Sittings · Document

PROVISIONAL AGREEMENT RESULTING FROM INTERINSTITUTIONAL NEGOTIATIONS 2023-11-20

Proposal for a regulation of the European Parliament and of the Council on the amending regulation (EU) No 910/2014 as regards establishing a framework for European Digital Indentity

Committee on Industry, Research and Energy

06.12.2023

PROVISIONAL AGREEMENT RESULTING FROM INTERINSTITUTIONAL NEGOTIATIONS

Subject: Proposal for a regulation of the European Parliament and of the Council on the amending regulation (EU) No 910/2014 as regards establishing a framework for European Digital Indentity

(COM(2021)0281 – C90200/2021 – 2021/0136(COD))

The interinstitutional negotiations on the aforementioned proposal for a regulation have led to a compromise. In accordance with Rule 74(4) of the Rules of Procedure, the provisional agreement, reproduced below, is submitted as a whole to the Committee on Industry, Research and Energy for decision by way of a single vote.

ANNEX

2021/0136 (COD)

Proposal for a

REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity

THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

Having regard to the proposal from the European Commission,

After transmission of the draft legislative act to the national parliaments,

Having regard to the opinion of the European Economic and Social Committee1,

Acting in accordance with the ordinary legislative procedure,

Whereas:

(1) The Commission Communication of 19 February 2020, entitled “Shaping Europe’s Digital Future”2 announces a revision of Regulation (EU) No 910/2014 of the European Parliament and of the Council with the aim of improving ▌ its effectiveness, extend its benefits to the private sector and promote trusted digital identities for all Europeans.

(2) In its conclusions of 1-2 October 20203, the European Council called on the Commission to propose the development of a Union-wide framework for secure public electronic identification, including interoperable digital signatures, to provide people with control over their online identity and data as well as to enable access to public, private and cross-border digital services.

(2a) The Digital Decade Policy Programme 2030, established by Decision (EU) 2022/2481 of the European Parliament and of the Council, sets the objectives and digital targets of a Union framework which, by 2030, leads to wide deployment of a trusted, voluntary, user-controlled digital identity, recognised throughout the Union and allowing each user to control their data in online interactions.

▌ (3a) The interinstitutional Declaration entitled “European Declaration on Digital Rights and Principles for the Digital Decade”, signed by the European Parliament, the Council and the Commission on 15 December 2022 (the ‘Declaration’), underlines every citizen’s right to access digital technologies, products and services that are safe, secure, and privacy-protective by design. This includes ensuring that all people living in the Union are offered an accessible, secure and trusted digital identity that enables access to a broad range of online and offline services, protected against all cyberthreats, including identity theft or manipulation. The Declaration also states that everyone has the right to the protection of their personal data online. That right encompasses the control on how the data is used and with whom it is shared.

(3b) Union citizens should have the right to a digital identity that is under their sole control and that enables them to exercise their rights as citizens in the digital environment and to participate in the digital economy. To achieve this aim, a European digital identity framework should be established allowing Union citizens to access public and private online and offline services throughout the Union.

(3c) A harmonised digital identity framework should contribute to the creation of a more digitally integrated Union by reducing digital barriers between Member States and by empowering Union citizens and residents to enjoy the benefits of digitalisation, while increasing transparency and the protection of their rights.

(4) A more harmonised approach to digital identification should reduce the risks and costs of the current fragmentation due to the use of divergent national solutions or, in some Member States, the absence of such electronic identification solutions. Such an approach should strengthen the Single Market by allowing citizens, other residents as defined by national law and businesses to identify and authenticate online and offline in a safe, trustworthy, user friendly, convenient, accessible and harmonised way, across the Union. The European Digital Identity Wallet should provide natural and legal persons across the Union with a harmonised electronic identification means enabling the authentication and sharing of data linked to their identity. Everyone should be able to securely access public and private services relying on an improved ecosystem for trust services and on verified proofs of identity and electronic attestations of attributes, such as academic qualifications, university degrees or other educational or professional entitlements. The framework for a European Digital Identity should achieve a shift from the reliance on national digital identity solutions only, to the provision of electronic attestations of attributes valid and legally recognised across the Union. Providers of electronic attestations of attributes should benefit from a clear and uniform set of rules, while public administrations should be able to rely on electronic documents in a given format.

(4a) Several Member States have implemented and largely use electronic identification means that nowadays are accepted by service providers in the Union. Additionally, investments were made into both national and cross-border solutions on the basis of Regulation (EU) No 910/2014 of the European Parliament and of the Council, including the interoperability of notified electronic identification schemes (eIDAS) pursuant to that Regulation. In order to guarantee the complementarity and a fast adoption of European Digital Identity Wallets by current users of notified electronic identification means and to minimise the impacts on existing service providers, European Digital Identity Wallets are expected to benefit from building on the experience with existing electronic identification means and taking advantage of the deployed eIDAS infrastructure at Union and national levels.

(4b) Regulation (EU) 2016/679 and, where relevant, Directive 2002/58/EC should apply to all personal data processing activities under this amending Regulation. The solutions under the interoperability framework provided in this amending Regulation should also comply with these rules. EU data protection law provides for data protection principles, such as the data minimisation and purpose limitation principle and obligations, such as data protection by design and by default. The implementation of this amending Regulation should comply with these data protection principles and obligations.

(5) To support the competitiveness of European businesses, both online and offline service providers should be able to rely on digital identity solutions recognised across the Union, irrespective of the Member State in which they have been provided, thus benefiting from a harmonised European approach to trust, security and interoperability. Both users and service providers ▌ should be able to benefit from the same legal value provided to electronic attestations of attributes across the Union. A harmonised digital identity framework should create economic value by providing easier access to goods and services and by significantly reducing operational costs linked to identification and authentication procedures, for instance during the on-boarding of new customers, by reducing the potential for cybercrimes, such as identity theft, data theft and online fraud, thus promoting efficiency gains and the secure digital transformation of Union’s micro, small and medium sized enterprises (SMEs).

▌ (5b) The European Digital Identity Wallet (EDIW) should facilitate the application of the ‘once only’ principle, thus reducing administrative burden and supporting cross-border mobility of citizens and businesses across the Union and fostering the development of interoperable e-government services across the Union.

(6) Regulations (EU) No 2016/6791 and (EU) 2018/17252 and Directive 2002/58/EC3 apply to the processing of personal data in the implementation of this amending Regulation. Therefore, this amending Regulation should lay down specific safeguards to prevent providers of electronic identification means and electronic attestation of attributes from combining personal data from other services with the personal data processed to provide the services falling within the scope of this amending Regulation. Personal data related to the provision of European Digital Identity Wallets should be kept logically separate from any other data held by the provider. This amending Regulation should not prevent providers of European Digital Identity Wallets to apply additional technical measures contributing to protection of personal data, such as physical separation of personal data relating to the provision of Wallets from any other data held by the provider. Without prejudice to Regulation (EU) 2016/679, this amending Regulation further specifies the application of principles of purpose limitation, data minimisation, and data protection by design and by default.

(6a) EDIWs should have the function of a common dashboard embedded into the design, in order to ensure a higher degree of transparency, privacy and control of the users over their data. This function should provide an easy, user friendly interface with an overview of all relying parties with whom the user has shared data, including attributes, and the type of data shared with each relying party. It should allow the user to track all transactions executed through EDIWs, with at least the following data: the time and date of the transaction, the counterpart identification, the data requested and the data shared. That information should be stored even if the transaction was not concluded. It should not be possible to repudiate the authenticity of the information contained in the transaction history. Such a function should be active by default. It should allow users to easily request to a relying party the immediate deletion of personal data pursuant Article 17 of Regulation (EU) 2016/679 and to easily report to the competent national authority where a relying party is established if an unlawful or inappropriate request of data is received without leaving the EDIW.

(6b) Member States should integrate different privacy-preserving technologies, such as zero knowledge proof, into the EDIW. These cryptographic methods should allow a relying party to validate that a given statement based on the person’s identification data and attestation of attributes is true, without revealing any data this statement is based on, thereby ensuring the privacy of the user.

(7) This Regulation should set out the harmonised conditions for the establishment of a framework for European Digital Identity Wallets to be provided by Member States. All Union citizens and ▌ residents as defined by national laws should be empowered to securely request, select, combine, store, delete, share and present data related to their identity and request deletion of their personal data in a user friendly and convenient way, under the sole control of the user, while enabling selective disclosure. This Regulation should reflect shared European values and uphold fundamental rights, legal safeguards and liability, thus protecting democratic societies and citizens. Technologies used to achieve those objectives should be developed aiming towards the highest level of security, privacy, user convenience, accessibility, wide usability and seamless interoperability. Member States should ensure equal access to digital identification to all their nationals and residents. Member States should not, directly or indirectly, limit access to public or private services to natural or legal persons not opting to use EDIWs and should make available appropriate alternative solutions.

(7a) Member States should rely on the possibilities offered by this Regulation to provide, under their responsibility, European Digital Identity Wallets for use by the natural and legal persons residing on their territory. To offer Member States flexibility and leverage the technological state of the art, this Regulation should enable provision of EDIWs directly by a Member State, under a mandate from a Member State, or independently of a Member State, but recognised by that Member State.

(8) For the purposes of registration, relying parties should provide the information necessary to allow for their identification and authentication towards the European Digital Identity Wallets. When declaring their intended use of the EUDIW, relying parties should provide information regarding the data that they will request, if any, in order to provide their services and the reason for the request. Relying party registration should facilitate Member States’ verifications related to the lawfulness of the activities of the relying parties in accordance with Union law. The obligation to register should be without prejudice to obligations laid down in other Union or national law, such as the information to be provided to the data subjects pursuant to the Regulation (EU) 2016/679. Relying parties should comply with the safeguards offered by Articles 35 and 36 of Regulation (EU) 2016/679, in particular by performing data protection impact assessments and by consulting the competent data protection authorities prior to data processing where data protection impact assessments indicate that the processing would result in a high risk. Such safeguards should support the lawful processing of personal data by relying parties, in particular when special categories of data are at stake, such as health data. The registration of relying parties should enhance transparency and trust in the use of the European Digital Identity Wallet. Registration should be cost-effective and proportionate to the related risks in order to ensure the uptake by service providers. In this context, registration should provide for the use of automated procedures, including the reliance on and the use of existing registers by Member States, and not entail a pre-authorisation process. The registration process should enable a variety of use-cases that may differ in terms of mode of operation (online/offline), or in terms of the requirement to authenticate devices for the purposes of interfacing with the European Digital Identity Wallet. Registration should exclusively apply to relying parties providing services by means of digital interaction.

(8a) Safeguarding citizens against unauthorised or fraudulent use of the wallet is of high importance for ensuring trust in and for the wide uptake of the European Digital Identity Wallets. Users should be provided with effective protection against such misuse. In particular, when facts that form the basis for a fraudulent or otherwise illegal use of the wallet are established by a national judicial authority in the context of another procedure, supervisory bodies of the wallet issuers should upon notification take the necessary measures to ensure that the registration of the relying party and the inclusion of relying parties in the authentication mechanism is withdrawn or suspended until the notifying authority confirms that the identified irregularities have been remedied.

(9) All EDIWs should enable users to electronically identify and authenticate online and offline across borders to access a wide range of public and private services. Without prejudice to Member States’ prerogatives as regards the identification of their nationals and residents, EDIWs can also serve the institutional needs of public administrations, international organisations and the Union’s institutions, bodies, offices and agencies. Offline use would be important in many sectors, including in the health sector where services are often provided through face-to-face interaction and ePrescriptions should be able to rely on QR-codes or similar technologies to verify authenticity. Relying on the level of assurance “high”, EDIWs should benefit from the potential offered by tamper-proof solutions such as secure elements, to comply with the security requirements under this Regulation. The European Digital Identity Wallets should also allow users to create and use qualified electronic signatures and seals which are accepted across the EU. When on-boarding into EDIWs, natural persons should be able to sign with qualified electronic signatures, free of charge and by default, without having to go through any additional administrative procedures. This should enable users to sign or seal self-claimed assertions or attributes. To achieve simplification and cost reduction benefits to persons and businesses across the Union, including by enabling powers of representation and e-mandates, Member States should provide EDIWs relying on common standards and technical specifications to ensure seamless interoperability and to adequately increase the IT security, strengthen robustness against cyber-attacks and thus significantly reduce the potential risks of ongoing digitalisation for citizens and businesses. Only Member States’ competent authorities can provide a high level of confidence in establishing the identity of a person and therefore provide assurance that the person claiming or asserting a particular identity is in fact the person he or she claims to be. It is therefore necessary for the provision of the European Digital Identity Wallets to rely on the legal identity of citizens, other residents or legal entities. Reliance on the legal identity should not hinder the possibility of EIDWs users to access services through the use of pseudonyms, where there is no legal requirement for legal identity for authentication. Trust in the EDIWs would be enhanced by the fact that issuing and managing parties are required to implement appropriate technical and organisational measures to ensure the highest level of security that is commensurate to the risks raised for the rights and freedoms of the natural persons, in line with Regulation (EU) 2016/679.

(9a) The use of qualified electronic signature should be free of charge to all natural persons for non-professional purposes. Member States may provide for measures to prevent the free-of-charge use of qualified electronic signatures by natural persons for professional purposes, ensuring that any such measures are proportionate to identified risks and are justified.

(9b) It is beneficial to facilitate the uptake and use of European Digital Identity Wallets by seamlessly integrating them with the ecosystem of public and private digital services already implemented at national, local or regional level. To achieve this goal, Member States may provide for legal and organizational measures in order to increase flexibility for issuers of European Digital Identity Wallets and to allow for additional functionalities of European Digital Identity Wallets beyond what is set out by this Regulation, including by enhanced interoperability with existing national electronic identification means. This should be by no means to the detriment of providing core functions of the European Digital Identity Wallets as set out in this Regulation nor to promote existing national solutions over European Digital Identity Wallets. Since they go beyond this Regulation, those additional functionalities do not benefit from the provisions on cross-border reliance on European Digital Identity Wallets set out in this Regulation.

(9c) EDIWs should include a functionality to generate user chosen and managed pseudonyms, to authenticate when accessing online services.

(10) In order to achieve a high level of security and trustworthiness, this Regulation establishes the requirements for European Digital Identity Wallets. The conformity of European Digital Identity Wallets with those requirements should be certified by accredited ▌conformity assessment bodies designated by Member States. ▌

(10a) In order to avoid divergent approaches and harmonize the implementation of the requirements laid down by this Regulation, European Digital Identity Wallets should be certified according to common specifications, procedures and reference standards adopted by the Commission according to this Regulation for the purpose of expressing detailed technical specifications of those requirements. For as long and as far as the certification of the conformity of European Digital Identity Wallet with relevant cybersecurity requirements are not covered by cybersecurity certification schemes that are available and referenced in this Regulation, and for as far as non-cybersecurity requirements relevant to the European Digital Identity Wallet are concerned, Member States should establish national certification schemes following the harmonized requirements set out in this Regulation.

(10b) Certification of conformity with the cybersecurity requirements established in this Regulation should, where available, rely on the relevant European cybersecurity certifications schemes established pursuant to Regulation (EU) 2019/881 which establishes a voluntary European cybersecurity certification framework for ICT products, processes and services.

(10c) In order to continuously assess and mitigate risks linked to security, certified European Digital Identity Wallet should be subject to regular vulnerability assessments aiming at detecting any vulnerability of the certified product, process, and service related components of the European Digital Identity Wallet.

(10d) By protecting users and companies from cybersecurity risks, the essential cybersecurity requirements laid down in this Regulation, are also to contribute to enhancing the protection of personal data and privacy of individuals. Synergies on both standardisation and certification on cybersecurity aspects should be considered through the cooperation between the Commission, the European Standardisation Organisations, the European Union Agency for Cybersecurity (ENISA), the European Data Protection Board (EDPB) established by Regulation (EU) 2016/679, and the national data protection supervisory authorities.

(10e) The on-boarding of citizens and residents to the European Digital Identity Wallet should be facilitated by relying on electronic identification means issued at level of assurance ʽhighʼ. Electronic identification means issued at level of assurance ʽsubstantialʼ should be relied upon only in cases where harmonised technical and operational specifications using electronic identification means issued at level of assurance ʽsubstantialʼ in combination with other supplementary means of identity verification will allow the fulfillment of the requirements set out in this Regulation as regards level of assurance ʽhighʼ. Such supplementary means or measures should be reliable and easy to utilize by the users and could be built on the possibility to use remote on-boarding procedures, qualified certificates supported by qualified signatures, qualified electronic attestation of attributes or a combination thereof. To ensure sufficient uptake of European Digital Identity Wallets, harmonised technical and operational specifications for on-boarding of users by using electronic identification means, including those issued at level of assurance ʽsubstantialʼ, should be set out in implementing acts.

