32014R0910 → 02014R0910-20240520
in force 2024-05-20 · detected 2026-08-11
86 provisions touched — 86 substantive, 0 date-only, 52 disputed · 0 sentences quoted verbatim by the gate, 17 changes shipped without an explanation
MODIFIED Art. 1 — Subject matter · applies from unchanged
The introductory sentence of Article 1 is expanded to state that the Regulation aims to enable and facilitate the exercise by natural and legal persons of the right to participate in digital society safely and to access online public and private services throughout the Union, in addition to the previously stated aims. Art. 1, v1 Art. 1, v2
Point (a) now also refers to Member States providing and recognising European Digital Identity Wallets, alongside recognising notified electronic identification schemes. Art. 1, v2
Point (c) adds electronic archiving, electronic attestation of attributes, electronic signature creation devices, electronic seal creation devices, and electronic ledgers to the list of items for which a legal framework is established. Art. 1, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 1Subject matterWith a view matterThis Regulation aims to ensuring ensure the proper functioning of the internal market while aiming at and the provision of an adequate level of security of electronic identification means and trust services used across the Union, in order to enable and facilitate the exercise by natural and legal persons of the right to participate in digital society safely and to access online public and private services throughout the Union. For those purposes, this Regulation:(a)lays down the conditions under which Member States are to recognise natural and legal persons’ electronic identification means of natural and legal persons falling under a notified electronic identification scheme of another Member State;(b)lays State and provide and recognise European Digital Identity Wallets;(b)lays down rules for trust services, in particular for electronic transactions; and(c)establishes transactions;(c)establishes a legal framework for electronic signatures, electronic seals, electronic time stamps, electronic documents, electronic registered delivery services and services, certificate services for website authentication. authentication, electronic archiving, electronic attestation of attributes, electronic signature creation devices, electronic seal creation devices, and electronic ledgers.
MODIFIED Art. 2 — Scope · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
Paragraph 1 now adds European Digital Identity Wallets provided by a Member State to the list of subjects the Regulation applies to, alongside notified electronic identification schemes and trust service providers established in the Union. Art. 2, v2
Paragraph 3 now also states that the Regulation does not affect sector-specific requirements relating to form, in addition to the previously stated non-effect on law concerning conclusion and validity of contracts and other legal or procedural obligations relating to form. Art. 2, v2
A new paragraph 4 has been added stating that the Regulation is without prejudice to Regulation (EU) 2016/679, whereas the prior version had no such paragraph. Art. 2, v1 Art. 2, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 2Scope1.This Regulation applies to electronic identification schemes that have been notified by a Member State, to European Digital Identity Wallets provided by a Member State and to trust service providers that are established in the Union.2.This Regulation does not apply to the provision of trust services that are used exclusively within closed systems resulting from national law or from agreements between a defined set of participants.3.This Regulation does not affect Union or national or Union law related to the conclusion and validity of contracts or contracts, other legal or procedural obligations relating to form. form, or sector-specific requirements relating to form.4.This Regulation is without prejudice to Regulation (EU) 2016/679 of the European Parliament and of the CouncilRegulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1)..
MODIFIED Art. 3 — Definitions · applies from unchanged
Several existing definitions were reworded, for instance broadening references to a natural person representing a legal person to also cover representing another natural person, and extending the definition of electronic identification means to cover offline as well as online services. Art. 3, v2
A new definition of user was inserted as point 5a, and point 16 on trust service was rewritten from a three-part list into a longer lettered list covering issuance and validation of certificates, creation and validation of signatures and seals, attestations of attributes, timestamps, registered delivery, archiving and ledger recording. Art. 3, v2
Numerous additional definitions, including remote qualified electronic signature and seal creation devices, European Digital Identity Wallet, attributes, authentic source, electronic archiving, EU Digital Identity Wallet Trust Mark, strong user authentication, electronic ledger, personal data, identity matching, data record and offline mode, were added as new points from point 23a through point 57, none of which appeared in the earlier version. Art. 3, v2 Art. 3, v1
text before / after
32014R0910 → 02014R0910-20240520
Article 3DefinitionsFor the purposes of this Regulation, the following definitions apply:(1)electronic identification means the process of using person identification data in electronic form uniquely representing either a natural or legal person, or a natural person representing another natural person or a legal person;(2)electronic identification means means a material and/or immaterial unit containing person identification data and which is used for authentication for an online service or, where appropriate, for an offline service;(3)person identification data means a set of data enabling that is issued in accordance with Union or national law and that enables the establishment of the identity of a natural or legal person, or of a natural person representing another natural person or a legal person to be established;(4)electronic person.