Sittings · Compare

What changed

From · opinion parliamentary committee draft · 2022-05-19 LIBE-PA-732601 on the proposal for a regulation of the European Parliament and of the Council Amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
To · Adopted text · 2024-02-29 TA-9-2024-0117 European Digital Identity Framework
+32 added · −147 removed · 0 modified paragraphs

SHORT JUSTIFICATION

P9_TA(2024)0117

With this draft opinion, several concerns with regard to the Commission proposal are raised, particularly for addressing the data protection and privacy aspects, which fall in the remit of the Committee on Civil Liberties, Justice and Home Affairs (LIBE). Some of these concerns were already shared by the European Data Protection Supervisor, as well as by the stakeholders consulted during the preparation of the draft opinion. The rapporteur for opinion would like to highlight them, based on the written inputs received from different experts in the field.

European Digital Identity Framework

The current proposal is of very technical nature and it touches upon critical aspects of fundamental rights, such as data protection and privacy. If the Parliament fails to come up with a coherent framework and a technically proof piece of legislation, the citizens will lose any control over their private data, which will become a commodity. Unfortunately, the technical options for the implementation of the proposal are to be adopted by the Commission via subsequent, non-legislative acts. This is a dangerous approach, as one technical option might be more intrusive than another, at the expense of the fundamental rights of the citizens.

Committee on Industry, Research and Energy

More specific concerns could be raised regarding the unclear relation between eIDAS and GDPR; the respect of core data protection elements, such as data minimisation and selective disclosure; privacy by design and the use of unique identifiers; the lack of openness and transparency in developing the eIDAS Wallet security specifications and of the involvement of civil society or academics; dependence on big tech companies; the weakening of browser security.

PE732.707

Through the proposed amendments, the LIBE rapporteur for opinion aims at correcting the issues mentioned above, which fall under the competence of LIBE. To protect the privacy of individuals and not deter the privacy standard for users of the European Digital Identity Wallet, the rapporteur of opinion takes into consideration the fact that the use of pseudonyms has to be an option in all cases where full identification is not legally mandated. Moreover, references to the relationship between eIDAS and the European Data Protection Legislation back to the existing 2014 level of protections are reinserted.

European Parliament legislative resolution of 29 February 2024 on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity (COM(2021)0281 – C9-0200/2021 – 2021/0136(COD))

The need for unlinkability and non-traceability has been broadly acknowledged by experts in the field. User transactions reveal large amounts of data, including data of highly personal nature, such as information of the individuals’ economic situation or information about the medical situation, travel history, consumption patterns and social interactions of citizens. Therefore, the architecture that is being considered should protect this data about a wide-range of online and offline user behaviour from centralised surveillance.

(Ordinary legislative procedure: first reading)

Last but not least, a unique, persistent identifier for natural persons would in some Member States be illegal or even unconstitutional (e.g. in Germany, the use of unique persistent identifiers is prohibited under the Census Act Ruling of 1983). The risk of a unique, life-long identifier cannot be deemed the least intrusive method for the purpose of uniquely identifying an individual. Article 11a is also not needed, as the existing interoperability framework of identification schemes according to the original Article 12 (4) (d) already entails a unique representation of an individual for cross-border cases and therefore it was proposed for deletion.

The European Parliament,

Nevertheless, the proposal has many loopholes outside of LIBE committee remit, which is why, in order to safeguard the Europeans’ fundamental rights, the entire proposal should be sent back to the Commission for a complete redesign. As this proposal is envisioned, it would lead to the Chinafication of Europe, allowing for the creation of a like social-credit system that would determine the mass surveillance and control of all Europeans, which must not be accepted. EU was envisioned as an “area of freedom” and efforts must be continued to keep it as such.