(10f) The objective of this Regulation is to provide the user with a fully mobile, secure and user-friendly European Digital Identity Wallet. As a transitional measure until the availability of certified tamper-proof solutions, such as secure elements within the users' devices, the European Digital Identity Wallets may rely upon certified external secure elements for the protection of the cryptographic material and other sensitive data or upon notified national solutions at level of assurance ʽhighʼ in order to demonstrate compliance with the relevant requirements of the Regulation as regards the level of assurance of the Wallet. The use of the above-mentioned transitional measure should be limited to use cases requiring level of assurance ʽhighʼ, such as on-boarding of the user to the Wallet and authenticating to services requiring level of assurance ʽhighʼ. When authenticating to services requiring level of assurance ʽsubstantialʼ, European Digital Identity Wallets should not require the use of the above-mentioned transitional measure. This Regulation should be without prejudice to national conditions for the issuance and use of certified external secure element in case this transitional measure relies on it.

(11) European Digital Identity Wallets should ensure the highest level of data protection and security for the purposes of authentication and identification to facilitate access to public and private services, irrespective of whether such data is stored locally or on cloud-based solutions, taking due account of the different levels of risk. ▌

(11a) EDIWs should be secure-by-design and implement advanced security features to protect against identity and other data theft, denial of service and any other cyber threat. This should include state of-the-art encryption and storage methods that are only accessible to and can be decrypted exclusively by the user and rely on end-to-end encrypted communication with other EDIWs and relying parties. Additionally, EDIWs should require secure explicit, and active users’ confirmation for the operations performed via the EDIWs.

(11c) The use of the wallet free of charge should not result in the processing of data beyond what is necessary for the provision of wallet services. This Regulation should not allow processing of personal data stored in or resulting from the use of the European Digital Identity Wallet by the provider of the European Digital Identity Wallet for other purposes than the provision of wallet services. To ensure privacy, EDIW providers should ensure unobservability by not collecting data and not having insight into the transactions of the users of the Wallet. This means that the providers should not be able to see the details of the transactions made by the user. However, in specific cases based on the previous explicit consent of users for each of those specific cases, and in full accordance with GDPR, providers of EDIW could be granted access to the information necessary for the provision of a particular service related to the Wallet.

(11d) The transparency of EDIWs and accountability of their providers are key elements to create social trust and trigger acceptance of the framework. The functioning of European Digital Identity Wallets should therefore be transparent and, in particular, allow for verifiable processing of personal data. To achieve this, Member States should disclose the source code of the user application software components of European Digital Identity Wallets, including those that are related to processing of personal data and data of legal persons. The publication of this source code under an open-source licence should enable society, including users and developers, to understand its operation, audit and review the code. This would increase users’ trust in the Wallet ecosystem and contribute to the security of EDIWs by enabling anyone to report vulnerabilities and errors in the code. Overall, this should incentivise suppliers to deliver and maintain a highly secure product. However, there are cases where the disclosure of the source code for the libraries used, communication channel or other elements that are not hosted on user device, could be limited by Member States, for duly justified reasons, especially for public security purposes.

(11e) The use of the EDIWs as well as the discontinuation of their use should be the exclusive right and choice of users. Member States should develop simple and secure procedures for the users to request immediate revocation of validity of EDIWs, including in case of loss or theft. Upon the death of the user or the cessation of activity by a legal person, a mechanism should be established to enable the authority responsible for settling the succession of the natural person or assets of the legal person to request the immediate termination of EDIWs.

(11f) In order to promote uptake of the EDIWs and wider use of digital identities, Member States should not only show the benefits of the relevant services, but also, in cooperation with the private sector, researchers and academia, develop training programmes aiming to strengthen the digital skills of their citizens and residents, in particular for vulnerable groups such as persons with disabilities and older persons. Member States should also raise awareness about the benefits and risks of the European Digital Identity Wallet by means of communication campaigns.

(12) To ensure that the European Digital Identity framework is open to innovation, technological development and future-proof, Member States are encouraged to jointly set up sandboxes to test innovative solutions in a controlled and secure environment in particular to improve the functionality, protection of personal data, security and interoperability of the solutions and to inform future updates of technical references and legal requirements. This environment should foster the inclusion of European SMEs, start-ups and individual innovators and researchers, as well as relevant industry stakeholders. Such initiatives should contribute to and strengthen the regulatory compliance and technical robustness of the EDIWs to be provided to the citizens, thus preventing the development of solutions non-compliant with Union law on data protection or open to security vulnerabilities.

(13) Regulation (EU) No 2019/11575 strengthens the security of identity cards with enhanced security features by August 2021. Member States should consider the feasibility of notifying them under electronic identification schemes to extend the cross-border availability of electronic identification means.

(14) The process of notification of electronic identification schemes should be simplified and accelerated to promote the access to convenient, trusted, secure and innovative authentication and identification solutions and, where relevant, to encourage private identity providers to offer electronic identification schemes to Member State’s authorities for notification as national electronic identification schemes under Regulation 910/2014.

(15) Streamlining of the current notification and peer-review procedures will prevent heterogeneous approaches to the assessment of various notified electronic identification schemes and facilitate trust-building between Member States. New, simplified, mechanisms should foster Member States’ cooperation on the security and interoperability of their notified electronic identification schemes.

(16) Member States should benefit from new, flexible tools to ensure compliance with the requirements of this Regulation and of the relevant implementing acts. This Regulation should allow Member States to use reports and assessments, performed by accredited conformity assessment bodies, as provided for in the context of certification schemes to be established at Union level under Regulation (EU) 2019/881, to support their claims on the alignment of the schemes or of parts thereof with the requirements of the Regulation on the interoperability and the security of the notified electronic identification schemes.

(17) Public service providers use the ▌ person identification data available from electronic identification means pursuant to Regulation (EU) No 910/2014 to match the electronic identity of the users from other Member States with the person identification data provided to those users in the Member State performing the cross-border identity matching process. However, in many cases, despite the use of the eIDAS minimum data set, ensuring accurate identity matching when Member States act as relying parties require additional information about the user and specific complementary unique identification procedures to be performed at national level. To further support the usability of electronic identification means, provide better online public services and increase legal certainty in relation to the electronic identity of the users, this Regulation should ▌ require Member States to take specific online measures to ensure unequivocal identity matching when users intend to access cross-border public services online.

(17b) When developing European Digital Identity Wallets, it is essential to take into consideration the needs of users . There should be meaningful use cases and online services relying on European Digital Identity Wallets available. For convenience of users and in order to ensure cross-border availability of such services, it is important to undertake actions in order to facilitate a similar approach to design, development and implementation of online services in all Member States. Non-binding guidelines on how to design, develop and implement online services relying on European Digital Identity Wallets have the potential of becoming a useful tool to achieve this goal. These guidelines should be prepared in due account of the interoperability framework of the Union. Member States should have a leading role when it comes to adopting them.

(18) In accordance with Directive (EU) 2019/8826, persons with disabilities should be able to use the European digital identity wallets, trust services and end-user products used in the provision of those services on an equal basis with other users.

(18a) In order to ensure effective enforcement of the obligations laid down in this Regulation, a minimum for the maximum of administrative fines for both qualified and non-qualified trust service providers should be established. Member States should implement penalties regimes providing for effective, proportionate and dissuasive sanctions. When determining the penalties, the size of the affected entities, their business models and the severity of the breaches should be duly taken into consideration.

(18b) Member States should lay down rules on penalties for infringements such as direct or indirect practices leading to confusion between non-qualified and qualified trust services or to the abusive use of the EU trust mark by non-qualified trust service providers. The EU trust mark should not be used under conditions which, directly or indirectly, lead to the belief that any non-qualified trust services offered by these providers are qualified.

(19) This Regulation should not cover aspects related to the conclusion and validity of contracts or other legal obligations where there are requirements as regards form laid down by Union or national law. In addition, it should not affect national form requirements pertaining to public registers, in particular commercial and land registers.

(20) The provision and use of trust services and the benefits brought in terms of convenience and legal certainty in the context of cross-border transactions, in particular when qualified trust services are used, are becoming increasingly important for international trade and cooperation. International partners of the EU are establishing trust frameworks inspired by Regulation (EU) No 910/2014. ▌ In order to facilitate the recognition of qualified trust services and their providers, implementing legislation may set the conditions under which trust frameworks of third countries could be considered equivalent to the trust framework for qualified trust services and providers in this Regulation. Such an approach should complement ▌ the possibility for the mutual recognition of trust services and providers established in the Union and in third countries in accordance with Article 218 of the Treaty. When setting out the conditions under which trust frameworks of third countries could be considered equivalent to the trust framework for qualified trust services and providers in this Regulation, compliance with the relevant provisions in the Directive (EU) 2022/2555 and Regulation (EU) 2016/679 should also be ensured, as well as the use of trusted lists as essential elements to build trust.

(21) ▌ [deleted] ▌

(21a) This Regulation should foster choice and the possibility of switching between EDIWs, where a Member State has endorsed more than one EDIW solution on its territory. In order to avoid lock-in effects in such situations, where technically feasible, the providers of EDIWs should ensure the effective portability of data at the request of EDIW users, and should not be allowed to use contractual, economic or technical barriers to prevent or to discourage effective switching between different EDIWs.

(21b) To ensure the proper functioning of the European Digital Identity Wallets, ‘wallet’ providers need effective interoperability and fair, reasonable and non-discriminatory conditions for the ‘wallet’ to access specific hardware and software features of mobile devices. These components may include in particular but not exclusively, Near Field Communication antennas and secure elements (including Universal Integrated Circuit Cards, embedded secure elements, microSD cards and Bluetooth Low Energy). The access to these components may be under the control of mobile network operators and equipment manufacturers. Therefore, whenever needed to provide the services of the European Digital Identity Wallets, original equipment manufacturers of mobile devices or providers of electronic communication services should not refuse access to such components. In addition, the undertakings that are designated gatekeepers for enumerated core platform services by the European Commission under Regulation (EU) 2022/1925, should remain subject to the specific provisions of such Regulation, building on Article 6(7) of the Regulation (EU) 2022/1925 of the European Parliament and of the Council.

(22) In order to streamline the cybersecurity obligations imposed on trust service providers, as well as to enable these providers and their respective competent authorities to benefit from the legal framework established by Directive EU 2022/2555, trust services are required to take appropriate technical and organisational measures pursuant to Directive EU 2022/2555, such as measures addressing system failures, human error, malicious actions or natural phenomena in order to manage the risks posed to the security of network and information systems which those providers use in the provision of their services as well as to notify significant incidents and cyber threats in accordance with Directive EU 2022/2555. With regard to the reporting of incidents, trust service providers should notify any incidents having a significant impact on the provision of their services, including such caused by theft or loss of devices, network cable damages or incidents occurred in the context of identification of persons. The cybersecurity risk management requirements and reporting obligations under Directive EU 2022/2555 should be considered complementary to the requirements imposed on trust service providers under this Regulation. Where appropriate, established national practices or guidance in relation to the implementation of security and reporting requirements and supervision of compliance with such requirements under Regulation (EU) No 910/2014 should continue to be applied by the competent authorities designated under Directive EU 2022/2555. Any requirements pursuant to this Regulation do not affect the obligation to notify personal data breaches under Regulation (EU) 2016/679.

(23) Due consideration should be given to ensure effective cooperation between the NIS and eIDAS authorities. In cases where the supervisory body under this Regulation is different from the competent authorities designated under Directive (EU) 2022/2555, those authorities should cooperate closely, in a timely manner by exchanging the relevant information in order to ensure effective supervision and compliance of trust service providers with the requirements set out in this Regulation and Directive (EU) 2022/2555. In particular, the supervisory bodies under this Regulation should be entitled to request the competent authority under Directive (EU) 2022/2555 to provide the relevant information needed to grant the qualified status and to carry out supervisory actions to verify compliance of the trust service providers with the relevant requirements under Directive (EU) 2022/2555 or require them to remedy non-compliance.

(24) It is essential to provide for a legal framework to facilitate cross-border recognition between existing national legal systems related to electronic registered delivery services. That framework could also open new market opportunities for Union trust service providers to offer new pan-European electronic registered delivery services. In order to ensure that the data using a qualified electronic registered delivery service is delivered to the correct addressee, qualified electronic registered delivery services should ensure with full certainty the identification of the addressee while a high level of confidence would suffice as regard to the identification of the sender. Providers of qualified electronic registered delivery services should be encouraged by Member States to have their services to be interoperable with qualified electronic registered delivery services provided by other qualified trust service providers in order to easily transfer the electronic registered data between two or more qualified trust service providers and to promote fair practices in the internal market.

(25) In most cases, citizens and other residents cannot digitally exchange, across borders, information related to their identity, such as addresses, age and professional qualifications, driving licenses and other permits and payment data, securely and with a high level of data protection.

(26) It should be possible to issue and handle trustworthy electronic attributes and contribute to reducing administrative burden, empowering citizens and other residents to use them in their private and public transactions. Citizens and other residents should be able, for instance, to demonstrate ownership of a valid driving license issued by an authority in one Member State, which can be verified and relied upon by the relevant authorities in other Member States, to rely on their social security credentials or on future digital travel documents in a cross border context.

(27) Any entity that issues attested attributes in electronic form such as diplomas, licenses, birth certificates or powers and mandates to represent or act on behalf of natural or legal persons should be considered as a trust service provider of electronic attestation of attributes. ▌ An electronic attestation of attributes should not be denied legal effect on the grounds that it is in an electronic form or that it does not meet the requirements of the qualified electronic attestation of attributes. Relying parties should be able to use the electronic attestations of attributes as equivalent to attestations in paper format. To that effect, general requirements should be laid down to ensure that a qualified electronic attestation of attributes has the equivalent legal effect of lawfully issued attestations in paper form. However, those requirements should apply without prejudice to Union or national law defining additional sector specific requirements as regards form with underlying legal effects and, in particular, the cross-border recognition of qualified electronic attestation of attributes, where appropriate.

(28) The wide availability and usability of EDIWs should rely on their acceptance and trust by both private individuals and private service providers. Therefore, private relying parties providing services such as in the areas of transport, energy, banking and financial services, social security, health, drinking water, postal services, digital infrastructure, telecommunications or education should accept the use of EDIWs for the provision of services where strong user authentication for online identification is required by Union or national law or by contractual obligation. The request for information to the EUDIW user should be necessary and proportionate with the intended use case and in line with the principle of data minimisation and ensure transparency over which data is shared and for what purposes.

To facilitate the use and acceptance of the European Digital Identity Wallets, widely accepted industry standards and specifications should be taken into account in their deployment ▌ .

(28a) Where very large online platforms as defined in Article 25(1) of Regulation (EU) 2022/2065 require users to authenticate to access online services, those platforms should be mandated to accept the use of EDIWs upon voluntary request of the user. Users should be under no obligation to use EDIWs to access private services and should not be restricted or hindered in their access to services on the grounds that they do not use an EDIW. However, if users wish to do so, very large online platforms should accept EDIWs for this purpose while respecting the principle of data minimisation and the right of the users to use freely chosen pseudonyms. Given the importance of very large online platforms, due to their reach, in particular as expressed in number of recipients of the service and economic transactions this is necessary to increase the protection of users from fraud and secure a high level of data protection.

(28b) Codes of conduct at Union level should be developed in order to contribute to wide availability and usability of electronic identification means, including EDIWs within the scope of this Regulation. The codes of conduct should facilitate wide acceptance of electronic identification means including EDIWs by those service providers which do not qualify as very large platforms and which rely on third party electronic identification services for user authentication.

(29) Selective disclosure is a concept empowering the owner of data to disclose only certain parts of a larger data set, in order for the receiving entity to obtain only such information that is necessary for the provision of a service requested by a user. The European Digital Identity Wallet should technically enable the selective disclosure of attributes to relying parties. Such selectively disclosed attributes, including when originally parts of multiple distinct electronic attestations, may be subsequently combined and presented to relying parties by the user. This feature should become a basic design feature of EDIWs thereby reinforcing convenience and the protection of personal data, including data minimization.

(29a) Unless specific rules of Union or national law require users to identify themselves, accessing services by using a pseudonym should not be prohibited.