(4)electronic identification scheme means a system for electronic identification under which electronic identification means are issued to natural or legal persons, persons or natural persons representing other natural persons or legal persons;(5)authentication means an electronic process that enables the confirmation of the electronic identification of a natural or legal person, person or the confirmation of the origin and integrity of data in electronic form to be confirmed;(6)relying form;(5a)user means a natural or legal person, or a natural person representing another natural person or a legal person, that uses trust services or electronic identification means provided in accordance with this Regulation;(6)relying party means a natural or legal person that relies upon an electronic identification, European Digital Identity Wallets or other electronic identification means, or upon a trust service;(7)public sector body means a state, regional or local authority, a body governed by public law or an association formed by one or several such authorities or one or several such bodies governed by public law, or a private entity mandated by at least one of those authorities, bodies or associations to provide public services, when acting under such a mandate;(8)body governed by public law means a body defined in point (4) of Article 2(1) of Directive 2014/24/EU of the European Parliament and of the CouncilDirective 2014/24/EU of the European Parliament and of the Council of 26 February 2014 on public procurement and repealing Directive 2004/18/EC (OJ L 94, 28.3.2014, p. 65).;(9)signatory means a natural person who creates an electronic signature;(10)electronic signature means data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign;(11)advanced electronic signature means an electronic signature which meets the requirements set out in Article 26;(12)qualified electronic signature means an advanced electronic signature that is created by a qualified electronic signature creation device, and which is based on a qualified certificate for electronic signatures;(13)electronic signature creation data means unique data which is used by the signatory to create an electronic signature;(14)certificate for electronic signature means an electronic attestation which links electronic signature validation data to a natural person and confirms at least the name or the pseudonym of that person;(15)qualified certificate for electronic signature means a certificate for electronic signatures, that is issued by a qualified trust service provider and meets the requirements laid down in Annex I;(16)trust service means an electronic service normally provided for remuneration which consists of:(a)the creation, verification, and of any of the following:(a)the issuance of certificates for electronic signatures, certificates for electronic seals, certificates for website authentication or certificates for the provision of other trust services;(b)the validation of certificates for electronic signatures, certificates for electronic seals, certificates for website authentication or certificates for the provision of other trust services;(c)the creation of electronic signatures or electronic seals;(d)the validation of electronic signatures or electronic seals;(e)the preservation of electronic signatures, electronic seals seals, certificates for electronic signatures or certificates for electronic time stamps, seals;(f)the management of remote electronic signature creation devices or remote electronic seal creation devices;(g)the issuance of electronic attestations of attributes;(h)the validation of electronic attestation of attributes;(i)the creation of electronic timestamps;(j)the validation of electronic timestamps;(k)the provision of electronic registered delivery services;(l)the validation of data transmitted through electronic registered delivery services and certificates related to those services, or(b)the creation, verification and validation of certificates for website authentication; or(c)the preservation evidence;(m)the electronic archiving of electronic signatures, seals or certificates related to those services;(17)qualified data and electronic documents;(n)the recording of electronic data in an electronic ledger;(17)qualified trust service means a trust service that meets the applicable requirements laid down in this Regulation;(18)conformity assessment body means a conformity assessment body as defined in Article 2, point 13 of Article 2 13, of Regulation (EC) No 765/2008, which is accredited in accordance with that Regulation as competent to carry out conformity assessment of a qualified trust service provider and the qualified trust services it provides;(19)trust provides, or as competent to carry out certification of European Digital Identity Wallets or electronic identification means;(19)trust service provider means a natural or a legal person who provides one or more trust services either as a qualified or as a non-qualified trust service provider;(20)qualified trust service provider means a trust service provider who provides one or more qualified trust services and is granted the qualified status by the supervisory body;(21)product means hardware or software, or relevant components of hardware or software, which are intended to be used for the provision of electronic identification and trust services;(22)electronic signature creation device means configured software or hardware used to create an electronic signature;(23)qualified electronic signature creation device means an electronic signature creation device that meets the requirements laid down in Annex II;(24)creator II;(23a)remote qualified electronic signature creation device means a qualified electronic signature creation device that is managed by a qualified trust service provider in accordance with Article 29a on behalf of a signatory;(23b)remote qualified electronic seal creation device means a qualified electronic seal creation device that is managed by a qualified trust service provider in accordance with Article 39a on behalf of a seal creator;(24)creator of a seal means a legal person who creates an electronic seal;(25)electronic seal means data in electronic form, which is attached to or logically associated with other data in electronic form to ensure the latter’s origin and integrity;(26)advanced electronic seal means an electronic seal, which meets the requirements set out in Article 36;(27)qualified electronic seal means an advanced electronic seal, which is created by a qualified electronic seal