– having regard to the Commission proposal to Parliament and the Council (COM(2021)0281),

AMENDMENTS

– having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90200/2021),

The Committee on Civil Liberties, Justice and Home Affairs calls on the Committee on Industry, Research and Energy, as the committee responsible, to take into account the following amendments:

– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

Amendment 1

– having regard to the opinion of the European Economic and Social Committee of 20 October 2021,

Proposal for a regulation

– having regard to the opinion of the Committee of the Regions of 13 October 2021,

Recital 6

– having regard to the provisional agreement approved by the responsible committee under Rule 74(4) of its Rules of Procedure and the undertaking given by the Council representative by letter of 6 December 2023 to approve Parliament’s position, in accordance with Article 294(4) of the Treaty on the Functioning of the European Union,

Or. en

– having regard to Rule 59 of its Rules of Procedure,

Amendment 2

– having regard to the opinions of the Committee on the Internal Market and Consumer Protection, the Committee on Legal Affairs and the Committee on Civil Liberties, Justice and Home Affairs,

Proposal for a regulation

– having regard to the report of the Committee on Industry, Research and Energy (A9-0038/2023),

Recital 11

1. Adopts its position at first reading hereinafter set out;

Or. en

2. Takes note of the statements by the Commission annexed to this resolution;

Justification

3. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

In order to ensure that users are in control of their data in the European Digital Identity Wallets, the envisaged system should not depend on a cloud-based infrastructure.

4. Instructs its President to forward its position to the Council, the Commission and the national parliaments.

Amendment 3

P9_TC1-COD(2021)0136

Proposal for a regulation

Position of the European Parliament adopted at first reading on 29 February 2024 with a view to the adoption of Regulation (EU) 2024/… of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework

Recital 29

(As an agreement was reached between Parliament and Council, Parliament's position corresponds to the final legislative act, Regulation (EU) 2024/1183.)

Or. en

ANNEX TO THE LEGISLATIVE RESOLUTION

Justification

Statement by the Commission on Article 45 on the occasion of the adoption of Regulation (EU) 2024/1183

Essential functions of the Wallet have to be implemented in a privacy-preserving manner as to limit the potential for automated tracking of the user in cases where they are choosing to cancel an already initiated information sharing request from a relying party, only choosing to selectively disclose individual attributes about them (e.g. age verification in a liquor store) or using the Wallet to log into a service without being subsequently tracked by them. The last feature is offered by Apple’s “Sign in with Apple” functionality, which the wallet seeks to replace.

The Commission welcomes the agreement reached, which, in its view, clarifies that web browsers are required to ensure support and interoperability for the qualified website authentication certificates (QWACs) for the sole purpose of displaying the identity data of the owner of the website in a user-friendly manner. The Commission understands this obligation as not prejudging the methods used to display such identity data.

Amendment 4

The Commission welcomes the agreement reached, which, in its view, clarifies that the requirement for the web browsers to recognise QWACs does not restrict browsers own security policies and that Article 45, as proposed, leaves it up to the web browsers to preserve and apply their own procedures and criteria in order to maintain and preserve the privacy of online communications using encryption and other proven methods. The Commission understands draft Article 45 as not imposing obligations or restrictions on how web browsers establish encrypted connections with websites or authenticate the cryptographic keys used when establishing those connections.

Proposal for a regulation

The Commission recalls that, in line with point 28 of the Interinstitutional Agreement between the European Parliament, the Council of the European Union and the European Commission on Better Law-Making of 13 April 2016, the Commission will make use of expert groups, consult targeted stakeholders and carry out public consultations, as appropriate.

Article 1 – paragraph 1 – point 3 – point i

Statement by the Commission on unobservability on the occasion of the adoption of Regulation (EU) 2024/1183

Regulation (EU) No 910/2014

The Commission welcomes the agreement reached, which in its view, confirms that this amending Regulation does not allow for the processing of personal data contained in or arising from the use of the European Digital Identity Wallet by the Wallet providers for other purposes than delivering wallet services.

Article 3 – paragraph 1 – point 47

The Commission also welcomes the inclusion of the concept of unobservability in Recital (11c) of the draft amending Regulation, which should prevent wallet providers from collecting and seeing the details of user’s day-to-day transactions. The Commission is of the view that this concept means that there should not be correlation of data across different services for the purposes of user tracking or tracing or for determining, analysing and predicting personal behaviour, interests or habits.