(30) Attributes provided by the qualified trust service providers as part of the qualified attestation of attributes should be verified against the authentic sources either directly by the qualified trust service provider or via designated intermediaries recognised at national level in accordance with national or Union law for the purpose of secure exchange of attested attributes between identity or attestation of attributes’ service providers and relying parties. Member States should establish appropriate mechanisms at national level to ensure that qualified trust service providers issuing qualified electronic attestation of attributes are able, based on the consent of the person to whom the attestation is issued, to verify the authenticity of the attributes relying on authentic sources. Appropriate mechanisms may include the use of specific intermediaries or technical solutions in compliance with national law allowing access to authentic sources. Ensuring the availability of a mechanism that will allow for the verification of attributes against authentic sources should facilitate the compliance of the qualified trust service providers of qualified electronic attestation of attributes with their obligations set by this Regulation. Annex VI contains a list of categories of attributes for which Member States should ensure that measures are taken to allow qualified providers of electronic attestations of attributes to verify by electronic means, at the request of the user, their authenticity against the relevant authentic source.

(31) Secure electronic identification and the provision of attestation of attributes should offer additional flexibility and solutions for the financial services sector to allow identification of customers and the exchange of specific attributes necessary to comply with, for example, customer due diligence requirements under the Anti Money Laundering Regulation, [reference to be added after the adoption of the proposal], with suitability requirements stemming from investor protection legislation, or to support the fulfilment of strong customer authentication requirements for online identification for the purposes of account login and of initiation of transactions in the field of payment services.

(31a) This Regulation should establish the principle that the legal effect of an electronic signature cannot be challenged on the grounds that it is in an electronic form or that it does not meet the requirements of the qualified electronic signature. However, it is for national law to define the legal effect of electronic signatures, except for the requirements provided for in this Regulation according to which the legal effect of a qualified electronic signature it is to be equivalent to that of a handwritten signature. In determining the legal effects of electronic signatures Member States should take into account the principle of proportionality between the judicial value of a document to be signed and level of security and cost that an electronic signature requires. To increase the accessibility and use of electronic signatures, Member States are encouraged to consider the use of advanced electronic signatures in the day-to- day transactions for which they provide a sufficient level of security and confidence.

(31a) In order to ensure the consistency of certification practices across the EU, the Commission should issue guidelines on the certification and recertification of qualified electronic signature creation devices and of qualified electronic seal creation devices, including their validity and limitations in time. This regulation does not prevent the receiving Member States from allowing public or private bodies that have certified qualified electronic signature creation devices to temporarily extend the recognition of the validity of certification when a recertification of the same device could not be performed within the legally defined time frame for a reason other than a breach or security incident, and without prejudice to the applicable certification practice.

(32) Website authentication services provide users with assurance with a high level of confidence in the identity of the entity standing behind the website, irrespective of the platform used to display it. Those services should contribute to the building of trust ▌ in conducting business online, as users would have confidence in a website that has been authenticated. ▌The use of website authentication services by websites should be voluntary. ▌In order for website authentication to become a means to increase trust, and to provide a better experience for the user and to foster growth in the internal market, this Regulation lays down a trust framework including minimal security and liability obligations for the providers of qualified website authentication services and requirements for the provision of their services. National trusted lists should confirm the qualified status of website authentication services and of their trust service providers, including their full compliance with the requirements of this Regulation with regards to the issuance of qualified certificates for website authentication. Recognition of QWACs means that the providers of web-browsers should not deny the authenticity of qualified certificates for website authentication for the sole purpose of attesting the link between the website domain name and the natural or legal person to whom the certificate is issued and confirming the identity of that person. Providers of web-browsers should display in a user-friendly manner the certified identity data and the other attested attributes to the end-user, in the browser environment, by relying on technical implementations of their choice. To that end, providers of web-browsers should ensure support and interoperability with qualified certificates for website authentication issued in full compliance with the requirement of this Regulation. The obligation of recognition, interoperability and support of QWACs is not to affect the freedom of web-browser providers to ensure web security, domain authentication and the encryption of web traffic in the manner and with the technology they consider most appropriate. In order to contribute to the online security of end-users, providers of web-browsers should be able to take measures, in exceptional circumstances, that are both necessary and proportionate in reaction to substantiated concerns on breaches of security or loss of integrity of an identified certificate or set of certificates. In this case, while taking any such precautionary measures, web-browser providers should notify without undue delay the national supervisory body and the Commission, the entity to whom the certificate was issued and the qualified trust service provider that issued that certificate or set of certificates of any such concern of a security breach as well as the measures taken relating to a single certificate or a set of certificates. These measures, should be without prejudice to the obligation of the browsers to recognize qualified website authentication certificates in accordance with the national trusted lists. To further protect citizens and promote their usage, public authorities in Member States should consider incorporating qualified certificates for website authentication in their websites. The measures put forward by this Regulation aiming to bring increased coherence between Member States’ divergent approaches and practices related to supervisory procedures should contribute to improved trust and confidence in the security, quality and availability of Qualified Website Authentication Certificates (QWACs).

(33) Many Member States have introduced national requirements for services providing secure and trustworthy electronic archiving in order to allow for the long term preservation of electronic data and electronic documents, and associated trust services. To ensure legal certainty, trust and harmonization across Member states, a legal framework for qualified electronic archiving services should be established, inspired by the framework of the other trust services set out in this Regulation. This framework should offer trust service providers and users an efficient toolbox that includes functional requirements for the electronic archiving service, as well as clear legal effects when a qualified electronic archiving service is used. These provisions should apply to electronically-born documents as well as paper documents that have been scanned and digitised. When required, these provisions should allow for the preserved electronic data and electronic documents to be ported on different media or formats for the purpose of extending their durability and legibility beyond the technological validity period, while preventing loss and alteration to the greatest extent possible. When electronic data and electronic documents submitted to the electronic archiving service contain one or more qualified electronic signatures or qualified electronic seals, the service should use procedures and technologies capable of extending their trustworthiness for the preservation period of such data, possibly relying on the use of other qualified trust services established by this Regulation. For creating preservation evidence where electronic signatures, electronic seals or electronic timestamps are used, qualified trust services should be used. As far as electronic archiving services are not harmonised by this Regulation, Member States may maintain or introduce national provisions, in conformity with Union law, relating to those services, such as specific provisions for services integrated in an organisation and strictly used for “internal archives” of this organisation. This Regulation should not distinguish between electronically born documents and physical documents that have been digitised.

(33a) National archives and memory institutions, in their capacity as organizations dedicated to preserving the documentary heritage in public interest, are usually mandated to conduct their activities by national law and do not necessarily provide trust services within the meaning of this Regulation. In so far these institutions do not provide such trust services, this Regulation is without prejudice to their operation.

(34) ▌Electronic ledgers are a sequence of electronic data records which should ensure their integrity and the accuracy of their chronological ordering. Electronic ledgers should establish a chronological sequence of data records. In conjunction with other technologies, they should contribute to solutions for more efficient and transformative public services such as e-voting, cross border cooperation of customs authorities, cross border cooperation of academic institutions, or the recording of ownership for real estate in decentralised land registries. Qualified electronic ledgers should establish a legal presumption for the unique and accurate sequential chronological ordering and integrity of the data records in the ledger. Due to their specificities, such as the sequential chronological ordering of data records, electronic ledgers should be distinguished from other trust services such as electronic time stamps and electronic registered delivery services. To ensure legal certainty and promote innovation, a pan-European legal framework should be established that allows for the cross-border recognition of trust services for the recording of data in electronic ledgers. This should sufficiently prevent that the same digital asset is copied and sold more than once to different parties. The process of creating and updating an electronic ledger depends on the type of ledger used (centralised or distributed). This Regulation should ensure technological neutrality, namely neither favouring nor discriminating against any technology used to implement the new trust service for electronic ledgers. In addition, sustainability indicators with regard to adverse impacts on climate and other environment‐related adverse impacts should be taken into account by the Commission, using adequate methodologies, when preparing the implementing acts specifying the requirements for qualified electronic ledgers.

(35) ▌Trust service providers for electronic ledgers should be mandated to ascertain the sequential recording of data into the ledger. This Regulation is without prejudice to any legal obligations that users of electronic ledgers may need to comply with under Union and national law. For instance, use cases that involve the processing of personal data should comply with Regulation (EU) 2016/679 and use cases that relate to financial services should comply with the relevant European financial▌7▌ services legislation.

(36) In order to avoid fragmentation and barriers, due to diverging standards and technical restrictions, and to ensure a coordinated process to avoid affecting the implementation of the future European digital Identity framework, a process for close and structured cooperation between the Commission, Member States, civil society, academia and the private sector is needed. To achieve this objective, Member States and the Commission should cooperate within the framework set out in the Commission Recommendation 2021/946 to identify a Toolbox for a European Digital Identity framework. In this context, Member States should agree on a comprehensive technical architecture and reference framework, a set of common standards and technical references including recognised existing standards and a set of guidelines and descriptions of best practices covering at least all ▌ functionalities and interoperability of the EDIWs including eSignatures and of the qualified trust service providers for electronic attestation of attributes as laid out in this regulation. In this context, Member States should also reach agreement on common elements of a business model and fee structure of EDIWs, to facilitate take up, in particular by SMEs, in a cross-border context. The content of the toolbox should evolve in parallel with and reflect the outcome of the discussion and the process of adoption of the European Digital Identity Framework.

(36b) This Regulation should ensure a harmonized level of quality, trustworthiness and security of qualified trust services, regardless of the place where the operations are conducted. Thus, a qualified trust service provider should be allowed to outsource its operations related to the provision of a qualified trust service outside of the Union, should it provide the adequate guarantees, ensuring that supervisory activities and audits can be enforced as if these operations were carried out in the Union. When the compliance with the Regulation cannot be fully assured, the supervisory bodies should be able to adopt proportionate and justified measures, including withdrawal of the qualified status of the trust service provided.

(36c) To ensure legal certainty as regards the validity of advanced electronic signatures based on qualified certificates, it is essential to specify the components of an advanced electronic signature based on qualified certificates, which should be assessed by the relying party carrying out the validation of that signature.

(36d) Trust service providers should use cryptographic algorithms reflecting current best practices and trustworthy implementations of these algorithms in order to ensure security and reliability of their trust services.

(36e) This Regulation should set out an obligation for qualified trust service providers to verify the identity of a natural or legal person to whom the qualified certificate or the qualified electronic attestation of attribute is issued based on various harmonized methods across the EU. To ensure that qualified certificates and qualified electronic attestations of attributes are issued to the person to whom they belong and that they attest the correct and unique set of data representing the identity of that person, qualified trust service providers issuing qualified certificates or issuing qualified electronic attestations of attributes should, at the moment of their issuance, ensure with full certainty the identification of that person. Moreover, in addition to the mandatory verification of the identity of the person, if applicable for the issuance of qualified certificates and when issuing a qualified electronic attestation of attributes, qualified trust service providers should ensure with full certainty the correctness and accuracy of the attested attributes of the person to whom the qualified certificate or the qualified electronic attestation of attributes is issued. These obligations of result and full certainty in verifying the attested data should be supported by appropriate means, including by using one or, when required, a combination of specific methods prescribed by this Regulation. These methods may be combined to provide an appropriate basis for the verification of the identity of the person to whom the qualified certificate or a qualified electronic attestation of attributes is issued. Such a combination may include the reliance on electronic identification means which meet the requirements of level of assurance ‘substantial’ in combination with other supplementary means of identity verification which would allow the fulfillment of the harmonized requirements set out in this Regulation as regards level of assurance 'high' as part of additional harmonized remote procedures which ensures the identification of the person with a high level of confidence. Those methods should include the possibility for the qualified trust service provider issuing a qualified electronic attestation of attributes to verify the attributes to be attested by electronic means at the request of the user and in accordance with national or Union law, including against authentic sources.

▌ (36g) To keep this Regulation in line with global developments and to follow the best practices on the internal market, the delegated and implementing acts adopted by the Commission should be reviewed and if necessary updated on a regular basis. The assessment of the necessity of these updates should take into account new technologies, practices, standards or technical specifications.

(37) The European Data Protection Supervisor has been consulted pursuant to Article 42 (1) of Regulation (EU) 2018/1525 of the European Parliament and of the Council8.

(38) Regulation (EU) 910/2014 should therefore be amended accordingly,

HAVE ADOPTED THIS REGULATION:

Article 1

Regulation (EU) 910/2014 is amended as follows:

(1) Article 1 is replaced by the following:

‘This Regulation aims at ensuring the proper functioning of the internal market and providing an adequate level of security of electronic identification means and trust services used across the Union in order to enable and to facilitate the exercise of the right to safely participate in the digital society and the access to online public and private services throughout the Union for any natural or legal person. For these purposes, this Regulation:

(a) lays down the conditions under which Member States shall provide and recognise electronic identification means of natural and legal persons, falling under a notified electronic identification scheme of another Member State;

(aa) lays down the conditions under which Member States shall provide and recognise European Digital Identity Wallets;

(b) lays down rules for trust services, in particular for electronic transactions;

(c) establishes a legal framework for electronic signatures, electronic seals, electronic time stamps, electronic documents, electronic registered delivery services, certificate services for website authentication, electronic archiving, electronic attestation of attributes, ▌ electronic signature and seal creation devices, and electronic ledgers;

▌ ’

(2) Article 2 is amended as follows:

(a) paragraph 1 is replaced by the following:

‘1. ▌ This Regulation applies to electronic identification schemes that have been notified by a Member State, European Digital Identity Wallets provided by Member States and to trust service providers that are established in the Union.’;’

(b) paragraph 3 is replaced by the following:

‘3. This Regulation does not affect national or Union law related to the conclusion and validity of contracts or other legal or procedural obligations relating to form or sector-specific requirements relating to form.’;

3a. This Regulation shall be without prejudice to Regulation (EU) 2016/679.’

(3) Article 3 is amended as follows:

(-a) point (1) is replaced by the following:

(1) ‘electronic identification’ means the process of using person identification data in electronic form uniquely representing either a natural or legal person, or a natural person representing a natural or legal person;’

(-b) point (3) is replaced by the following:

(3) ‘person identification data’ means a set of data, issued in accordance with Union or national law, enabling the identity of a natural or legal person, or of a natural person representing a natural or legal person, to be established.

(ba) point (5) is replaced by the following:

(5) ‘authentication’ means an electronic process that enables the electronic identification of a natural or legal person to be confirmed, or the origin and integrity of data in electronic form to be confirmed;

(a) point (2) is replaced by the following:

‘(2) ‘electronic identification means’ means a material and/or immaterial unit ▌ containing person identification data and which is used for authentication to an online service or, where appropriate, to an offline service;’

▌ ’

(b) point (4) is replaced by the following:

‘(4) ‘electronic identification scheme’ means a system for electronic identification under which electronic identification means ▌ are issued to natural or legal persons or natural persons representing natural or legal persons;’;

(6) ‘relying party’ means a natural or legal person that relies upon an electronic identification, European Digital Identity Wallets or other electronic identification means, or a trust service;’

(bb) the following point (5a) is inserted:

(5a) ‘user’ means a natural or legal person, or a natural person representing a natural or legal person, using trust services or electronic identification means, provided according to this Regulation;

(c) point (14) is replaced by the following:

‘(14) ‘certificate for electronic signature’ means an electronic attestation ▌ which links electronic signature validation data to a natural person and confirms at least the name or the pseudonym of that person';’

(d) point (16) is replaced by the following:

‘(16) ‘trust service’ means an electronic service normally provided for remuneration which consists of:

(a) the issuing of certificates for electronic signatures, of certificates for electronic seals, of certificates for website authentication or of certificates for the provision of other trust services;

(aa) the validation of certificates for electronic signatures, of certificates for electronic seals, of certificates for website authentication or of certificates for the provision of other trust services;

(b) the creation of electronic signatures or of electronic seals;

(c) the validation of electronic signatures or of electronic seals;

(d) the preservation of electronic signatures, of electronic seals, of certificates for electronic signatures or of certificates for electronic seals;

(e) the management of remote electronic signature creation devices or of remote electronic seal creation devices;

(f) the issuing of electronic attestations of attributes;

(fa) the validation of electronic attestation of attributes;

(fb) the creation of electronic timestamps;

(fc) the validation of electronic timestamps;

(fd) the provision of electronic registered delivery services;

(fe) the validation of data transmitted through electronic registered delivery services and related evidence;

(ff) the electronic archiving of electronic data; or

(fg) the recording of electronic data into an electronic ledger;’

(da) point (18) is replaced by the following:

(18) ‘conformity assessment body’ means a body defined in point 13 of Article 2 of Regulation (EC) No 765/2008, which is accredited in accordance with that Regulation as competent to carry out conformity assessment of a qualified trust service provider and the qualified trust services it provides, or to carry out certification of European Digital Identity Wallets or electronic identification means;

(e) point (21) is replaced by the following:

‘(21) ‘product’ means hardware or software, or relevant components of hardware and / or software, which are intended to be used for the provision of electronic identification and trust services;;’