creation device, and that is based on a qualified certificate for electronic seal;(28)electronic seal creation data means unique data, which is used by the creator of the electronic seal to create an electronic seal;(29)certificate for electronic seal means an electronic attestation that links electronic seal validation data to a legal person and confirms the name of that person;(30)qualified certificate for electronic seal means a certificate for an electronic seal, that is issued by a qualified trust service provider and meets the requirements laid down in Annex III;(31)electronic seal creation device means configured software or hardware used to create an electronic seal;(32)qualified electronic seal creation device means an electronic seal creation device that meets mutatis mutandis the requirements laid down in Annex II;(33)electronic time stamp means data in electronic form which binds other data in electronic form to a particular time establishing evidence that the latter data existed at that time;(34)qualified electronic time stamp means an electronic time stamp which meets the requirements laid down in Article 42;(35)electronic document means any content stored in electronic form, in particular text or sound, visual or audiovisual recording;(36)electronic registered delivery service means a service that makes it possible to transmit data between third parties by electronic means and provides evidence relating to the handling of the transmitted data, including proof of sending and receiving the data, and that protects transmitted data against the risk of loss, theft, damage or any unauthorised alterations;(37)qualified electronic registered delivery service means an electronic registered delivery service which meets the requirements laid down in Article 44;(38)certificate for website authentication means an electronic attestation that makes it possible to authenticate a website and links the website to the natural or legal person to whom the certificate is issued;(39)qualified certificate for website authentication means a certificate for website authentication, which is issued by a qualified trust service provider and meets the requirements laid down in Annex IV;(40)validation data means data that is used to validate an electronic signature or an electronic seal;(41)validation means the process of verifying and confirming that data in electronic form are valid in accordance with this Regulation;(42)European Digital Identity Wallet means an electronic signature identification means which allows the user to securely store, manage and validate person identification data and electronic attestations of attributes for the purpose of providing them to relying parties and other users of European Digital Identity Wallets, and to sign by means of qualified electronic signatures or to seal by means of qualified electronic seals;(43)attribute means a seal characteristic, quality, right or permission of a natural or legal person or of an object;(44)electronic attestation of attributes means an attestation in electronic form that allows attributes to be authenticated;(45)qualified electronic attestation of attributes means an electronic attestation of attributes which is valid. issued by a qualified trust service provider and meets the requirements laid down in Annex V;(46)electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source means an electronic attestation of attributes issued by a public sector body that is responsible for an authentic source or by a public sector body that is designated by the Member State to issue such attestations of attributes on behalf of the public sector bodies responsible for authentic sources in accordance with Article 45f and with Annex VII;(47)authentic source means a repository or system, held under the responsibility of a public sector body or private entity, that contains and provides attributes about a natural or legal person or object and that is considered to be a primary source of that information or recognised as authentic in accordance with Union or national law, including administrative practice;(48)electronic archiving means a service ensuring the receipt, storage, retrieval and deletion of electronic data and electronic documents in order to ensure their durability and legibility as well as to preserve their integrity, confidentiality and proof of origin throughout the preservation period;(49)qualified electronic archiving service means an electronic archiving service which is provided by a qualified trust service provider and which meets the requirements laid down in Article 45j;(50)EU Digital Identity Wallet Trust Mark means a verifiable, simple and recognisable indication which is communicated in a clear manner that a European Digital Identity Wallet has been provided in accordance with this Regulation;(51)strong user authentication means an authentication based on the use of at least two authentication factors from different categories of either knowledge, something only the user knows, possession, something only the user possesses or inherence, something the user is, that are independent, in that the breach of one does not compromise the reliability of the others, and is designed in such a way as to protect the confidentiality of the authentication data;(52)electronic ledger means a sequence of electronic data records, ensuring the integrity of those records and the accuracy of the chronological ordering of those records;(53)qualified electronic ledger means an electronic ledger which is provided by a qualified trust service provider and which meets the requirements laid down in Article 45l;(54)personal data means any information as defined in Article 4, point (1), of Regulation (EU) 2016/679;(55)identity matching means a process where person identification data, or electronic identification means are matched with or linked to an existing account belonging to the same person;(56)data record means electronic data recorded with related meta-data supporting the processing of the data;(57)offline mode means, as regards the use of European Digital Identity Wallets, an interaction between a user and a third party at a physical location using close proximity technologies, whereby the European Digital Identity Wallet is not required to access remote systems via electronic communication networks for the purpose of the interaction.