Or. en

At the same time, the Commission acknowledges that, in full compliance with Regulation (EU) 2016/679, the providers of European Digital Identity Wallets may access certain categories of personal data with the user’s explicit consent, such as in order to ensure continuity in the provision of wallet services or to protect users from disruptions in their provision. That data should be limited to what is necessary for each specific purpose.

Amendment 5

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) No 910/2014

Article 5 – paragraph 1

Or. en

Justification

To protect the privacy of individuals and not deter the privacy standard for users of the European Digital Identity Wallet, the use of pseudonyms has to be an option in all cases where full identification is not legally mandated. Restore references to the relationship between eIDAS and the European Data Protection Legislation back to the existing 2014 level of protections. The original eIDAS Regulation offered a higher standard of data protection than afforded by Directive 95/46/EC by mandating the facilitation of privacy by design in Article 12(3)(c).

Amendment 6

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) No 910/2014

Article 6a – paragraph 4 – point a – point 2 a (new)

Or. en

Justification

The Common Interface should include this safeguard to prevent unapproved or unidentified relying parties to request information exceeding their use case. The eIDAS expert group organised by the European Commission acknowledged the need of “sharing policies” that restrict what information a relying party can ask from the user and prevent excessive information requests (See chapter 4.6.1 and footnote 22 of the final Outline from February 17th 2022).

Amendment 7

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) No 910/2014

Article 6a – paragraph 4 – point a – point 2 b (new)

Or. en

Justification

The Common Interface should ensure that proxies acting as intermediaries between relying parties and users of the European Digital Identity Wallet cannot have access to the content of the transaction they convey. Such technical protections are commonplace and don’t limit the functioning of the system. The existence of such proxies has been acknowledged in the eIDAS Expert Group (See chapter 4.8.3 of the final Outline from February 17th 2022).

Amendment 8

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) No 910/2014

Article 6a – paragraph 4 – point a – point 3

Or. en

Justification

The success of the European Digital Identity Wallet depends on citizens making informed decisions on the information they share with relying parties. Similar guidance about mandatory information on the purpose of the processing by the relying party, as well as the possibility of the use to refuse information requests has been given by the eIDAS Expert Group that is currently developing the Toolbox. (see chapter 4.6.1 of the final Outline from February 17th 2022).

Amendment 9

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) No 910/2014

Article 6a – paragraph 4 – point b

Or. en

Justification

This amendment extends the safeguards to protect user behaviour from being tacked. Examples of providers of non-qualified attribute attestation are private companies, membership clubs or universities. With this change in the text an existing technical safeguard of the European Digital Identity Wallet is simply extended to more stakeholders.

Amendment 10

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) No 910/2014

Article 6a – paragraph 4 – point e

Or. en

Justification

The need for unlinkability and non-traceability was acknowledged by the eIDAS Expert Group (see page 26 in chapter 5 of the final Outline from February 17th 2022. User transactions will reveal large amounts of data, including data of highly personal nature, such as information of the individuals' economic situation or information about the medical situation, travel history, consumption patterns and social interactions of citizens.

Amendment 11

Proposal for a regulation

Article 1 – paragraph 1 – point 7

Regulation (EU) No 910/2014

Article 6a – paragraph 7

Or. en

Justification

Only an architecture that protects data like the medical situation, travel history, consumption patterns and social interactions of citizens which goes about a wide-range of online and offline user behaviour from centralised surveillance is an electronic identity system deserving citizens' trust. The issuer is the controller as it determines the means of processing of personal data by determining the concrete system, i.e. the means of processing, irrespective whether that system is executed or not on a device under their control (see C-40/17 and C-25/17).

Amendment 12

Proposal for a regulation

Article 1 – paragraph 1 – point 12

Regulation (EU) No 910/2014

Article 11a

Or. en

Justification

A unique, persistent identifier for natural persons would in some Member States be illegal or even unconstitutional (In Germany, the use of unique persistent identifiers is prohibited under the Census Act Ruling of 1983. The risk of a unique, life-long identifier cannot be deemed the least intrusive method for the purpose of uniquely identifying an individual. Article 11a is also not needed as the existing interoperability framework of identification schemes according to the original Article 12 (4) (d) already entails a unique representation of an individual for cross-border cases.