(f) the following points (23a) and (23b) are inserted:

‘(23a) ‘remote qualified electronic signature creation device’ means a qualified electronic signature creation device managed by a qualified trust service provider in accordance with Article 29a on behalf of a signatory;

(23b) ‘remote qualified electronic seal creation device’ means a qualified electronic seal creation device managed by a qualified trust service provider in accordance with Article 39a on behalf of a seal creator; ▌’

(g) point (29) is replaced by the following:

‘(29) ‘certificate for electronic seal’ means an electronic attestation ▌ that links electronic seal validation data to a legal person and confirms the name of that person;’;

(ga) points (38) and (39) are replaced by the following:

(38) ‘certificate for website authentication’ means an electronic attestation that makes it possible to authenticate a website and links the website to the natural or legal person to whom the certificate is issued;

(39) ‘qualified certificate for website authentication’ means a certificate for website authentication, which is issued by a qualified trust service provider and meets the requirements laid down in Annex IV;’

(h) point (41) is replaced by the following:

‘(41) ‘validation’ means the process of verifying and confirming that data in electronic form are valid according to the requirements of this Regulation’;’

(i) the following points ▌ are added:

‘(42) ‘European Digital Identity Wallet’ means an electronic identification means, which allows the user to securely store, manage and validate identity data and electronic attestations of attributes, to provide them to relying parties ▌ and to other users of European Digital Identity Wallets, and to sign by means of qualified electronic signatures or to seal by means of qualified electronic seals;

(43) ‘attribute’ means a characteristic, quality, right or permission of a natural or legal person or of an object;

(44) ‘electronic attestation of attributes’ means an attestation in electronic form that allows the authentication of attributes;

(45) ‘qualified electronic attestation of attributes’ means an electronic attestation of attributes, which is issued by a qualified trust service provider and meets the requirements laid down in Annex V;

(45a) ‘electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source’ means an electronic attestations of attributes issued by a public sector body responsible for an authentic source or by a public sector body designated by the Member State to issue such attestations of attributes on behalf of the public sector bodies responsible for authentic sources in accordance with Article 45da and meeting the requirements laid down in Annex VIa;

(46) ‘authentic source’ is a repository or system, held under the responsibility of a public sector body or private entity, that contains and provides attributes about a natural or legal person and is considered to be a primary source of that information or recognised as authentic in accordance with Union or national law, including administrative practice;

(47) ‘electronic archiving’ means a service ensuring the receipt, storage, retrieval and deletion of electronic data and electronic documents in order to guarantee their durability and legibility as well as to preserve their integrity, confidentiality and proof of origin throughout the preservation period;

(48) ‘qualified electronic archiving service’ means an electronic archiving service that meets the requirements laid down in Article 45ga;

(49) ‘EU Digital Identity Wallet Trust Mark’ means a verifiable indication in a simple, recognisable and clear manner that a European Digital Identity Wallet has been provided in accordance with this Regulation;

(50) ‘strong user authentication’ means an authentication based on the use of at least two authentication factors from different categories of either knowledge (something only the user knows), possession (something only the user possesses) or inherence (something the user is) that are independent, in ▌ that the breach of one does not compromise the reliability of the others, and is designed in such a way as to protect the confidentiality of the authentication data;

(53) ‘electronic ledger’ means a sequence of electronic data records, ensuring their integrity and the accuracy of their ▌ chronological ordering’;

(53a) ‘qualified electronic ledger’ means an electronic ledger that meets the requirements laid down in Article 45i;

(54) ‘Personal data’ means any information as defined in point 1 of Article 4 of Regulation (EU) 2016/679.;

(55) ‘identity matching’ means a process where person identification data, or person identification means are matched with or linked to an existing account belonging to the same person ▌ ;’

▌ ‘

(55b) ‘data record’ means electronic data recorded with related meta-data supporting the processing of the data.

(55c) ‘offline use of European Digital Identity Wallets’ means an interaction between a user and a third party at a physical location using close proximity technologies, whereby the Wallet is not required to access remote systems via electronic communication networks for the purpose of the interaction.

(4) Article 5 is replaced by the following:

‘Article 5

Pseudonyms in electronic transaction

Without prejudice to specific rules of Union or national law requiring users to identify themselves and without prejudice to the legal effect given to pseudonyms under national law, the use of pseudonyms, chosen by the user, shall not be prohibited. ▌’

(5) in Chapter II the following section is inserted before Article 6a:

‘SECTION I

EUROPEAN DIGITAL IDENTITY WALLET;’

‘Article 6a

European Digital Identity Wallets

1. For the purpose of ensuring that all natural and legal persons in the Union have secure, trusted and seamless cross-border access to ▌ public and private services, while having full control over their data, each Member State shall provide at least one European Digital Identity Wallet within 24 months after the entry into force of the implementing acts referred to in paragraph 11 and Article 6c(4).

2. European Digital Identity Wallets shall be provided:

(a) directly by a Member State;

(b) under a mandate from a Member State;

(c) independently of a Member State but recognised by that Member State.

2a. The source code of the application software components of the European Digital Identity Wallets shall be open-source licensed. Member States may provide that, for duly justified reasons, specific components other than those installed on user devices shall not be disclosed.

3. European Digital Identity Wallets are electronic identification means that shall enable the user in a manner that is user-friendly, transparent, and traceable by the user to:

(a) securely request, obtain, select, combine, store, delete, share and present, under the sole control of the user, person identification data and, where applicable, in combination with electronic attestations of attributes, to authenticate to relying parties online and, where appropriate, offline in order to use public and private services, while ensuring that selective disclosure of data is possible;▌

(ac) generate pseudonyms and store them encrypted and locally within it;

(ad) securely authenticate another person’s European Digital Identity Wallet, and receive and share identity data and electronic attestations of attributes in a secured way between the two wallets.

(ae) access a log of all transactions carried out through the European Digital Identity Wallet via a common dashboard enabling the user to:

(i) view an up to date list of relying parties with whom the user has established a connection and where applicable all data exchanged;

(ii) easily request to a relying party the deletion of personal data pursuant to Article 17 of the Regulation (EU) 2016/679);

(iii) easily report to the national data protection authority where a relying party is established when an allegedly unlawful or suspicious request of data is received.

(b) sign by means of qualified electronic signatures and seal by means of qualified electronic seals.

(ba) download, to the extent technically feasible, users' data, electronic attestation of attributes and configurations;

(bb) exercise users’ rights to data portability.

4. European Digital Identity Wallets shall, in particular:

(a) support common protocols and interfaces:

(1) for issuance of person identification data, qualified and non-qualified electronic attestations of attributes or ▌ qualified and non-qualified ▌ certificates to the European Digital Identity Wallet;

(2) for relying parties to request and validate person identification data and electronic attestations of attributes;

(3) for the sharing and presentation to relying parties of person identification data, electronic attestation of attributes or of selectively disclosed related data online and, where appropriate, also offline;

(4) for the user to allow interaction with the European Digital Identity Wallet and display an “EU Digital Identity Wallet Trust Mark”;

(4a) to securely on-board the user with the electronic identification means associated pursuant to Article 6a(11a);

(4c) for interaction with another person’s European Digital Identity Wallet for the purpose of receiving, validating and sharing identity data and electronic attestations of attributes in a secured way between two wallets;

(4d) for authenticating relying parties by implementing authentication mechanisms in accordance with Article 6b;

(4e) for relying parties to verify the authenticity and validity of European Digital Identity Wallets;

(4h) for requesting to a relying party the deletion of personal data pursuant to Article 17 of the Regulation (EU) 2016/679);

(4i) for reporting to the national data protection authority where a relying party is established when an allegedly unlawful or suspicious request of data is received;

(4j) for the creation of qualified electronic signatures or seals by means of qualified signature or seal creation devices;

(b) not provide any information to trust service providers of electronic attestations of attributes ▌ about the use of these attributes;

(ba) Ensure that the identity of relying parties can be validated by implementing authentication mechanisms in accordance with Article 6b;

(c) meet the requirements set out in Article 8 with regards to assurance level “high”, in particular as applied to the requirements for identity proofing and verification, and electronic identification means management and authentication;

(ca) in the case of electronic attestation of attributes with embedded disclosure policies, implement the appropriate mechanism to inform that the requesting relying party or the requesting user of European Digital Identity Wallets have the permission to access it;

(e) ensure that the person identification data, which is available from the electronic identification scheme under which the EUDIW is provided, uniquely represents the natural person, legal person or the natural person representing the natural or legal person, and is associated with the Wallet;

(ec) offer the ability to sign by means of qualified electronic signatures to all natural persons by default and free of charge. Member States may provide for proportionate measures to ensure that the free-of-charge use of qualified electronic signatures by natural persons is for non-professional purposes.

4a. Member State shall inform users, without delay, of any security breach that may have entirely or partially compromised their European Digital Identity Wallet or its content and in particular if their European Digital Identity Wallet has been suspended or revoked pursuant to Article 6da.

(4b) Without prejudice to Article 6db, Member States may provide, in accordance with national law, for additional functionalities of the European Digital Identity Wallets, including interoperability with existing national eID means. Those additional functionalities shall comply with the requirements of this Article.

5. Member States shall provide free-of-charge validation mechanisms to:

(a) ▌ ensure that the authenticity and validity of European Digital Identity Wallets can be verified;

(ca) allow European Digital Identity Wallet users to verify the authenticity and validity of the identity of relying parties registered in accordance with Article 6b.

5a. Member States shall provide means to revoke the validity of the European Digital Identity Wallet

(a) upon the explicit request of the user;

(b) when its security has been compromised;

(c) upon the death of the user or cease of activity of the legal person.

5c. Providers of European Digital Identity Wallets shall ensure that users can easily request technical support and report technical problems or any other incidents having a negative impact on the provision of services of the European Digital Identity Wallet.

6. The European Digital Identity Wallets shall be provided under a ▌ electronic identification scheme of level of assurance ‘high’. ▌

6a. European Digital Identity Wallets shall ensure security-by-design.

6b. The issuance, use and revocation of the European Digital Identity Wallets shall be free of charge to all natural persons.

7. The users shall be in full control of the use of the European Digital Identity Wallet and of the data in their European Digital Identity Wallet. The provider of the European Digital Identity Wallet shall not collect information about the use of the wallet which are not necessary for the provision of the wallet services, nor shall it combine person identification data and any other personal data stored or relating to the use of the European Digital Identity Wallet with personal data from any other services offered by this provider or from third-party services which are not necessary for the provision of the wallet services, unless the user has expressly requested it. Personal data relating to the provision of European Digital Identity Wallets shall be kept ▌ logically separate from any other data held by the provider of European Digital Identity Wallets. If the European Digital Identity Wallet is provided by private parties in accordance to paragraph 2 (b) and (c), the provisions of article 45f paragraph 4 shall apply mutatis mutandis.

7a. The use of the European Digital Identity Wallet shall be voluntary. Access to public and private services, access to labour market and freedom to conduct business shall not in any way be restricted or made disadvantageous for natural or legal persons not using European Digital Identity Wallets. It shall remain possible to access public and private services by other existing identification and authentication means.

7b. The technical framework of the European Digital Identity Wallet shall:

(a) not allow providers of electronic attestations of attributes or any other party, after the issuance of the attestation of attributes, to obtain data that allows for tracking, linking, correlating or otherwise obtain knowledge of transactions or user behaviour unless explicitly authorised by the user.

(b) enable privacy preserving techniques which ensure unlinkability, where attestation of attributes do not require the identification of the user.

7c. Any processing of personal data carried out by the Member States or on their behalf by bodies or parties responsible for the provision of the European Digital Identity Wallets as electronic identification means shall implement appropriate and effective measures and be able to demonstrate the compliance of processing activities with Regulation (EU) 2016/679. Member States shall be allowed to introduce national provisions to further specify the application of such rules.

7d. Member States shall notify to the Commission, without undue delay information about:

(a) the body responsible for establishing and maintaining the list of registered relying parties that rely on the European Digital Identity Wallets in accordance with Article 6b(1e), and the location of such a list;

(b) the bodies responsible for the provision of the European Digital Identity Wallets in accordance with Article 6a(1);

(c) the bodies responsible for ensuring that the person identification data is associated with the Wallet in accordance with Article 6a(4)(e);

(d) the mechanism allowing for the validation of the person identification data referred to in 6a(4)(e) and of the identity of the relying parties.

(e) the mechanism to validate the authenticity and validity of the European Digital Identity Wallets.

The Commission shall make available to the public, through a secure channel, the information referred in this paragraph in electronically signed or sealed form suitable for automated processing.

8. Article 11 shall apply mutatis mutandis to the European Digital Identity Wallet without prejudice to Art.6a(10a).

9. Article 24(2), points (b), (d), (e), (f), (fa), (fb), (g), and (h) shall apply mutatis mutandis to the providers of European Digital Identity Wallets.

10. The European Digital Identity Wallet shall be made accessible for use, in accordance with Directive 2019/882, by persons with disabilities, on an equal basis with other users.

10a. For the purposes of the provision of the EUDIW, the EUDIW and the electronic identification schemes under which they are provided shall not be subject to the requirements referred to in Articles 7, 9, 10, 12 and 12a.

11. By … [6 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for the requirements referred to in paragraphs 3, 4, 5 and 7c on the implementation of the European Digital Identity Wallet. These implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

11a. The Commission shall reference standards and when necessary establish technical and operational specifications in order to facilitate the on-boarding to the European Digital Identity Wallet of users using either electronic identification means conforming to level ‘high’ or electronic identification means conforming to level ‘substantial’ in conjunction with additional remote on-boarding procedures that together meet the requirements of level of assurance ‘high’. This implementing act shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 6b

European Digital Identity Wallets Relying Parties

1. Where a relying party intends to rely upon European Digital Identity Wallets for the provision of public or private services it shall register in the Member State where the relying party is established ▌ .

1a. The registration process shall be cost-effective and proportionate-to-risk. Relying parties shall provide at least: a) the information necessary to authenticate to European Digital Identity Wallets, which as a minimum includes:

i) the Member State in which they are established and

ii) the name of the relying party and, where applicable, its registration number as stated in an official record together with identification data of that official record;

b) contact details;

c) the intended use of the European Digital Identity Wallet, including the data to be requested.

1c. Relying parties shall not request any data beyond what they have registered for according to paragraphs 1 and 1a.

1d. Paragraphs 1 and 1a shall be without prejudice to requirements in accordance with Union or national law, applicable for the provision of specific services.

1e. Member States shall make the information referred to in paragraph 1a publicly available online in electronically signed or sealed form suitable for automated processing.

1g. Relying parties registered in accordance with this Article shall inform Member States without delay about any changes in to the information provided.

2. Member States shall provide a common mechanism for allowing the identification and authentication of relying parties, as referred to in Article 6a(4)(ba) [GA].

2a. Where relying parties intend to rely upon European Digital Identity Wallets issued in accordance with this Regulation, they shall identify themselves to the user of the European Digital Identity Wallet.

3. Relying parties shall be responsible for carrying out the procedure for authenticating and validating person identification data and electronic attestation of attributes requested from European Digital Identity Wallets. Relying parties shall not refuse the use of pseudonyms, where the identification of the user is not required by Union or national law.

3a. Intermediaries acting on behalf of relying parties are to be considered relying parties and shall not store data about the content of the transaction.

4. By ... [6 months after the date of the entering into force of this amending Regulation], the Commission shall establish technical and operational specifications for the requirements referred to in paragraphs 1a, 1e, 1g, 2, 2a and 3 by means of an implementing act on the implementation of the European Digital Identity Wallets as referred to in Article 6a(11). This implementing act shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 6c

Certification of the European Digital Identity Wallets

1. The conformity of European Digital Identity Wallets and of the electronic identification scheme under which they are provided with the requirements laid down in Article 6a(3), (4), (5), with the requirement for logical separation laid down Article 6a(7) and, where applicable, in accordance with standards and technical specifications referred to in Article 6a(11a), shall be certified by conformity assessment bodies designated by Member States.

2. Certification of the conformity of European Digital Identity Wallets with cybersecurity relevant requirements referred to in paragraph 1, or parts thereof, shall be carried out in accordance with cybersecurity schemes adopted pursuant to Regulation (EU) 2019/881 and referenced in the implementing acts referred to in paragraph 4.

2a. For those non-cybersecurity requirements referred to in paragraph1 and, for as long as cybersecurity certification schemes referred to in paragraph 2 do not or do not fully cover the relevant cybersecurity requirements, for those requirements, Member States shall establish national certification schemes following the requirements set out in the implementing acts referred to in paragraph 4. Member States shall transmit their draft national certification schemes to the EDICG, which may issue opinions and recommendations.