MODIFIED Art. 5 — Pseudonyms in electronic transaction · applies from unchanged
The article's heading changed from referring to data processing and protection to referring solely to pseudonyms in electronic transaction. Art. 5, v1 Art. 5, v2
The former paragraph 1 stating that processing of personal data shall be carried out in accordance with Directive 95/46/EC has been removed, and the remaining text is no longer split into numbered paragraphs. Art. 5, v1 Art. 5, v2
The non-prohibition of pseudonyms now also carries an exception for specific rules of Union or national law requiring users to identify themselves, and specifies that the pseudonyms in question are those chosen by the user. Art. 5, v2
text before / after
texts differ too much for an inline diff; shown separately
before (32014R0910)
Article 5Data processing and protection1.Processing of personal data shall be carried out in accordance with Directive 95/46/EC.2.Without prejudice to the legal effect given to pseudonyms under national law, the use of pseudonyms in electronic transactions shall not be prohibited.
after (02014R0910-20240520)
Article 5Pseudonyms in electronic transactionWithout prejudice to specific rules of Union or national law requiring users to identify themselves or to the legal effect given to pseudonyms under national law, the use of pseudonyms that are chosen by the user shall not be prohibited.
INSERTED Art. 5a — European Digital Identity Wallets · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
A new Article 5a is added, setting out detailed provisions on European Digital Identity Wallets, covering how Member States must provide them, their functionalities, open-source licensing of the application source code, security, revocation, cost-free issuance and use, user control over data, accessibility, and related implementing-act mandates. Art. 5a, v2
The article includes a deadline requiring the Commission to adopt certain implementing acts by 21 November 2024 and requires Member States to make at least one wallet available within 24 months of the entry into force of those implementing acts. Art. 5a, v2
text before / after
inserted text (02014R0910-20240520)
Article 5aEuropean Digital Identity Wallets1.For the purpose of ensuring that all natural and legal persons in the Union have secure, trusted and seamless cross-border access to public and private services, while having full control over their data, each Member State shall provide at least one European Digital Identity Wallet within 24 months of the date of entry into force of the implementing acts referred to in paragraph 23 of this Article and in Article 5c(6).2.European Digital Identity Wallets shall be provided in one or more of the following ways:(a)directly by a Member State;(b)under a mandate from a Member State;(c)independently of a Member State but recognised by that Member State.3.The source code of the application software components of European Digital Identity Wallets shall be open-source licensed. Member States may provide that, for duly justified reasons, the source code of specific components other than those installed on user devices shall not be disclosed.4.European Digital Identity Wallets shall enable the user, in a manner that is user-friendly, transparent, and traceable by the user, to:(a)securely request, obtain, select, combine, store, delete, share and present, under the sole control of the user, person identification data and, where applicable, in combination with electronic attestations of attributes, to authenticate to relying parties online and, where appropriate, in offline mode, in order to access public and private services, while ensuring that selective disclosure of data is possible;(b)generate pseudonyms and store them encrypted and locally within the European Digital Identity Wallet;(c)securely authenticate another person’s European Digital Identity Wallet, and receive and share person identification data and electronic attestations of attributes in a secured way between the two European Digital Identity Wallets;(d)access a log of all transactions carried out through the European Digital Identity Wallet via a common dashboard enabling the user to:(i)view an up-to-date list of relying parties with which the user has established a connection and, where applicable, all data exchanged;(ii)easily request the erasure by a relying party of personal data pursuant to Article 17 of the Regulation (EU) 2016/679;(iii)easily report a relying party to the competent national data protection authority, where an allegedly unlawful or suspicious request for data is received;(e)sign by means of qualified electronic signatures or seal by means of qualified electronic seals;(f)download, to the extent technically feasible, the user’s data, electronic attestation of attributes and configurations;(g)exercise the user’s rights to data portability.5.European Digital Identity Wallets shall, in particular:(a)support common protocols and interfaces:(i)for issuance of person identification data, qualified and non-qualified electronic attestations of attributes or qualified and non-qualified certificates to the European Digital Identity Wallet;(ii)for relying parties to request and validate person identification data and electronic attestations of attributes;(iii)for the sharing and presentation to relying parties of person identification data, electronic attestation of attributes or of selectively disclosed related data online and, where appropriate, in offline mode;(iv)for the user to allow interaction with the European Digital Identity Wallet and display an EU Digital Identity Wallet Trust Mark;(v)to securely onboard the user by using an electronic identification means in accordance with Article 5a(24);(vi)for interaction between two persons’ European Digital Identity Wallets for the purpose of receiving, validating and sharing person identification data and electronic attestations of attributes in a secure manner;(vii)for authenticating and identifying relying parties by implementing authentication mechanisms in accordance with Article 5b;(viii)for relying parties to verify the authenticity and validity of European Digital Identity Wallets;(ix)for requesting a relying party the erasure of personal data pursuant to Article 17 of Regulation (EU) 2016/679;(x)for reporting a relying party to the competent national data protection authority where an allegedly unlawful or suspicious request for data is received;(xi)for the creation of qualified electronic signatures or electronic seals by means of qualified