Amendment 13

Proposal for a regulation

Article 1 – paragraph 1 – point 13 – point b

Regulation (EU) No 910/2014

Article 12 – paragraph 4 – point d

Or. en

Justification

The Commission proposal would require a unique and persistent identification independent from a particular electronic identification scheme. In effect, this seemingly technical change of the interoperability framework would have the same effect as Article 11a.

Amendment 14

Proposal for a regulation

Article 1 – paragraph 1 – point 22 – point b

Regulation (EU) No 910/2014

Article 20 – paragraph 2

Or. en

Justification

According to Article 33 and 34 of the GDPR the controller has certain duties in case of a data breach. To fulfill these duties, they should be informed about a potential data breach in their system.

Amendment 15

Proposal for a regulation

Article 1 – paragraph 1 – point 22 – point b

Regulation (EU) No 910/2014

Article 20 – paragraph 2 – subparagraph 1 a (new)

Or. en

Amendment 16

Proposal for a regulation

Article 1 – paragraph 1 – point 25 – point c – point 2

Regulation (EU) No 910/2014

Article 24 – paragraph 2 – point fb a (new)

Or. en

ANNEX: LIST OF ENTITIES OR PERSONS FROM WHOM THE RAPPORTEUR HAS RECEIVED INPUT

The following list is drawn up on a purely voluntary basis under the exclusive responsibility of the rapporteur. The rapporteur has received input from the following entities or persons in the preparation of the draft opinion:

1. European Commission DG CNECT

2. The European Data Protection Supervisor

3. Brussels Privacy Hub, THE EUROPEAN COMMISSION PROPOSAL AMENDING THE eIDAS REGULATION (EU) No 910/2014: A PERSONAL DATA PROTECTION PERSPECTIVE

4. Professor Ricardo Genghini, Chairman of the European Standardization Committee E-Signature and Infrastructures (ESI) within the European Telecommunications Standards Institute (ETSI) - Notes on the current draft of eIDAS Revision Proposal

5. epicenter.works & European Digital Rights (EDRI)

6. Luukas Ilves, Deputy Secretary General of the Estonian Ministry of Economic Affairs and Communications for Digital Development

7. European Consumer Organisation (BEUC) - Making European Digital Identity as Safe as It Is needed - BEUC Position Paper

8. Jaap-Henk Hoepman, Associate Professor of privacy enhancing protocols and privacy by design in the Digital Security group at the Institute for Computing and Information Sciences of the Radboud University Nijmegen, Civil liberties aspects of the commission proposal to amend the eIDAS regulation

9. Eric Verheul, professor in the Digital Security Group of the Radboud University Nijmegen - Issues and recommendations on the eIDAS wallet as proposed in the eIDAS update

10. Manuel Atug expert in IT Security and engineering Chaos Computer Club & Christian Kahlo eID expert - written input

11. Lukasz Olejnik, PhD, https://lukaszolejnik.com, written contribution

12. Carmela Troncoso - Professor on Security and Privacy at Swiss Federal Institute of Technology Lausanne - written input

13. Dr. F. S. Gürses, Associat Professor at the Faculty of Technology, Policy and Management, TU Delft - written input

14. Eurosmart - The Voice Of The Digital Security Industry - Feedback on the revision of eIDAS

15. Mozzila

16. Google

17. Apple

18. The International Association for Trusted Blockchain Applications (INATBA) - Establishing a Framework for a European Digital Identity (eIDAS) - Policy Position

19. TWG Trusted Information of the EU Observatory for ICT Standardisation - report on “Trust in the European digital space in the age of automated bots and fakes”

20. Rule of Law Defense Coalition, Bucharest Romania

21. American Chamber of Commerce to the European Union, Brussels - written input