2b. The certification referred to in paragraph 1 shall be valid for not more than five years, conditional upon a regular two-year vulnerabilities assessment.

3. Compliance with the requirements set out in Article 6a related to the personal data processing operations may be certified pursuant to Regulation (EU) 2016/679.

4. By ... [6 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary establish specifications and procedures for the certification of the European Digital Identity Wallets referred to in paragraph 1 to 2a. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2) of this Regulation.

5. Member States shall communicate to the Commission the names and addresses of the ▌conformity assessment bodies referred to in paragraph ▌1. The Commission shall make that information available to all Member States.

6. The Commission shall be empowered to adopt ▌delegated acts in accordance with Article 47 establishing specific criteria to be met by the designated conformity assessment bodies referred to in paragraph 1 of this Article.

Article 6d

Publication of a list of certified European Digital Identity Wallets

1. Member States shall inform the Commission and the EDICG referred to in Art.46e without undue delay of the European Digital Identity Wallets that have been provided pursuant to Article 6a and certified by the conformity assessment bodies referred to in Article 6c paragraph 1. They shall also inform the Commission and the EDICG referred to in Art.46e, without undue delay where the certification is cancelled and state the reasons for such cancellation.

1a. Without prejudice to Art.6a(7c), the information provided by Member States referred to in paragraph 1 shall include at least:

a) the certificate and certification assessment report of the certified EUDIW;

b) a description of the electronic identification scheme under which the EUDIW is provided;

c) the applicable supervisory regime and information on the liability regime with respect to the party providing the EUDIW;

d) the authority or authorities responsible for the electronic identification scheme;

e) arrangements for suspension or revocation of either the notified electronic identification scheme or authentication or the compromised parts concerned.

2. On the basis of the information received, the Commission shall establish, publish, maintain and update in a machine-readable form a list of certified European Digital Identity Wallets.

2a. A Member State may submit to the Commission a request to remove an EUDIW and the electronic identification scheme under which it is provided from the list referred to in paragraph 2. A Member State shall submit updates to the provided information referred to in paragraph 1. The Commission shall publish in the list referred to in paragraph 2 the corresponding amendments to the list within one month from the date of receipt of the Member State’s request or updated information.

3. By ... [6 months after the date of entry into force of this amending Regulation], the Commission shall define formats and procedures applicable for the purposes of paragraph 1 and 2a by means of an implementing act on the implementation of the European Digital Identity Wallets as referred to in Article 6a(11). This implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Article

6da

Security breach of the European Digital Identity Wallets

1. Where European Digital Identity Wallets provided pursuant to Article 6a or the validation mechanisms referred to in Article 6a(5), or the electronic identification scheme under which the wallets are provided, are breached or partly compromised in a manner that affects their reliability or the reliability of other European Digital Identity Wallets, the providing Member State shall, without undue delay, suspend the provision and the use of the European Digital Identity Wallet. The Member States where concerned Wallets were provided shall inform the affected users, the single points of contact designated pursuant to Article 46c, the relying parties and the Commission accordingly.

2. If the breach or compromise referred to in paragraph 1 is not remedied within three months of the suspension, the Member State concerned shall withdraw the European Digital Identity Wallets concerned and have their validity revoked. Member States concerned shall inform the affected users, the single points of contact designated pursuant to Article 46c, the relying parties and the Commission of the withdrawal accordingly. Where it is justified by the severity of the breach, the European Digital Identity Wallet concerned shall be withdrawn without undue delay.

3. Where the breach or compromise referred to in paragraph 1 is remedied, the providing Member State shall re-establish the issuance and the use of the European Digital Identity Wallets and inform the affected users and relying parties, the single points of contact designated pursuant to Article 46c and the Commission without undue delay.

4. The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list referred to in Article 6d without undue delay.

5. By … [6 months after the entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish the reference standards and when necessary, establish specifications and procedures for the measures referred to in paragraphs 1, 2 and 3. These implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article

6db

Cross-border reliance on European Digital Identity Wallets

1. Where Member States require an electronic identification and authentication to access an online service provided by a public sector body, they shall also accept European Digital Identity Wallets provided in accordance with this Regulation.

2. Where private relying parties providing services, with the exception of microenterprises and small enterprises as defined in Commission Recommendation 2003/361/EC, are required by national or Union law to use strong user authentication for online identification or where strong user authentication for online identification is required by contractual obligation, including in the areas of transport, energy, banking, financial services, social security, health, drinking water, postal services, digital infrastructure, education or telecommunications, private relying parties shall, no later than 36 months after the entry into force of the implementing acts referred to in [Article 6a] paragraph 11 and Article 6c(4)] and strictly upon voluntary request of the user, also accept the use of European Digital Identity Wallets provided in accordance with this Regulation.

3. Where providers of very large online platforms as referred to in Article 33 of Regulation (EU) 2022/2065 require users to authenticate to access online services, they shall also accept and facilitate the use of European Digital Identity Wallets provided in accordance with this Regulation, for authentication of the user strictly upon voluntary request of the user and in respect of the minimum data necessary for the specific online service for which authentication is requested.

4. In cooperation with Member states, the Commission shall facilitate the development of codes of conduct in close collaboration with all relevant stakeholders, including civil society, in order to contribute to wide availability and usability of European Digital Identity Wallets within the scope of this Regulation, and to encourage service providers to complete the development of codes of conduct.

5. Within 24 months after deployment of the European Digital Identity Wallets, the Commission shall carry out an assessment on demand, availability and usability of the European Digital Identity Wallets, considering criteria such as users’ take up, cross-border presence of service providers, technological developments, evolution in usage patterns and consumer demand. ’

(8) the following heading is inserted before Article 7:

‘SECTION II

ELECTRONIC IDENTIFICATION SCHEMES;’

(9a) In Article 7 point (g) is replaced by the following:

‘(g) at least six months prior to the notification pursuant to Article 9(1), the notifying Member State provides the other Member States for the purposes of the obligation under Article 12(5) a description of that scheme in accordance with the procedural arrangements established by the implementing acts referred to in Article 12(6);’

(9b) In Article 8, paragraph 3, the introductory paragraph is replaced by the following:

‘3. By 18 September 2015, taking into account relevant international standards and subject to paragraph 2, the Commission shall, by means of implementing acts, set out minimum technical specifications, standards and procedures with reference to which assurance levels low, substantial and high are specified for electronic identification means.’

(10) in Article 9 paragraphs 2 and 3 are replaced by the following:

‘2. The Commission shall, without undue delay, publish in the Official Journal of the European Union a list of the electronic identification schemes which were notified pursuant to paragraph 1 of this Article and the basic information thereon.

3. The Commission shall publish in the Official Journal of the European Union the amendments to the list referred to in paragraph 2 within one month from the date of receipt of that notification.;

(10a) In Article 10, the title is replaced by the following:

▌ Security breach of electronic identification schemes’

(12) the following Article ▌ is inserted:

‘Article 11a

Cross-border identity matching

1. Member States, when acting as relying parties for cross-border services shall ensure unequivocal identity matching for natural persons using notified electronic identification means or European Digital Identity Wallets.

2b. Member States shall provide for technical and organisational measures to ensure high level of protection of personal data used for identity matching and to prevent the profiling of users.

3. By … [6 months after the date of entry into force of this amending Regulation], the Commission shall establish the reference standards and when necessary, establish specifications and procedures for the requirements referred to in paragraph 1 ▌ by means of an implementing act. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 48(2).

▌ ‘

(13) Article 12 is amended as follows:

(-a) the title is replaced by the following:

(13a) 'Interoperability'

(a) in paragraph 3, point (c) is replaced by the following and point (d) is deleted:

(c) it facilitates the implementation of privacy and security by design;

(b) in paragraph 4, point (d) is replaced by the following:

‘(d) a reference to a minimum set of person identification data necessary to uniquely represent a natural person, legal person or a natural person representing natural or legal persons which is available from electronic identification schemes;’

(ba) paragraph 5 is replaced by the following:

▌ ▌

(5) Member States shall carry out peer reviews of electronic identification schemes falling under this Regulation, to be notified pursuant to Article 9(1).

(b) ▌ paragraph 6 ▌ is replaced by the following:

(6) By 18 March 2025, the Commission shall, by means of implementing acts, establish the necessary procedural arrangements for the peer reviews referred to in paragraph 5 with a view to fostering a high level of trust and security appropriate to the degree of risk.

▌ ▌

▌ ▌

(ca) paragraph 7 is deleted;

(e) Paragraph 8 is replaced by the following:

(8) By 18 September 2025, for the purpose of setting uniform conditions for the implementation of the requirement under paragraph 1, the Commission shall, subject to the criteria set out in paragraph 3 and taking into account the results of the cooperation between Member States, adopt implementing acts on the interoperability framework as set out in paragraph 4.

(cb) paragraph 9 is replaced by the following:

(9) The implementing acts referred to in paragraphs 6 and 8 of this Article shall be adopted in accordance with the examination procedure referred to in Article 48(2).;

(14) the following Article 12a is inserted:

‘Article 12a

Certification of electronic identification schemes

1. The conformity of ▌ electronic identification schemes to be notified with cybersecurity requirements laid down in this Regulation shall be certified by conformity assessment bodies designated by Member States.

2. Certification referred to in paragraph 1 including the conformity with cybersecurity relevant requirements set out in Article 8(2) regarding the assurance levels of electronic identification schemes shall be carried out under a relevant ▌ cybersecurity certification scheme ▌ pursuant to Regulation (EU) 2019/881 or parts thereof, in so far as the cybersecurity certificate or parts thereof cover those cybersecurity requirements.

2a. The certification referred to in paragraph 1 shall be valid for not more than five years, conditional upon a regular two-year vulnerabilities assessment. Where vulnerabilities are identified and not remedied within three months, the certification shall be cancelled.

2b. Notwithstanding paragraph 2 of this Article, Member States may request additional information about electronic identification schemes or part thereof certified according to paragraph 2 of this Article from a notifying Member State.

2c. The peer-review of electronic identification schemes referred to in paragraph 5.c of Article 46e shall not apply to electronic identification schemes or part of such schemes certified in accordance with paragraph 1 of this Article. Member States may use a certificate or a statement of conformity, issued in accordance with a relevant certification scheme or parts of such schemes, with the non-cybersecurity requirements set out in Article 8(2) of this Regulation regarding the assurance levels of electronic identification schemes.

3. Member States shall communicate to the Commission ▌ the names and addresses of the conformity assessment bodies referred to in paragraph 1. The Commission shall make that information available to all Member States.;

‘Article 12b

Access to hardware and software features

When providers of European Digital Identity Wallets and issuers of notified electronic identification means acting in a commercial or professional capacity and using core platform services as defined in Article 2(2) of Regulation (EU) 2022/1925 for the purpose of, or in the course of, providing European Digital Identity Wallet services and electronic identification means to end-users are business users in accordance with Article 2(21) of Regulation (EU) 2022/1925, gatekeepers shall allow them, free of charge, effective interoperability with, and access for the purposes of interoperability to the same operating system, hardware or software features, regardless of whether those features are part of the operating system, as are available to, or used by, that gatekeeper when providing such services, within the meaning of Article 6(7) of Regulation (EU) 2022/1925. This provision is without prejudice to Article 6a(7).’

(17) In Article 13, paragraph 1 is replaced by the following:

‘1. ▌ Notwithstanding paragraph 2 of this Article and without prejudice to Regulation (EU) 2016/679, trust service providers shall be liable for damage caused intentionally or negligently to any natural or legal person due to a failure to comply with the obligations under this Regulation. Any natural or legal person who has suffered material or non-material damage as result of an infringement of this Regulation by trust service providers shall have the right to seek compensation in accordance with Union and national law. ▌

The burden of proving intention or negligence of a non-qualified trust service provider shall lie with the natural or legal person claiming the damage referred to in the first subparagraph.

The intention or negligence of a qualified trust service provider shall be presumed unless that qualified trust service provider proves that the damage referred to in the first subparagraph occurred without the intention or negligence of that qualified trust service provider.’

(18) Article 14 is replaced by the following:

‘Article 14

International aspects

1. Trust services provided by trust service providers established in a third country or by an international organisation shall be recognised as legally equivalent to qualified trust services provided by qualified trust service providers established in the Union where the trust services originating from the third country or international organisation are recognised under an implementing decision or an agreement concluded between the Union and the third country or international organisation in accordance with Article 218 of the Treaty.

2. The implementing decisions and agreements referred to in paragraph 1 shall ensure that the requirements applicable to qualified trust service providers established in the Union and the qualified trust services they provide are met by the trust service providers in the third country or international organisations and by the trust services they provide. Third countries and international organisations shall in particular establish, maintain and publish a trusted list of recognised trust service providers. ▌

(2a) The agreements referred to in paragraph 1 shall ensure that the qualified trust services provided by qualified trust service providers established in the Union are recognised as legally equivalent to trust services provided by trust service providers in the third country or international organisation with which the agreement is concluded.

2b. The implementing decisions referred to in paragraph 1 shall be adopted in accordance with the examination procedure referred to in Article 48(2).’

(19) Article 15 is replaced by the following:

‘Article 15

Accessibility for persons with disabilities and special needs

The provision of electronic identification means, trust services and end-user products used in the provision of those services shall be made available in plain and intelligible language and in accordance with the United Nations Convention on the Rights of Persons with Disabilities. Further, alignment with the requirements set out in Annex I of Directive (EU) 2019/8821, should also benefit persons who experience functional limitations, such as elderly people, and persons with limited access to digital technologies. ▌

(19a) Article 16 is replaced by the following:

Article 16

Penalties

1. Without prejudice to Article 31 of the Directive (EU) 2022/2555 , Member States shall lay down the rules on penalties applicable to infringements of this Regulation. The penalties shall be effective, proportionate and dissuasive,

2. Member States shall ensure that infringements by qualified and non-qualified trust service providers of the obligations of this Regulation be subject to administrative fines of a maximum of at least EUR 5,000,000 when the trust service provider is a natural persons or EUR 5,000,000 or 1% of the total worldwide annual turnover of the undertaking to which the trust service provider belonged in the financial year preceding the year in which the infringement occurred, whichever is higher.

3. Depending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fine is initiated by the competent supervisory authority and imposed by competent national courts. The application of such rules in those Member States shall ensure that those legal remedies are effective and have an equivalent effect to administrative fines imposed directly by supervisory authorities.’

(20) Articles 17, 18 and 19 are deleted.

(21a) The following Article is inserted:

Article 19a

‘Requirements for non-qualified trust service providers’

1. A non-qualified trust service provider providing non-qualified trust services shall:

(a) have appropriate policies and take corresponding measures to manage legal, business, operational and other direct or indirect risks to the provision of the non-qualified trust service. Notwithstanding the provisions of Article 18 of Directive EU 2022/2555, those measures shall include at least the following:

(i) measures related to registration and on-boarding procedures to a trust service;

(ii) measures related to procedural or administrative checks needed to provide trust services;

(iii) measures related to the management and implementation of trust services.

(b) notify the supervisory body, the identifiable affected individuals, the public if it is of public interest and, where applicable, other relevant competent authorities, of any breaches or disruptions in the provision of the service or the implementation of the measures referred to in paragraph (a), points (i), (ii) and (iii) that have a significant impact on the trust service provided or on the personal data maintained therein, without undue delay and in any case no later than 24 hours after having become aware of any breaches or disruptions.

2. By [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards, and when necessary, establish specifications and procedures for paragraph 1(a). Compliance with the requirements laid down in this Article shall be presumed where those standards, specifications and procedures are met. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

(22) Article 20 is amended as follows:

(a) paragraph 1 is replaced by the following

‘1. Qualified trust service providers shall be audited at their own expense at least every 24 months by a conformity assessment body. the audit shall confirm that the qualified trust service providers and the qualified trust services provided by them fulfil the requirements laid down in this Regulation and in Article 21 of Directive (EU) 2022/2555. qualified trust service providers shall submit the resulting conformity assessment report to the supervisory body within three working days of receipt.;’

(aa) the following paragraphs 1a and 1b are inserted:

1a. Qualified trust service providers shall inform the supervisory body at the latest one month in advance about planned audits and allow for the participation of the supervisory body as an observer upon request.

1b. Member States shall notify, without undue delay, to the Commission the names, addresses and accreditation details of the conformity assessment bodies referred to in paragraph 1 and any subsequent changes thereto. The Commission shall make that information available to all Member States.

(b) in paragraph 2, the last sentence is replaced by the following

‘Where personal data protection rules appear to have been breached, the supervisory body shall, without undue delay, inform the competent supervisory authorities under Regulation (EU) 2016/679 ▌ .’;’

(c) paragraphs 3 and 4 are replaced by the following:

‘3. Where the qualified trust service provider fails to fulfil any of the requirements set out by this Regulation, the supervisory body shall require it to provide a remedy within a set time limit, if applicable.