electronic signature or electronic seal creation devices;(b)not provide any information to trust service providers of electronic attestations of attributes about the use of those electronic attestations;(c)ensure that the relying parties can be authenticated and identified by implementing authentication mechanisms in accordance with Article 5b;(d)meet the requirements set out in Article 8 with regard to assurance level high, in particular as applied to the requirements for identity proofing and verification, and electronic identification means management and authentication;(e)in the case of the electronic attestation of attributes with embedded disclosure policies, implement the appropriate mechanism to inform the user that the relying party or the user of the European Digital Identity Wallet requesting that electronic attestation of attributes has the permission to access such attestation;(f)ensure that the person identification data, which is available from the electronic identification scheme under which the European Digital Identity Wallet is provided, uniquely represents the natural person, legal person or the natural person representing the natural or legal person, and is associated with that European Digital Identity Wallet;(g)offer all natural persons the ability to sign by means of qualified electronic signatures by default and free of charge.Notwithstanding point (g) of the first subparagraph, Member States may provide for proportionate measures to ensure that the use of qualified electronic signatures free-of-charge by natural persons is limited to non-professional purposes.6.Member State shall inform users, without delay, of any security breach that could have entirely or partially compromised their European Digital Identity Wallet or its contents, in particular if their European Digital Identity Wallet has been suspended or revoked pursuant to Article 5e.7.Without prejudice to Article 5f, Member States may provide, in accordance with national law, for additional functionalities of European Digital Identity Wallets, including interoperability with existing national electronic identification means. Those additional functionalities shall comply with this Article.8.Member States shall provide validation mechanisms free-of-charge, in order to:(a)ensure that the authenticity and validity of European Digital Identity Wallets can be verified;(b)allow users to verify the authenticity and validity of the identity of relying parties registered in accordance with Article 5b.9.Member States shall ensure that the validity of the European Digital Identity Wallet can be revoked in the following circumstances:(a)upon the explicit request of the user;(b)where the security of the European Digital Identity Wallet has been compromised;(c)upon the death of the user or cease of activity of the legal person.10.Providers of European Digital Identity Wallets shall ensure that users can easily request technical support and report technical problems or any other incidents having a negative impact on the use of European Digital Identity Wallets.11.European Digital Identity Wallets shall be provided under an electronic identification scheme with assurance level high.12.European Digital Identity Wallets shall ensure security-by-design.13.The issuance, use and revocation of the European Digital Identity Wallets shall be free of charge to all natural persons.14.Users shall have full control of the use of and of the data in their European Digital Identity Wallet. The provider of the European Digital Identity Wallet shall neither collect information about the use of the European Digital Identity Wallet which is not necessary for the provision of European Digital Identity Wallet services, nor combine person identification data or any other personal data stored or relating to the use of the European Digital Identity Wallet with personal data from any other services offered by that provider or from third-party services which are not necessary for the provision of European Digital Identity Wallet services, unless the user has expressly requested otherwise. Personal data relating to the provision of the European Digital Identity Wallet shall be kept logically separate from any other data held by the provider of the European Digital Identity Wallet. If the European Digital Identity Wallet is provided by private parties in accordance with paragraph 2, points (b) and (c), of this Article, the provisions of Article 45h(3) shall apply mutatis mutandis.15.The use of European Digital Identity Wallets shall be voluntary. Access to public and private services, access to the labour market and freedom to conduct business shall not in any way be restricted or made disadvantageous to natural or legal persons that do not use European Digital Identity Wallets. It shall remain possible to access public and private services by other existing identification and authentication means.16.The technical framework of the European Digital Identity Wallet shall:(a)not allow providers of electronic attestations of attributes or any other party, after the issuance of the attestation of attributes, to obtain data that allows transactions or user behaviour to be tracked, linked or correlated, or knowledge of transactions or user behaviour to be otherwise obtained, unless explicitly authorised by the user;(b)enable privacy preserving techniques which ensure unlikeability, where the attestation of attributes does not require the identification of the user.17.Any processing of personal data carried out by the Member States or on their behalf by bodies or parties responsible for the provision of European Digital Identity Wallets as electronic identification means shall be carried out in accordance with appropriate and effective data protection measures. Compliance of such processing with Regulation (EU) 2016/679 shall be demonstrated. Member States may introduce national provisions to further specify the application of such measures.18.Member States shall, without undue delay, notify the Commission of information about:(a)the body responsible for establishing and maintaining the list of registered relying parties that rely on European Digital Identity Wallets in accordance with Article 5b(5) and the location of that list;(b)the bodies responsible for the provision of European Digital Identity Wallets in accordance with Article 5a(1);(c)the bodies responsible for ensuring that the person identification data is associated with the European Digital Identity Wallet in accordance with Article 5a(5), point (f);(d)the