 – paragraph 1 – point 25 – point b
Regulation (EU) No 910/2014
Article 24 – paragraph 1a
Amendment 81
Proposal for a regulation
Article 1 – paragraph 1 – point 25 – point e
Regulation (EU) No 910/2014
Article 24 – paragraph 5
Amendment 82
Proposal for a regulation
Article 1 – paragraph 1 – point 25 – point e a (new)
Regulation (EU) No 910/2014
Article 24 – paragraph 5 a (new)
Amendment 83
Proposal for a regulation
Article 1 – paragraph 1 – point 25 – point f
Regulation (EU) No 910/2014
Article 24 – paragraph 6
Amendment 84
Proposal for a regulation
Article 1 – paragraph 1 – point 27
Regulation (EU) No 910/2014
Article 29 – paragraph 1 a
Amendment 85
Proposal for a regulation
Article 1 – paragraph 1 – point 28
Regulation (EU) No 910/2014
Article 29a – paragraph 1 a (new)
Amendment 86
Proposal for a regulation
Article 1 – paragraph 1 – point 28
Regulation (EU) No 910/2014
Article 29a – paragraph 2
Amendment 87
Proposal for a regulation
Article 1 – paragraph 1 – point 38
Regulation (EU) No 910/2014
Article 45
Amendment 88
Proposal for a regulation
Article 1 – paragraph 1 – point 39
Regulation (EU) No 910/2014
Article 45a – paragraph 1
Amendment 89
Proposal for a regulation
Article 1 – paragraph 1 – point 39
Regulation (EU) No 910/2014
Article 45a – paragraph 2
Amendment 90
Proposal for a regulation
Article 1 – paragraph 1 – point 39
Regulation (EU) No 910/2014
Article 45c – paragraph 3 a (new)
Amendment 91
Proposal for a regulation
Article 1 – paragraph 1 – point 39
Regulation (EU) No 910/2014
Article 45c – paragraph 4
Amendment 92
Proposal for a regulation
Article 1 – paragraph 1 – point 3922 – point b
Regulation (EU) No 910/2014
Article 45d20 – paragraph 1 a (new)2
Amendment 93
Or. en
Justification
According to Article 33 and 34 of the GDPR the controller has certain duties in case of a data breach. To fulfill these duties, they should be informed about a potential data breach in their system.
Amendment 15
Proposal for a regulation
Article 1 – paragraph 1 – point 3922 – point b
Regulation (EU) No 910/2014
Article 45d20 – paragraph 2 – subparagraph 1 a (new)
Amendment 94
Or. en
Amendment 16
Proposal for a regulation
Article 1 – paragraph 1 – point 3925 a– (new)point c – point 2
Regulation (EU) No 910/2014
Article 47
Article 24 – paragraph 2 – point fb a (new)
Amendment 95
Or. en
Proposal for a regulation
ANNEX: LIST OF ENTITIES OR PERSONS FROM WHOM THE RAPPORTEUR HAS RECEIVED INPUT
Annex V – paragraph 1 – introductory part
The following list is drawn up on a purely voluntary basis under the exclusive responsibility of the rapporteur. The rapporteur has received input from the following entities or persons in the preparation of the draft opinion:
Amendment 96
1. European Commission DG CNECT
Proposal for a regulation
2. The European Data Protection Supervisor
Annex V – paragraph 1 – point a
3. Brussels Privacy Hub, THE EUROPEAN COMMISSION PROPOSAL AMENDING THE eIDAS REGULATION (EU) No 910/2014: A PERSONAL DATA PROTECTION PERSPECTIVE
Amendment 97
4. Professor Ricardo Genghini, Chairman of the European Standardization Committee E-Signature and Infrastructures (ESI) within the European Telecommunications Standards Institute (ETSI) - Notes on the current draft of eIDAS Revision Proposal
Proposal for a regulation
5. epicenter.works & European Digital Rights (EDRI)
Annex V – paragraph 1 – point a a (new)
6. Luukas Ilves, Deputy Secretary General of the Estonian Ministry of Economic Affairs and Communications for Digital Development
Amendment 98
7. European Consumer Organisation (BEUC) - Making European Digital Identity as Safe as It Is needed - BEUC Position Paper
Proposal for a regulation
8. Jaap-Henk Hoepman, Associate Professor of privacy enhancing protocols and privacy by design in the Digital Security group at the Institute for Computing and Information Sciences of the Radboud University Nijmegen, Civil liberties aspects of the commission proposal to amend the eIDAS regulation
Annex V – paragraph 1 – point b – introductory part
9. Eric Verheul, professor in the Digital Security Group of the Radboud University Nijmegen - Issues and recommendations on the eIDAS wallet as proposed in the eIDAS update
Amendment 99
10. Manuel Atug expert in IT Security and engineering Chaos Computer Club & Christian Kahlo eID expert - written input
Proposal for a regulation
11. Lukasz Olejnik, PhD, https://lukaszolejnik.com, written contribution
Annex V – paragraph 1 – point c
12. Carmela Troncoso - Professor on Security and Privacy at Swiss Federal Institute of Technology Lausanne - written input
Amendment 100
13. Dr. F. S. Gürses, Associat Professor at the Faculty of Technology, Policy and Management, TU Delft - written input
Proposal for a regulation
14. Eurosmart - The Voice Of The Digital Security Industry - Feedback on the revision of eIDAS
Annex V – paragraph 1 – point d
15. Mozzila
Amendment 101
16. Google
Proposal for a regulation
17. Apple
Annex V – paragraph 1 – point e
18. The International Association for Trusted Blockchain Applications (INATBA) - Establishing a Framework for a European Digital Identity (eIDAS) - Policy Position
Amendment 102
19. TWG Trusted Information of the EU Observatory for ICT Standardisation - report on “Trust in the European digital space in the age of automated bots and fakes”
Proposal for a regulation
20. Rule of Law Defense Coalition, Bucharest Romania
Annex V – paragraph 1 – point f
21. American Chamber of Commerce to the European Union, Brussels - written input
Amendment 103
Proposal for a regulation
Annex V – paragraph 1 – point g
Amendment 104
Proposal for a regulation
Annex V – paragraph 1 – point h
Amendment 105
Proposal for a regulation
Annex V – paragraph 1 – point h a (new)
Amendment 106
Proposal for a regulation
Annex V – paragraph 1 – point h b (new)
Amendment 107
Proposal for a regulation
Annex VI – paragraph 1 – point 2
Justification
Date of birth is more useful information than age.
Amendment 108
Proposal for a regulation
Annex VI – paragraph 1 – point 10 a (new)
PROCEDURE – COMMITTEE ASKED FOR OPINION
FINAL VOTE BY ROLL CALL IN COMMITTEE ASKED FOR OPINION