Where that provider does not provide a remedy and, where applicable within the time limit set by the supervisory body, the supervisory body, where justified in particular by the extent, duration and consequences of that failure, shall withdraw the qualified status of that provider or of the affected service it provides ▌ .

3a. Where the supervisory body is informed by the national competent authorities under Directive (EU) 2022/2555 that the qualified trust service provider fails to fulfil any of the requirements set out by Article 21 of Directive (EU) 2022/2555, the supervisory body, where justified in particular by the extent, duration and consequences of that failure, shall withdraw the qualified status of that provider or of the affected service it provides.

3b. Where the supervisory body is informed by the supervisory authorities under Regulation (EU) 2016/679 that the qualified trust service provider fails to fulfil any of the requirements set out by Regulation (EU) 2016/679, the supervisory body, where justified in particular by the extent, duration and consequences of that failure, shall withdraw the qualified status of that provider or of the affected service it provides.

3c. The supervisory body shall inform the qualified trust service provider of the withdrawal of its qualified status or of the qualified status of the service concerned. The supervisory body shall inform the body referred to in Article 22(3) for the purposes of updating the trusted lists referred to in Article 22(1) and the national competent authority referred to in Directive (EU) 2022/2555.

4. By ... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for the following ▌ :

(a) the accreditation of the conformity assessment bodies and for the conformity assessment report referred to in paragraph 1;

(b) the auditing requirements for the conformity assessment bodies to carry out their conformity assessment, including composite assessment, of the qualified trust service providers as referred to in paragraph 1 ▌ ;

(c) the conformity assessment schemes for carrying out the conformity assessment of the qualified trust service providers by the conformity assessment bodies and for the provision of the ▌ report referred to in paragraph 1.

Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).;’

(23) Article 21 is amended as follows:

(a) paragraph 1 is replaced by the following:

1. Where trust service providers intend to start providing a qualified trust service, they shall submit to the supervisory body a notification of their intention together with a conformity assessment report issued by a conformity assessment body confirming the fulfilment of the requirements laid down in this Regulation and in Article 21 of Directive (EU) 2022/2555.’;

(b) paragraph 2 is replaced by the following:

‘2. The supervisory body shall verify whether the trust service provider and the trust services provided by it comply with the requirements laid down in this Regulation, and in particular, with the requirements for qualified trust service providers and for the qualified trust services they provide.

In order to verify the compliance of the trust service provider with the requirements laid down in Article 21 of Directive (EU) 2022/2555, the supervisory body shall request the competent authorities referred to in Directive (EU) 2022/2555 to carry out supervisory actions in that regard and to provide information about the outcome without undue delay, and no later than two months from the receipt of this request by the competent authorities referred to in Directive (EU) 2022/2555. If the verification is not concluded within two months of the notification, the competent authorities referred to in Directive (EU) 2022/2555 shall inform the supervisory body specifying the reasons for the delay and the period within which the verification is to be concluded.

Where the supervisory body concludes that the trust service provider and the trust services provided by it comply with the requirements laid down in this Regulation, the supervisory body shall grant qualified status to the trust service provider and the trust services it provides and inform the body referred to in Article 22(3) for the purposes of updating the trusted lists referred to in Article 22(1), not later than three months after notification in accordance with paragraph 1 of this Article.

Where the verification is not concluded within three months of notification, the supervisory body shall inform the trust service provider specifying the reasons for the delay and the period within which the verification is to be concluded.;’

(c) paragraph 4 is replaced with the following:

‘4. By ... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, define the formats and procedures of the notification and verification for the purposes of paragraphs 1 and 2 ▌ . Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;’

(25) Article 24 is amended as follows:

(a) paragraph 1 is replaced by the following:

‘1. ▌ When issuing a qualified certificate or a qualified electronic attestation of attributes ▌ , a qualified trust service provider shall verify the identity and, if applicable, any specific attributes of the natural or legal person to whom the qualified certificate or the qualified electronic attestation of attributes will be issued. ▌

The verification of the identity referred to in the first subparagraph shall be verified, by appropriate means, by the qualified trust service provider, either directly or by relying on a third party, based on one of the following methods or on a combination thereof when needed, and in accordance with the implementing acts referred to in paragraph 1a:

(a) by means of the European Digital Identity Wallet or a notified electronic identification means which meets the requirements set out in Article 8 with regard to the assurance level ‘high’;

(b) by means of ▌ a certificate of a qualified electronic signature or of a qualified electronic seal issued in compliance with point (a), (c) or (d).

(c) by using other identification methods ▌ which ensure the identification of the ▌ person with a high level of confidence, the conformity of which shall be confirmed by a conformity assessment body;

(d) through the physical presence of the natural person or of an authorised representative of the legal person by appropriate procedures and in accordance with national laws .▌

(da) The verification of the attributes referred to in the first subparagraph shall be verified, by appropriate means, by the qualified trust service provider, either directly or by relying on a third party, based on one of the following methods or on a combination thereof when needed, and in accordance with the implementing acts referred to in paragraph 1a:

(i) by means of the European Digital Identity Wallet or a notified electronic identification means which meets the requirements set out in Article 8 with regard to the assurance level ‘high’;

(ii) by means of a certificate of a qualified electronic signature or of a qualified electronic seal issued in compliance with point (a), (c) or (d);

(iii) by means of a qualified electronic attestation of attributes;

(iv) by using other methods, which ensure the verification of the attributes with a high level of confidence, the conformity of which shall be confirmed by a conformity assessment body;

(v) through the physical presence of the natural person or of an authorised representative of the legal person by appropriate [evidences,] procedures and in accordance with national laws.‘

(b) the following paragraph ▌ is inserted:

‘1a. By... [12 months after the date of entry into force of this amending Regulation], the Commission shall by means of implementing acts, establish a list of reference standards and when necessary, establish technical specifications and procedures for the verification of identity and attributes in accordance with paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2). ▌’

(c) paragraph 2 is amended as follows:

(-1) point (a) is replaced by the following:

(a) inform the supervisory body at least one month before implementing any change in the provision of its qualified trust services or at least three months in case of an intention to cease those activities. The supervisory body may request additional information or the result of a conformity assessment and may condition the granting of the permission to implement the intended changes to the qualified trust services. If the verification is not concluded within three months of notification, the supervisory body shall inform the trust service provider, specifying the reasons for the delay and the period within which the verification is to be concluded.

(1) points (d) and (e) are replaced by the following:

‘(d) before entering into a contractual relationship, inform, in a clear, comprehensive and easily accessible manner, in a publicly accessible space and individually any person seeking to use a qualified trust service of the precise terms and conditions regarding the use of that service, including any limitations on its use;;

e) use trustworthy systems and products that are protected against modification and ensure the technical security and reliability of the processes supported by them, including using suitable cryptographic techniques;’;’

(2) the new points (fa) and (fb) are inserted:

‘(fa) have appropriate policies and take corresponding measures to manage legal, business, operational and other direct or indirect risks to the provision of the qualified trust service. Notwithstanding the provisions of Article 21 of Directive (EU) 2022/2555, those measures shall include at least the following:

(i) measures related to registration and on-boarding procedures to a service;

(ii) measures related to procedural or administrative checks;

(iii) measures related to the management and implementation of services.

(fb) notify the supervisory body, the identifiable affected individuals, other relevant competent bodies where applicable and, at the request of the supervisory body, the public if it is of public interest, of any breaches or disruptions in the provision of the service or the implementation of the measures referred to in paragraph (fa), points (i), (ii) and, (iii) that have a significant impact on the trust service provided or on the personal data maintained therein, without undue delay and in any case no later than 24 hours after the incident.’; ’

(3) point (g) and (h) are replaced by the following:

‘(g) take appropriate measures against forgery, theft or misappropriation of data or, without right, deleting, altering or rendering data inaccessible;

(h) record and keep accessible for as long as necessary after the activities of the qualified trust service provider have ceased, all relevant information concerning data issued and received by the qualified trust service provider, for the purpose of providing evidence in legal proceedings and for the purpose of ensuring continuity of the service. Such recording may be done electronically; ▌

(i) have an up-to-date termination plan to ensure continuity of service in accordance with provisions verified by the supervisory body under point (i) of Article 46b(4);’

(4) point (j) is deleted;

(d) the following paragraph 4a is inserted:

‘4a. Paragraphs 3 and 4 shall apply accordingly to the revocation of qualified electronic attestations of attributes.’;’

(e) paragraph 5 is replaced by the following:

‘5. By... [12 months after the date of the entering into force of this amending Regulation], ▌ the Commission shall, by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the requirements referred to in paragraph 2(b) to (h) of this Article. Compliance with the requirements laid down in this paragraph of this Article shall be presumed, where those standards, specifications, and procedures are met. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).;’

(f) the following paragraph 6 is inserted:

‘6. The Commission shall be empowered to adopt delegated acts in accordance with Article 47, establishing additional measures referred to in paragraph 2(fa) of this Article.’;

(X) the following Article 24a is inserted:

Article

24a

Recognition of qualified trust services

1. Qualified electronic signatures based on a qualified certificate created in one Member State, and qualified electronic seals based on a qualified certificate issued in one Member State, shall be recognised respectively as qualified electronic signatures and qualified electronic seals in all other Member States.

2. Qualified electronic signature creation devices certified in one Member State, and qualified electronic seal creation devices certified in one Member State, shall be recognised respectively as qualified electronic signature creation devices and qualified electronic seal creation devices in all other Member States.

3. A qualified certificate for electronic signatures, a qualified certificate for electronic seals, a qualified trust service for the management of remote qualified electronic signature creation devices, a qualified trust service for the management of remote qualified electronic seal creation devices, provided in one Member State shall be respectively recognised as a qualified certificate for electronic signatures, a qualified certificate for electronic seals, a qualified trust service for the management of remote qualified electronic signature creation devices, a qualified trust service for the management of remote qualified electronic seal creation devices in all other Member States.

4. A qualified validation service for qualified electronic signatures, a qualified validation service for qualified electronic seals provided in one Member State shall be respectively recognised as a qualified validation service for qualified electronic signatures and a qualified validation service for qualified electronic seals in all other Member States.

5. A qualified preservation service for qualified electronic signatures, a qualified preservation service for qualified electronic seals provided in one Member State shall be respectively recognised as a qualified preservation service for qualified electronic signatures and a qualified preservation service for qualified electronic seals in all other Member States.

6. A qualified electronic time stamp provided in one Member State shall be recognised as a qualified electronic time stamp in all other Member States.

7. A qualified certificate for website authentication provided in one Member State shall be recognised as a qualified certificate for website authentication in all other Member States.

8. A qualified electronic registered delivery service provided in one Member State shall be recognised as a qualified electronic registered delivery service in all other Member States.

9. A qualified electronic attestation of attributes provided in one Member State shall be recognised as a qualified electronic attestation of attributes in all other Member States.

10. A qualified electronic archiving service provided in one Member State shall be recognised as a qualified electronic archiving service in all other Member States.

11. A qualified electronic ledger provided in one Member State shall be recognised as a qualified electronic ledger in all other Member States.’

(fa) In Article 25, paragraph 3 is deleted.

(fb) Article 26 is amended as follows:

"Article

Requirements for advanced electronic signatures"

2. Within 24 months after the entry into force of this Regulation, the Commission shall carry out an assessment on whether it is necessary to adopt an implementing act, establishing a list of reference standards and when necessary, establishing specifications and procedures for advanced electronic signatures. Based on the outcome of this assessment, the Commission may adopt such an implementing act. Compliance with the requirements for advanced electronic signatures shall be presumed when an advanced electronic signature meets those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

(25a) Article 27(4) is deleted.

(26) In Article 28, paragraph 6 is replaced by the following:

‘6. By... [12 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for qualified certificates for electronic signature. Compliance with the requirements laid down in Annex I shall be presumed where a qualified certificate for electronic signature meets those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;’

(27) In Article 29, the following new paragraph 1a is added:

‘1a. Generating or managing electronic signature creation data or duplicating such signature creation data for back-up purposes may only be done on behalf of and at the request of the signatory by a qualified trust service provider providing a qualified trust service for the management of a remote ▌ qualified electronic signature creation device.’;’

(28) the following Article ▌ is inserted:

‘Article 29a

Requirements for a qualified service for the management of remote qualified electronic signature creation devices

1. The management of remote qualified electronic signature creation devices as a qualified service may only be carried out by a qualified trust service provider that:

(a) Generates or manages electronic signature creation data on behalf of the signatory;

(b) notwithstanding point (1)(d) of Annex II, may duplicate the electronic signature creation data only for back-up purposes provided the following requirements are met:

(i) the security of the duplicated datasets must be at the same level as for the original datasets;

(ii) the number of duplicated datasets shall not exceed the minimum needed to ensure continuity of the service.

(c) complies with any requirements identified in the certification report of the specific remote qualified signature creation device issued pursuant to Article 30.

2. By... [12 months after the entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish reference standards and, when necessary, technical and operational specifications for the purposes of paragraph 1. These implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).”;’

(29) In Article 30, the following paragraph 3a is inserted:

‘3a. The validity of a certification referred to in paragraph 1 shall not exceed 5 years, conditional upon a regular 2 year vulnerabilities assessment. Where vulnerabilities are identified and not remedied, the certification shall be cancelled.’;’

(30) In Article 31, paragraph 3 is replaced by the following:

‘3. By... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, define formats and procedures applicable for the purpose of paragraph 1. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).;’

(31) Article 32 is amended as follows:

(a) in paragraph 1, the following sub-paragraph is added:

‘Compliance with the requirements laid down in the first sub-paragraph shall be presumed where the validation of qualified electronic signatures meet the standards, specifications and procedures referred to in paragraph 3. ▌’

(b) paragraph 3 is replaced by the following:

‘3. By.... [12 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for the validation of qualified electronic signatures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).;

(31a)

The following Article 32a is inserted:

Article 32a

Requirements for the validation of advanced electronic signatures based on qualified certificates

1. The process for the validation of an advanced electronic signature based on qualified certificate shall confirm the validity of an advanced electronic signature based on qualified certificate provided that:

(a) the certificate that supports the signature was, at the time of signing, a qualified certificate for electronic signature complying with Annex I;

(b) the qualified certificate was issued by a qualified trust service provider and was valid at the time of signing;

(c) the signature validation data corresponds to the data provided to the relying party;

(d) the unique set of data representing the signatory in the certificate is correctly provided to the relying party;

(e) the use of any pseudonym is clearly indicated to the relying party if a pseudonym was used at the time of signing;

(f) the integrity of the signed data has not been compromised;

(g) the requirements provided for in Article 26 were met at the time of signing.

2. The system used for validating the advanced electronic signature based on qualified certificate shall provide to the relying party the correct result of the validation process and shall allow the relying party to detect any security relevant issues.

3. By.... [12 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for the validation of advanced electronic signatures based on qualified certificates. Compliance with the requirements laid down in paragraph 1 shall be presumed where the validation of advanced electronic signature based on qualified certificates meets those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’

(31b)

Article 33 is amended as follows:’

2. By.... [12 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for qualified validation service referred to in paragraph 1. Compliance with the requirements laid down in paragraph 1 shall be presumed where the qualified validation service for qualified electronic signatures meets those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’

(32) Article 34 is replaced by the following:

‘Article 34

Qualified preservation service for qualified electronic signatures

1. A qualified preservation service for qualified electronic signatures may only be provided by a qualified trust service provider that uses procedures and technologies capable of extending the trustworthiness of the qualified electronic signature beyond the technological validity period.

2. Compliance with the requirements laid down in the paragraph 1 shall be presumed where the arrangements for the qualified preservation service for qualified electronic signatures meet the standards, specifications and procedures referred to in paragraph 3.

3. By... [12 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for the qualified preservation service for qualified electronic signatures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2). ▌

(32a)

In Article 36 a new paragraph 2 is added:

2. By... [24 months after the date of the entering into force of this amending Regulation], the Commission shall carry out an assessment on whether it is necessary to adopt an implementing act, establishing a list of reference standards and when necessary, establishing specifications and procedures for advanced electronic seals. Based on the outcome of this assessment, the Commission may adopt such an implementing act. Compliance with the requirements for advanced electronic seals shall be presumed when an advanced electronic seal meets those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

▌ ’

(32a) In Article 35, paragraph 3 is deleted.

(33) Article 37 is amended as follows:

(b) paragraph 4 is deleted.