mechanism allowing for the validation of the person identification data referred to in Article 5a(5), point (f), and of the identity of the relying parties;(e)the mechanism by which to validate the authenticity and validity of European Digital Identity Wallets.The Commission shall make available the information notified pursuant to the first subparagraph to the public through a secure channel, in electronically signed or sealed form suitable for automated processing.19.Without prejudice to paragraph 22 of this Article, Article 11 shall apply mutatis mutandis to the European Digital Identity Wallet.20.Article 24(2), points (b), and (d) to (h), shall apply mutatis mutandis to providers of European Digital Identity Wallets.21.European Digital Identity Wallets shall be made accessible for use, by persons with disabilities, on an equal basis with other users, in accordance with Directive (EU) 2019/882 of the European Parliament and of the CouncilDirective (EU) 2019/882 of the European Parliament and of the Council of 17 April 2019on the accessibility requirements for products and services (OJ L 151, 7.6.2019, p. 70)..22.For the purposes of the provision of European Digital Identity Wallets, European Digital Identity Wallets and the electronic identification schemes under which they are provided shall not be subject to the requirements laid down in Articles 7, 9, 10, 12 and 12a.23.By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the requirements referred to in paragraphs 4, 5, 8 and 18 of this Article on the implementation of the European Digital Identity Wallet. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).24.The Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures in order to facilitate the onboarding of users to the European Digital Identity Wallet either by electronic identification means conforming to assurance level high or by electronic identification means conforming to assurance level substantial in conjunction with additional remote onboarding procedures that together meet the requirements of assurance level high. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 5b — European Digital Identity Wallet-Relying Parties · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This is a newly inserted article setting out obligations for relying parties that intend to use European Digital Identity Wallets, including registration in their Member State of establishment, provision of specified information, restrictions on requesting additional data, publication of registered information, notification of changes, identification of relying parties to users, and rules on intermediaries acting on their behalf. Art. 5b, v2
It also directs the Commission to establish technical specifications and procedures for several of these requirements by means of implementing acts, with a stated deadline of 21 November 2024 for doing so. Art. 5b, v2
text before / after
inserted text (02014R0910-20240520)
Article 5bEuropean Digital Identity Wallet-Relying Parties1.Where a relying party intends to rely upon European Digital Identity Wallets for the provision of public or private services by means of digital interaction, the relying party shall register in the Member State where it is established.2.The registration process shall be cost-effective and proportionate-to-risk. The relying party shall provide at least:(a)the information necessary to authenticate to European Digital Identity Wallets, which as a minimum includes:(i)the Member State in which the relying party is established; and(ii)the name of the relying party and, where applicable, its registration number as stated in an official record together with identification data of that official record;(b)the contact details of the relying party;(c)the intended use of European Digital Identity Wallets, including an indication of the data to be requested by the relying party from users.3.Relying parties shall not request users to provide any data other than that indicated pursuant to paragraph 2, point (c).4.Paragraphs 1 and 2 shall be without prejudice to Union or national law that is applicable to the provision of specific services.5.Member States shall make the information referred to in paragraph 2 publicly available online in electronically signed or sealed form suitable for automated processing.6.Relying parties registered in accordance with this Article shall inform Member States without delay about any changes to the information provided in the registration pursuant to paragraph 2.7.Member States shall provide a common mechanism for allowing the identification and authentication of relying parties, as referred to in Article 5a(5), point (c).8.Where relying parties intend to rely upon European Digital Identity Wallets, they shall identify themselves to the user.9.Relying parties shall be responsible for carrying out the procedure for authenticating and validating person identification data and electronic attestation of attributes requested from European Digital Identity Wallets. Relying parties shall not refuse the use of pseudonyms, where the identification of the user is not required by Union or national law.10.Intermediaries acting on behalf of relying parties shall be deemed to be relying parties and shall not store data about the content of the transaction.11.By 21 November 2024, the Commission shall establish technical specifications and procedures for the requirements referred to in paragraphs 2, 5 and 6 to 9 of this Article by means of implementing acts on the implementation of European Digital Identity Wallets as referred to in Article 5a(23). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 5c — Certification of European Digital Identity Wallets · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This article is new and sets out a certification framework for European Digital Identity Wallets, requiring conformity assessment bodies designated by Member States to certify wallets against specified requirements, with cybersecurity-relevant requirements addressed through European cybersecurity certification schemes or, where those schemes do not fully cover them, through national certification schemes. Art. 5c, v2
It further provides that certification is valid for up to five years subject to periodic vulnerability assessment, that personal data processing aspects may be certified under Regulation (EU) 2016/679, and that the Commission is to adopt implementing acts establishing reference standards and specifications and delegated acts on criteria for conformity assessment bodies. Art. 5c, v2
text before / after
inserted text (02014R0910-20240520)
Article 5cCertification of European Digital Identity Wallets1.The conformity of European Digital Identity Wallets and the electronic identification scheme under which they are provided with the requirements laid down in Article 5a(4), (5), (8), the requirement for logical separation laid down in Article 5a(14) and, where applicable, with the standards and technical specifications referred to in Article 5a(24), shall be certified by conformity assessment bodies designated by Member States.2.Certification of the conformity of European Digital Identity Wallets with requirements referred to in paragraph 1 of this Article, or parts thereof, that are relevant for cybersecurity shall be carried out in accordance with European cybersecurity certification schemes adopted pursuant to Regulation (EU) 2019/881 of the European Parliament and of the CouncilRegulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ L 151, 7.6.2019, p. 15). and referred to in the implementing acts referred to in paragraph 6 of this Article.3.For requirements referred to in paragraph 1 of this Article that are not relevant for cybersecurity, and, for requirements referred to in paragraph 1 of this Article that are relevant for cybersecurity, to the extent that cybersecurity certification schemes as referred to in paragraph 2 of this Article do not, or only partially, cover those cybersecurity requirements, also for those requirements, Member States shall establish national certification schemes following the requirements set out in the implementing acts referred to in paragraph 6 of this Article. Member States shall transmit their draft national certification schemes to the European Digital Identity Cooperation Group established pursuant to Article 46e(1) (the Cooperation Group). The Cooperation Group may issue opinions and recommendations.4.Certification pursuant to paragraph 1 shall be valid for up to five years, provided that a vulnerability assessment is carried out every two years. Where a vulnerability is identified and not remedied in a timely manner, certification shall be cancelled.5.Compliance with the requirements set out in Article 5a of this Regulation related to the personal data processing operations may be certified pursuant to Regulation(EU) 2016/679.6.By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the certification of European Digital Identity Wallets referred to in paragraph 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).7.Member States shall communicate to the Commission the names and addresses of the conformity assessment bodies referred to in paragraph 1. The Commission shall make that information available to all Member States.8.The Commission shall be empowered to adopt delegated acts in accordance with Article 47 establishing specific criteria to be met by the designated conformity assessment bodies referred to in paragraph 1 of this Article.
INSERTED Art. 5d — Publication of a list of certified European Digital Identity Wallets · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This provision is entirely new, adding a set of rules requiring Member States to inform the Commission and the Cooperation Group about certified European Digital Identity Wallets, including certificates, assessment reports, supervisory and liability regimes, and arrangements for suspension or revocation. Art. 5d, v2
It also establishes a Commission-maintained, machine-readable list of certified wallets published in the Official Journal, with procedures for removal requests, updates, and a one-month timeline for reflecting changes, plus a deadline for the Commission to set formats and procedures by implementing act. Art. 5d, v2
The text itself states that the Commission shall establish the relevant formats and procedures by 21 November 2024. Art. 5d, v2
text before / after
inserted text (02014R0910-20240520)
Article 5dPublication of a list of certified European Digital Identity Wallets1.Member States shall inform the Commission and the Cooperation Group established pursuant to Article 46e(1) without undue delay of European Digital Identity Wallets that have been provided pursuant to Article 5a and certified by the conformity assessment bodies referred to in Article 5c(1). They shall inform the Commission and the Cooperation Group established pursuant to Article 46e(1), without undue delay if a certification is cancelled and shall state the reasons for the cancellation.2.Without prejudice to Article 5a(18), the information provided by Member States referred to in paragraph 1 of this Article shall include at least:(a)the certificate and certification assessment report of the certified European Digital Identity Wallet;(b)a description of the electronic identification scheme under which the European Digital Identity Wallet is provided;(c)the applicable supervisory regime and information on the liability regime with respect to the party providing the European Digital Identity Wallet;(d)the authority or authorities responsible for the electronic identification scheme;(e)arrangements for suspension or revocation of the electronic identification scheme or authentication or of the compromised parts concerned.3.On the basis of the information received pursuant to paragraph 1, the Commission shall establish, publish in the Official Journal of the European Union and maintain in a machine-readable form a list of certified European Digital Identity Wallets.4.A Member State may submit a request to the Commission to remove a European Digital Identity Wallet and the electronic identification scheme under which it is provided from the list referred to in paragraph 3.5.Where there are changes to the information provided pursuant to paragraph 1, the Member State shall provide the Commission with updated information.6.The Commission shall keep the list referred to in paragraph 3 updated by publishing in the Official Journal of the European Union the corresponding amendments to the list within one month of receipt of a request pursuant to paragraph 4 or of updated information pursuant to paragraph 5.7.By 21 November 2024, the Commission shall establish the formats and procedures applicable for the purposes of paragraphs 1, 4 and 5 of this Article by means of implementing acts on the implementation of European Digital Identity Wallets as referred to in Article 5a(23). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 5e — Security breach of European Digital Identity Wallets · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This new provision sets out obligations for a Member State when European Digital Identity Wallets, their validation mechanisms, or the underlying electronic identification scheme are breached or partly compromised, including suspension, withdrawal, notification of affected users, single points of contact, relying parties and the Commission, and re-establishment once the breach is remedied. Art. 5e, v2