‘▌ ’

(34) Article 38 is amended as follows:

(a) paragraph 1 is replaced by the following:

‘1. Qualified certificates for electronic seals shall meet the requirements laid down in Annex III. ▌’

(b) paragraph 6 is replaced by the following:

‘6. By... [12 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for qualified certificates for electronic seals. Compliance with the requirements laid down in Annex III shall be presumed where a qualified certificate for electronic seal meets those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’’

(35) the following Article ▌ is inserted:

‘Article 39a

Requirements for a qualified service for the management of remote qualified electronic seal creation devices

Article 29a shall apply mutatis mutandis to a qualified service for the management of remote qualified electronic seal creation devices.’;

(35a)

the following Article 40a is inserted:

Article

40a

Requirements for the validation of advanced electronic seals based on qualified certificates

(1) Article 32a shall apply mutatis mutandis to the validation of advanced electronic seals based on qualified certificates.’;’

(35a) In Article 41, paragraph 3 is deleted.

(36) Article 42 is amended as follows:

(a) the following new paragraph 1a is inserted:

‘1a. Compliance with the requirements laid down in paragraph 1 shall be presumed where the binding of date and time to data and the accuracy of the time source meet the standards, specifications and procedures referred to in paragraph 2.’;’

(b) paragraph 2 is replaced by the following

‘2. By ... [12 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for the binding of date and time to data and for establishing the accuracy of time sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2). ▌’

(37) Article 44 is amended as follows:

(a) the following paragraph 1a is inserted:

1a. Compliance with the requirements laid down in paragraph 1 shall be presumed where the process for sending and receiving data meets the standards and specifications and procedures referred to in paragraph 2.’;

(b) paragraph 2 is replaced by the following:

2. By ... [12 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for processes for sending and receiving data. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2). ▌

(ba) the following paragraphs 2a and 2b are inserted:

2a. Providers of qualified electronic registered delivery services may agree on the interoperability between qualified electronic registered delivery services which they provide. Such interoperability framework shall comply with the requirements laid down in paragraph 1. The compliance shall be confirmed by a conformity assessment body.’;

(2b) The Commission may, by means of implementing acts, establish a list of reference standards and, when necessary, establish specifications and procedures for the interoperability framework referred to in paragraph 2a. The technical specifications and content of standards shall be cost-effective and proportionate. The implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

(38) Article 45 is replaced by the following:

‘Article 45

Requirements for qualified certificates for website authentication

1. Qualified certificates for website authentication shall meet the requirements laid down in Annex IV. Evaluation of compliance with those requirements shall be carried out in accordance with the standards and the specifications referred to in paragraph 3.

2. Qualified certificates for website authentication issued in accordance with paragraph 1 shall be recognised by web-browsers. ▌Web-browsers shall ensure that the identity data attested in the certificate and additional attested attributes are displayed in a user-friendly manner. Web-browsers shall ensure support and interoperability with qualified certificates for website authentication referred to in paragraph 1, with the exception of enterprises ▌ considered to be microenterprises and small enterprises in accordance with Commission Recommendation 2003/361/EC during the first 5 years of operating as providers of web-browsing services.

2b. Qualified certificates for website authentication shall not be subject to any mandatory requirements other than the requirements laid down in paragraph 1.

3. By ... [12 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for qualified certificates for website authentication, referred to in paragraph 1. ▌ Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).”

3a. Article 45a-1

Cybersecurity precautionary measures

1. Web-browsers shall not take any measures contrary to their obligations set out in Article 45, notably the requirement to recognise Qualified Certificates for Website Authentication, and to display the identity data provided in a user friendly manner.

2. By way of derogation to paragraph 1 and only in case of substantiated concerns related to breaches of security or loss of integrity of an identified certificate or set of certificates, web-browsers may take precautionary measures in relation to that certificate or set of certificates.

3. Where measures are taken, web-browsers shall notify their concerns in writing without undue delay, jointly with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory authority, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory authority shall issue an acknowledgement of receipt to the web-browser in question.

4. The competent supervisory authority shall consider the issues raised in the notification in accordance with Article 17(3)(c). When the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate(s), the supervisory authority shall inform the web-browser accordingly and request it to put an end to the precautionary measures referred to in paragraph 2.’

(39) the following sections 9, 10 and 11 are inserted after Article 45:

‘SECTION 9

ELECTRONIC ATTESTATION OF ATTRIBUTES

Article 45a

Legal effects of electronic attestation of attributes

1. An electronic attestation of attributes shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in electronic form, or that it does not meet the requirements for qualified electronic attestations of attributes.

2. A qualified electronic attestation of attributes and attestations of attributes issued by, or on behalf of, a public sector body responsible for an authentic source shall have the same legal effect as lawfully issued attestations in paper form.

3a. An attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source shall be recognised as an attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source in all Member States.

Article 45b

Electronic attestation of attributes in public services

When an electronic identification using an electronic identification means and authentication is required under national law to access an online service provided by a public sector body, person identification data in the electronic attestation of attributes shall not substitute electronic identification using an electronic identification means and authentication for electronic identification unless specifically allowed by the Member State ▌ . In such a case, qualified electronic attestation of attributes from other Member States shall also be accepted. ▌

Article 45c

Requirements for qualified electronic attestation of attributes

1. Qualified electronic attestation of attributes shall meet the requirements laid down in Annex V. ▌

1a. Evaluation of compliance with the requirements laid down in Annex V shall be carried out in accordance with the standards, specifications and procedures referred to in paragraph 4.

2. Qualified electronic attestations of attributes shall not be subject to any mandatory requirement in addition to the requirements laid down in Annex V.

3. Where a qualified electronic attestation of attributes has been revoked after initial issuance, it shall lose its validity from the moment of its revocation, and its status shall not in any circumstances be reverted.

4. By ... [6 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for qualified electronic attestations of attributes. Those implementing acts shall be consistent with the implementing act referred to in Article 6a(11) on the implementation of the European Digital Identity Wallet and shall be adopted in accordance with the examination procedure referred to in Article 48(2)

Article 45d

Verification of attributes against authentic sources

1. Member States shall ensure within 24 months after entry into force of the implementing acts referred to in Article 6a(11) and Article 6c(4) that, at least for the attributes listed in Annex VI, wherever these attributes rely on authentic sources within the public sector, measures are taken to allow qualified trust service providers of electronic attestations of attributes to verify these attributes by electronic means at the request of the user and in accordance with national or Union law.

2. By … [6 months after the date of the entering into force of this amending Regulation], the Commission shall, taking into account relevant international standards, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for the catalogue of attributes and schemes for the attestation of attributes and verification procedures for qualified electronic attestations of attributes. Those implementing acts shall be consistent with the implementing act referred to in Article 6a(11) on the implementation of the European Digital Identity Wallet and shall be adopted in accordance with the examination procedure referred to in Article 48(2). ▌

Article

45da

Requirements for electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source.

1. An electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source shall meet the following requirements:

(a) the requirements set out in Annex VIa;

(b) the qualified certificate supporting the qualified electronic signature or qualified electronic seal of the public sector body referred to in Article 3 (45a) identified as the issuer referred to in point (b) of Annex VIa, shall contain a specific set of certified attributes in a form suitable for automated processing:

(i) indicating that the issuing body is established in accordance with a national or Union law as the responsible for the authentic source on the basis of which the electronic attestation of attributes is issued or as the body designated to act on its behalf;

(ii) providing a set of data unambiguously representing the authentic source referred to in letter (i); and

(iii) identifying the national or Union law referred to in letter (i).

2. The Member State where the public sector bodies referred to in Article 3(45a) are established shall ensure that the public sector bodies that issue electronic attestations of attributes meet the equivalent level of reliability and trustworthiness as qualified trust service providers in accordance with Article 24.

3. Member States shall notify the public sector bodies referred to in Article 3 (45a) to the Commission. This notification shall include a conformity assessment report issued by a conformity assessment body confirming that the requirements set out in paragraphs 1, 2 and 6 of this Article are met. The Commission shall make available to the public, through a secure channel, the list of the public sector bodies referred to in Article 3 (45a) in electronically signed or sealed form suitable for automated processing.

4. Where an electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source has been revoked after initial issuance, it shall lose its validity from the moment of its revocation. After revocation, the revoked status of an electronic attestation shall not be reverted.

5. An electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source shall be deemed compliant with the requirements laid down in paragraph (1) of this Article, where it meets the standards referred to in paragraph (6).

6. By … [6 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source. Those implementing acts shall be consistent with the implementing act referred to in Article 6a(11) on the implementation of the European Digital Identity Wallet and shall be adopted in accordance with the examination procedure referred to in Article 48(2).

7. By … [6 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications, formats and procedures for the purposes of paragraph 3. Those implementing acts shall be consistent with the implementing act referred to in Article 6a(11) on the implementation of the European Digital Identity Wallet and shall be adopted in accordance with the examination procedure referred to in Article 48(2).”

8. Public sector bodies referred to in Article 3(45a) issuing electronic attestation of attributes shall provide an interface with the European Digital Identity Wallets provided in accordance with Article 6a.

Article 45e

Issuing of electronic attestation of attributes to the European Digital Identity Wallets

1. Providers of electronic attestations of attributes shall provide EUDI Wallet users with the possibility to request, obtain, store and manage the electronic attestation of attributes irrespective of the Member States where the wallet is provided.

2. Providers of qualified electronic attestations of attributes shall provide an interface with the European Digital Identity Wallets provided in accordance in Article 6a. ▌

Article 45f

Additional rules for the provision of electronic attestation of attributes services

1. Providers of qualified and non-qualified electronic attestation of attributes services shall not combine personal data relating to the provision of those services with personal data from any other services offered by them or their commercial partners.

2. Personal data relating to the provision of electronic attestation of attributes services shall be kept logically separate from other data held by the provider of electronic attestation of attributes.

4. Providers of qualified electronic attestation of attributes’ services shall implement the provision of such qualified trust services in a manner that is functionally separated from any other service provided by them.

SECTION 10

▌ ELECTRONIC ARCHIVING SERVICES

Article 45g

Legal effect of electronic archiving services

1. Electronic data and electronic documents preserved using an electronic archiving service shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that they are in electronic form or that they are not preserved using a qualified electronic archiving service.

2. Electronic data and electronic documents preserved using a qualified electronic archiving service shall enjoy the presumption of their integrity and of their origin for the duration of the preservation period by the qualified trust service provider.

Article 45ga

Requirements for qualified electronic archiving services

1. Qualified electronic archive services shall meet the following requirements:

(a) They are provided by qualified trust service providers

(b) They use procedures and technologies capable of ensuring the durability and legibility of the electronic data beyond the technological validity period and at least throughout the legal or contractual preservation period, while maintaining their integrity and the accuracy of their origin;

(c) They ensure that the electronic data is preserved in such a way that they are safeguarded against loss and alteration, except for changes concerning their medium or electronic format;

(d) They shall allow authorised relying parties to receive a report in an automated manner that confirms that an electronic data retrieved from a qualified electronic archive enjoys the presumption of integrity of the data from the beginning of the preservation period to the moment of retrieval. This report shall be provided in a reliable and efficient way and it shall bear the qualified electronic signature or qualified electronic seal of the provider of the qualified electronic archiving service;

2. By … [12 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for qualified electronic archiving services. Compliance with the requirements for qualified electronic archive services shall be presumed when a qualified electronic archive service meets those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).”

SECTION 11

ELECTRONIC LEDGERS

Article 45h

Legal effects of electronic ledgers

1. An electronic ledger shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements for qualified electronic ledgers.

2. Data records contained in a qualified electronic ledger shall enjoy the presumption of ▌ their unique and accurate sequential chronological ordering and of their integrity.

Article 45i

Requirements for qualified electronic ledgers

1. Qualified electronic ledgers shall meet the following requirements:

(a) they are created and managed by one or more qualified trust service provider or providers;

(b) they establish the origin of data records in the ledger;

(c) they ensure the unique sequential chronological ordering of data records in the ledger ▌ ;

(d) they record data in such a way that any subsequent change to the data is immediately detectable, ensuring their integrity over time.

2. Compliance with the requirements laid down in paragraph 1 shall be presumed where an electronic ledger meets the standards, specifications and procedures referred to in paragraph 3.

3. By … [12 months after the date of the entering into force of this amending Regulation], the Commission shall, by means of implementing acts, establish a list of reference standards and when necessary, establish specifications and procedures for the requirements laid down in paragraph 1. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).”

(39e) The following heading is inserted before Article 46a

CHAPTER IVa GOVERNANCE FRAMEWORK

(39f) The following Articles are inserted:

"Article 46a

Supervision of the EDIW framework

1. Member States shall designate one or more supervisory bodies established in their territory. Supervisory bodies shall be given the necessary powers and adequate resources for the exercise of their tasks in an effective, efficient and independent manner.

2. Member States shall notify to the Commission the names and the addresses of their respective designated supervisory bodies and any subsequent changes thereto. The Commission shall publish a list of the notified supervisory bodies.

3. The role of the supervisory bodies shall be:

(a) to supervise providers of European Digital Identity Wallets established in the designating Member State and to ensure, through ex ante and ex post supervisory activities, that those issuers and the European Digital Identity Wallets they provide meet the requirements laid down in this Regulation.

(b) to take action, if necessary, in relation to providers of European Digital Identity Wallets established in the territory of the designating Member State, through ex post supervisory activities, when informed that those issuers and the European Digital Identity Wallets they provide allegedly do not meet the requirements laid down in this Regulation.

4. The tasks of the supervisory bodies shall include in particular:

(a) to cooperate with other supervisory bodies and to provide them with assistance in accordance with Articles 46c and 46e;

(b) to request information necessary to monitor the compliance with the relevant provisions of this Regulation;

(c) to inform the relevant national competent authorities of the Member States concerned, designated pursuant to Directive (EU) 2022/2555, of any significant breaches of security or loss of integrity they become aware of in the performance of their tasks and, in the case of a significant breach of security or loss of integrity which concerns other Member States, to inform the single point of contact of the Member State concerned designated pursuant to Directive (EU) 2022/2555 and single points of contact designated pursuant to Article 46c of this Regulation in the other Member States concerned. The notified supervisory body shall inform the public or require the European Digital Identity Wallet provider to do so where it determines that disclosure of the breach of security or loss of integrity is in the public interest;

(d) to carry out on-site inspections and off-site supervision;

(e) to require that providers of European Digital Identity Wallets remedy any failure to fulfil the requirements laid down in this Regulation;

(f) To suspend or cancel the registration and inclusion of relying parties in the mechanism referred to in Article 6b(2) in the case of illegal or fraudulent use of the European Digital Identity Wallet;

(g) to cooperate with competent supervisory authorities established under Regulation (EU) 2016/679, in particular, by informing them without undue delay, where personal data protection rules appear to have been breached and about security breaches which appear to constitute personal data breaches;

5. Where the supervisory body requires the provider of a European Digital Identity Wallet to remedy any failure to fulfil requirements under this Regulation pursuant to paragraph 4 (d) and where that provider does not act accordingly, and if applicable within a time limit set by the supervisory body, taking into account, in particular, the extent, duration and consequences of that failure, may order the provider to suspend or to cease the issuance of the European Digital Identity Wallet. The supervisory bodies shall inform the supervisory bodies of other Member States, the Commission, relying parties and users of the European Digital Identity Wallet without undue delay of the decision to require the suspension or cessation of the European Digital Identity Wallet.

6. By 31 March each year, each supervisory body shall submit to the Commission a report on its previous calendar year’s main activities.

7. The Commission shall make the annual reports referred to in paragraph 6 available to the European Parliament and the Council.

8. By … [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, define the formats and procedures for the report referred to in paragraph 6. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 46b

Supervision of trust services

1. Member States shall designate a supervisory body established in their territory or, upon mutual agreement with another Member State, a supervisory body established in that other Member State. That body shall be responsible for supervisory tasks in the designating Member State. Supervisory bodies shall be given the necessary powers and adequate resources for the exercise of their tasks.

2. Member States shall notify to the Commission the names and the addresses of their respective designated supervisory bodies.

3. The role of the supervisory body shall be:

(a) to supervise qualified trust service providers established in the territory of the designating Member State through ex ante and ex post supervisory activities, that those qualified trust service providers and the qualified trust services that they provide meet the requirements laid down in this Regulation;

(b) to take action if necessary, in relation to non-qualified trust service providers established in the territory of the designating Member State, through ex post supervisory activities, when informed that those non-qualified trust service providers or the trust services they provide allegedly do not meet the requirements laid down in this Regulation;

4. The tasks of the supervisory body shall include in particular:

(a) to inform the relevant national competent authorities of the Member States concerned, designated pursuant to Directive (EU) 2022/2555, of any significant breaches of security or loss of integrity they become aware of in the performance of their tasks and, in the case of a significant breach of security or loss of integrity which concerns other Member States, to inform the single point of contact of the Member State concerned designated pursuant to Directive (EU) 2022/2555 and single points of contact designated pursuant to [Article 46c] of this Regulation in the other Member States concerned. The notified supervisory body shall inform the public or require the trust service provider to do so where it determines that disclosure of the breach of security or loss of integrity is in the public interest;’;

(b) to cooperate with other supervisory bodies and to provide them with assistance in accordance with Articles 46c and 46e;

(c) to analyse the conformity assessment reports referred to in Articles 20(1) and 21(1);

(d) to report to the Commission about its main activities in accordance with paragraph 6 of this Article;

(e) to carry out audits or request a conformity assessment body to perform a conformity assessment of the qualified trust service providers in accordance with Article 20(2);

(f) to cooperate with competent supervisory authorities established under Regulation (EU) 2016/679, in particular, by informing them without undue delay where personal data protection rules appear to have been breached and about security breaches which appear to constitute personal data breaches;’

(g) to grant qualified status to trust service providers and to the services they provide and to withdraw this status in accordance with Articles 20 and 21;

(h) to inform the body responsible for the national trusted list referred to in Article 22(3) about its decisions to grant or to withdraw qualified status, unless that body is also the supervisory body;

(i) to verify the existence and correct application of provisions on termination plans in cases where the qualified trust service provider ceases its activities, including how information is kept accessible in accordance with Article 24(2), point (h);

(j) to require that trust service providers remedy any failure to fulfil the requirements laid down in this Regulation.

(k) to investigate claims made by web-browsers pursuant to Article 45a and to take action if necessary.

5. Member States may require the supervisory body to establish, maintain and update a trust infrastructure in accordance with the conditions under national law.

6. By 31 March each year, each supervisory body shall submit to the Commission a report on its previous calendar year’s main activities.

7. The Commission shall make the annual reports referred to in paragraph 6 available to the European Parliament and the Council.

8. By … [12 months after the date of entry into force of this amending Regulation], the Commission shall adopt guidelines on the exercise by the Supervisory bodies of the tasks referred to in paragraph 4, and, by means of implementing acts adopted in accordance with the examination procedure referred to in Article 48(2), define the formats and procedures for the report referred to in paragraph 6.’;

Article 46c

Single points of contact

1. Each Member State shall designate one national single point of contact for trust services, European Digital Identity Wallets and notified electronic identification schemes.

2. Single points of contact shall exercise a liaison function to facilitate cross-border cooperation between the supervisory bodies for trust service providers and between the supervisory bodies for the providers of the European Digital Identity Wallets and, where appropriate, with the Commission and European Union Agency for Cybersecurity and with other competent authorities within its Member State.

3. Each Member State shall make public and, without undue delay, notify to the Commission the names and the addresses of the designated single point of contact referred to in paragraph 1 and any subsequent change thereto.

4. The Commission shall publish a list of the notified single points of contact.

Article 46d

Mutual assistance

1. In order to facilitate the supervision and enforcement of obligations under this Regulation, supervisory bodies responsible for trust services and for European Digital Identity Wallets may seek, including through the EDICG, mutual assistance from supervisory bodies of another Member State where the trust service provider or the provider of the European Digital Identity Wallet is established, its network and information systems are located, or its services are provided.

2. The mutual assistance shall at least entail that:

(a) the supervisory body applying supervisory and enforcement measures in one Member State, shall inform and consult the supervisory body from the other Member State concerned;

(b) a supervisory body may request the supervisory body of another Member State concerned to take supervisory or enforcement measures, including, for instance requests to carry out inspections related to the conformity assessment reports as referred to in Articles 20 and 21 regarding the provision of trust services;

(c) where appropriate, supervisory bodies may carry out joint investigations with other Member States’ supervisory bodies. The arrangements and procedures for such joint actions shall be agreed upon and established by the Member States concerned in accordance with their national law.

3. A supervisory body to which a request for assistance is addressed may refuse that request on any of the following grounds:

(a) the requested assistance is not proportionate to supervisory activities of the supervisory body carried out in accordance with Articles 46a and 46b;

(b) the supervisory body is not competent to provide the requested assistance;

(c) providing the requested assistance would be incompatible with this Regulation.

4. By … [12 months after the date of entry into force of this amending Regulation] [and every two years thereafter], the EDICG shall issue guidance on the organisational aspects and procedures for the mutual assistance referred to in paragraphs 1 and 2.

Article 46e

The European Digital Identity Cooperation Group

1. In order to support and facilitate Member States’ cross-border cooperation and exchange of information on trust services, European Digital Identity Wallets and notified electronic identification schemes, the European Digital Identity Cooperation Group (the ‘EDICG’), shall be established by the Commission.

2. The EDICG shall be composed of representatives appointed by the Member States and of the Commission. The EDICG shall be chaired by the Commission who shall provide the EDICG Secretariat.

3. Representatives of relevant stakeholders may be invited to attend meetings of the EDICG and to participate in its work as observers, on an ad hoc basis.

4. The European Union Agency for Cybersecurity shall be invited to participate as observer in the workings of the EDICG when it exchanges views, best practices and information on relevant cybersecurity aspects such as notification of security breaches, the use of cybersecurity certificates or standards are addressed.

5. The EDICG shall have the following tasks:

(a) exchange advice and cooperate with the Commission on emerging policy initiatives in the field of digital identity wallets, electronic identification means and trust services;

(b) advise the Commission, as appropriate, in the early preparation of draft implementing and delegated acts to be adopted pursuant to this Regulation;

(c) in order to support the supervisory bodies in the implementation of the provisions of this Regulation, the EDICG shall:

(i) exchange best practices and information regarding the implementation of the provisions of this Regulation; identification and trust services sectors;

(iii) organise joint meetings with relevant interested parties from across the Union to discuss activities carried out by the cooperation group and gather input on emerging policy challenges;

(iv) with the support of ENISA, exchange views, best practices and information on relevant cybersecurity aspects concerning European Digital Identity Wallets, electronic identification schemes and trust services;

(v) exchange best practices in relation to the development and implementation of policies on notification of breaches, and common measures as referred to in Articles 10 and 10a;

(vi) organise joint meetings with the NIS Cooperation Group established under Directive EU 2022/2555 to exchange relevant information in relation to trust services and electronic identification related cyber threats, incidents, vulnerabilities, awareness raising initiatives, trainings, exercises and skills, capacity building, standards and technical specifications capacity as well as standards and technical specifications;

(vii) organise peer reviews of electronic identification schemes to be notified falling under this Regulation;

(viii) discuss, upon a request of a supervisory body, specific requests for mutual assistance as referred to in Article 46d;

(ix) facilitate the exchange of information between the supervisory bodies by providing guidance on the organisational aspects and procedures for the mutual assistance referred to in Article 46d.

6. Member States shall ensure effective and efficient cooperation of their designated representatives in the EDICG.

7. Within 12 months of the entry into force of the Regulation, the Commission shall, by means of implementing acts, establish the necessary procedural arrangements to facilitate the cooperation between the Member States referred to in point (vii) of paragraph 5 . That implementing act shall be adopted in accordance with the examination procedure referred to in Article 48(2).’

(39b) Article 47 is amended as follows:

(a) paragraphs 2 and 3 are replaced by the following:

2. The power to adopt delegated acts referred to in Article 6c(6), Article 24(6), and Article 30(4) shall be conferred on the Commission for an indeterminate period of time from 17 September 2014.

3. The delegation of power referred to in Article 6c(6), Article 24(6), and Article 30(4) may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.

(b) paragraph 5 is replaced by the following:

(ii) assess the relevant developments in the digital wallet, electronic

5. A delegated act adopted pursuant to Article 6c(6), Article 24(6), or Article 30(4) shall enter into force only if no objection has been expressed either by the European Parliament or the Council within a period of two months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by two months at the initiative of the European Parliament or of the Council.’

(40) The following Article ▌ is inserted:

‘Article 48a

Reporting requirements

1. Member States shall ensure the collection of statistics in relation to the ▌ functioning of the European Digital Identity Wallets and the qualified trust services provided on their territory.

2. The statistics collected in accordance with paragraph 1, shall include the following:

(a) the number of natural and legal persons having a valid European Digital Identity Wallet;

(b) the type and number of services accepting the use of the European Digital Identity Wallet;

(ba) the number of user complaints and consumer protection or data protection incidents relating to relying parties and qualified trust services;

(c) summary report including data on incidents preventing the use of the European Digital Identity Wallet ▌ .

(ca) a summary of significant security incidents, data breaches and affected users of European Digital Identity Wallets or of qualified trust services;

3. The statistics referred to in paragraph 2 shall be made available to the public in an open and commonly used, machine-readable format.

4. By 31 March each year, Member States shall submit to the Commission a report on the statistics collected in accordance with paragraph 2.’;’

(41) Article 49 is replaced by the following:

‘Article 49

Review

1. The Commission shall review the application of this Regulation and shall report to the European Parliament and to the Council within 24 months ▌ after its entering into force. The Commission shall evaluate in particular whether it is appropriate to modify the scope of this Regulation or its specific provisions including, in particular, the provisions included in Article 6c(3), taking into account the experience gained in the application of this Regulation, as well as technological, market and legal developments. Where necessary, that report shall be accompanied by a proposal for amendment of this Regulation.

2. The evaluation report shall include an assessment of the availability, security and usability of the notified electronic identification means and European Digital Identity Wallets in scope of this Regulation and assess whether all online private service providers relying on third party electronic identification services for users authentication, shall be mandated to accept the use of notified electronic identification means and European Digital Identity Wallet.

3. In addition, the Commission shall submit a report to the European Parliament and the Council every four years after the report referred to in the first paragraph on the progress towards achieving the objectives of this Regulation.‘

(42) Article 51 is replaced by the following:

‘Article 51

Transitional measures

1. Secure signature creation devices of which the conformity has been determined in accordance with Article 3(4) of Directive 1999/93/EC shall continue to be considered as qualified electronic signature creation devices under this Regulation until 36 months following the entry into force of this Regulation ▌ .

2. Qualified certificates issued to natural persons under Directive 1999/93/EC shall continue to be considered as qualified certificates for electronic signatures under this Regulation until 24 months after the entry into force of this Regulation ▌ .’.

2a. The management of remote qualified electronic signature and seal creation devices by qualified trust service providers other than qualified trust service providers providing qualified trust services for the management of remote qualified electronic signature and seal creation devices in accordance with Articles 29a and 39a shall continue to be considered without the need to obtain the qualified status for the provision of these management services until 24 months after the entry into force of this Regulation.

2b. Qualified trust service providers that have been granted their qualified status under this Regulation before [date of entry into force of the amending Regulation], using methods for identity verification for the issuance of qualified certificates in compliance with Article 24(1), shall submit a conformity assessment report to the supervisory body proving compliance with Article 24(1) as soon as possible, but no later than 24 months after entry into force of the amending Regulation. Until the submission of such a conformity assessment report and the completion of its assessment by the supervisory body, the qualified trust service provider may continue to rely on the use of the methods for identity verification set out in Article 24(1) of Regulation (EU) No 910/2014.’

(43) Annex I is amended in accordance with Annex I to this Regulation;

(44) Annex II is replaced by the text set out in Annex II to this Regulation;

(45) Annex III is amended in accordance with Annex III to this Regulation;

(46) Annex IV is amended in accordance with Annex IV to this Regulation;

(47) a new Annex V is added as set out in Annex V to this Regulation;

(48) a new Annex VI is added as set out in Annex VI to this Regulation.

(48a) a new Annex VIa is added as set out in Annex VIa to this Regulation.

(48b) In Article 2 the following title is inserted:

Article 2

Entry into force

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels,

For the European ParliamentFor the Council
The PresidentThe President

Annex I

In Annex I, point (i) is replaced by the following:

(i) the information, or the location of the services that can be used to enquire, about the validity status of the qualified certificate;.

Annex II

REQUIREMENTS FOR QUALIFIED ELECTRONIC SIGNATURE CREATION DEVICES

1. Qualified electronic signature creation devices shall ensure, by appropriate technical and procedural means, that at least:

(a) the confidentiality of the electronic signature creation data used for electronic signature creation is reasonably assured;

(b) the electronic signature creation data used for electronic signature creation can practically occur only once;

(c) the electronic signature creation data used for electronic signature creation cannot, with reasonable assurance, be derived and the electronic signature is reliably protected against forgery using currently available technology;

(d) the electronic signature creation data used for electronic signature creation can be reliably protected by the legitimate signatory against use by others.

2. Qualified electronic signature creation devices shall not alter the data to be signed or prevent such data from being presented to the signatory prior to signing.

Annex III

In Annex III, point (i) is replaced by the following:

(i) the information, or the location of the services that can be used to enquire, about the validity status of the qualified certificate;.

(ia) ▌

Annex IV

Annex IV is amended as follows:

(1) point (c) is replaced by the following:

(c) for natural persons: at least the name of the person to whom the certificate has been issued, or a pseudonym. If a pseudonym is used, it shall be clearly indicated;

(ca) for legal persons: a unique set of data unambiguously representing the legal person to whom the certificate is issued, with at least the name of the legal person to whom the certificate is issued and, where applicable, the registration number as stated in the official records;

▌ point (j) is replaced by the following:

(j) the information, or the location of the certificate validity status services that can be used to enquire, about the validity status of the qualified certificate..

Annex V

REQUIREMENTS FOR QUALIFIED ELECTRONIC ATTESTATION OF ATTRIBUTES

Qualified electronic attestation of attributes shall contain:

(a) an indication, at least in a form suitable for automated processing, that the attestation has been issued as a qualified electronic attestation of attributes;

(b) a set of data unambiguously representing the qualified trust service provider issuing the qualified electronic attestation of attributes including at least, the Member State in which that provider is established and:

- for a legal person: the name and, where applicable, registration number as stated in the official records,

- for a natural person: the person’s name;

(c) a set of data unambiguously representing the entity to which the attested attributes are referring to; if a pseudonym is used, it shall be clearly indicated;

(d) the attested attribute or attributes, including, where applicable, the information necessary to identify the scope of those attributes;

(e) details of the beginning and end of the attestation’s period of validity;

(f) the attestation identity code, which must be unique for the qualified trust service provider and if applicable the indication of the scheme of attestations that the attestation of attributes is part of;

(g) the qualified electronic signature or qualified electronic seal of the issuing qualified trust service provider;

(h) the location where the certificate supporting the qualified electronic signature or qualified electronic seal referred to in point (g) is available free of charge;

(i) the information or location of the services that can be used to enquire about the validity status of the qualified attestation.

Annex VI

MINIMUM LIST OF ATTRIBUTES

Further to Article 45d, Member States shall ensure that measures are taken to allow qualified providers of electronic attestations of attributes to verify by electronic means at the request of the user, the authenticity of the following attributes against the relevant authentic source at national level or via designated intermediaries recognised at national level, in accordance with Union or national law and in cases where these attributes rely on authentic sources within the public sector:

1. Address;

2. Age;

3. Gender;

4. Civil status;

5. Family composition;

6. Nationality or citizenship;

6a. ▌

7. Educational qualifications, titles and licenses;

8. Professional qualifications, titles and licenses;

8a. Powers and mandates to represent natural or legal persons

9. Public permits and licenses;

10. For legal persons, financial and company data.

ANNEX VIa

REQUIREMENTS FOR ELECTRONIC ATTESTATION OF ATTRIBUTES ISSUED BY OR ON BEHALF OF A PUBLIC BODY RESPONSIBLE FOR AN AUTHENTIC SOURCE

1. An electronic attestation of attributes issued by or on behalf of a public body responsible for an authentic source shall contain:

(a) an indication, at least in a form suitable for automated processing, that the attestation has been issued as an electronic attestation of attributes issued by or on behalf of a public body responsible for an authentic source;

(b) a set of data unambiguously representing the public body issuing the electronic attestation of attributes, including at least, the Member State in which that public body is established and its name and, where applicable, its registration number as stated in the official records;

(c) a set of data unambiguously representing the entity which the attested attributes is referring to; if a pseudonym is used, it shall be clearly indicated;

(d) the attested attribute or attributes, including, where applicable, the information necessary to identify the scope of those attributes;

(e) details of the beginning and end of the attestation’s period of validity;

(f) the attestation identity code, which must be unique for the issuing public body and if applicable the indication of the scheme of attestations that the attestation of attributes is part of;

(g) the qualified electronic signature or qualified electronic seal of the issuing body;

(h) the location where the certificate supporting the qualified electronic signature or qualified electronic seal referred to in point (g) is available free of charge;

(i) the information or location of the services that can be used to enquire about the validity status of the attestation.

_______________