It also directs the Commission to publish corresponding amendments to the list referred to in Article 5d and to adopt implementing acts establishing reference standards and, where necessary, specifications and procedures for these measures. Art. 5e, v2
text before / after
inserted text (02014R0910-20240520)
Article 5eSecurity breach of European Digital Identity Wallets1.Where European Digital Identity Wallets provided pursuant to Article 5a, the validation mechanisms referred to in Article 5a(8) or the electronic identification scheme under which the European Digital Identity Wallets are provided are breached or partly compromised in a manner that affects their reliability or the reliability of other European Digital Identity Wallets, the Member State that provided the European Digital Identity Wallets shall, without undue delay, suspend the provision and the use of European Digital Identity Wallets.Where justified by the severity of the security breach or compromise referred to in the first subparagraph, the Member State shall withdraw European Digital Identity Wallets without undue delay.The Member State shall inform the users affected, the single points of contact designated pursuant to Article 46c(1), the relying parties and the Commission accordingly.2.If the security breach or compromise referred to in paragraph 1, first subparagraph, of this Article is not remedied within three months of the suspension, the Member State that provided the European Digital Identity Wallets shall withdraw European Digital Identity Wallets and revoke their validity. The Member State shall inform the users affected, the single points of contact designated pursuant to Article 46c(1), the relying parties and the Commission of the withdrawal accordingly.3.Where the security breach or compromise referred to in paragraph 1, first subparagraph, of this Article is remedied, the providing Member State shall re-establish the provision and the use of European Digital Identity Wallets and inform the affected users and relying parties, the single points of contact designated pursuant to Article 46c(1) and the Commission without undue delay.4.The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list referred to in Article 5d without undue delay.5.By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the measures referred to in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 5f — Cross-border reliance on European Digital Identity Wallets · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This article is newly inserted and sets out obligations for public sector bodies, certain private relying parties, and providers of very large online platforms to accept European Digital Identity Wallets under specified conditions, along with provisions on codes of conduct and a Commission assessment of wallet demand and usability. Art. 5f, v2
text before / after
inserted text (02014R0910-20240520)
Article 5fCross-border reliance on European Digital Identity Wallets1.Where Member States require electronic identification and authentication to access an online service provided by a public sector body, they shall also accept European Digital Identity Wallets that are provided in accordance with this Regulation.2.Where private relying parties that provide services, with the exception of microenterprises and small enterprises as defined in Article 2 of the Annex to Commission Recommendation 2003/361/ECCommission Recommendation 2003/361/EC of 6 May 2003concerning the definition of micro, small and medium-sized enterprises (OJ L 124, 20.5.2003, p. 36)., are required by Union or national law to use strong user authentication for online identification or where strong user authentication for online identification is required by contractual obligation, including in the areas of transport, energy, banking, financial services, social security, health, drinking water, postal services, digital infrastructure, education or telecommunications, those private relying parties shall, no later than 36 months from the date of entry into force of the implementing acts referred to in Article 5a(23) and Article 5c(6) and only upon the voluntary request of the user, also accept European Digital Identity Wallets that are provided in accordance with this Regulation.3.Where providers of very large online platforms as referred to in Article 33 of Regulation (EU) 2022/2065 of the European Parliament and of the CouncilRegulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) (OJ L 277, 27.10.2022, p. 1). require user authentication for access to online services, they shall also accept and facilitate the use of European Digital Identity Wallets that are provided in accordance with this Regulation for user authentication only upon the voluntary request of the user and in respect of the minimum data necessary for the specific online service for which authentication is requested.4.In cooperation with Member States, the Commission shall facilitate the development of codes of conduct in close collaboration with all relevant stakeholders, including civil society, in order to contribute to the wide availability and usability of European Digital Identity Wallets within the scope of this Regulation, and to encourage service providers to complete the development of codes of conduct.5.Within 24 months after deployment of the European Digital Identity Wallets, the Commission shall assess the demand for, and the availability and usability of, European Digital Identity Wallets, taking into account criteria such as user take-up, cross-border presence of service providers, technological developments, evolution in usage patterns and consumer demand.
MODIFIED Art. 6 · applies from unknown
Disputed — seen by the instruction parse, not by the structural diff, corpus metadata.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED Art. 7 — Eligibility for notification of electronic identification schemes · applies from unchanged
In point (g), the phrasing describing the notifying Member State's obligation to provide a description of the scheme was reworded, with minor stylistic changes such as adding a comma and changing 'a description' to 'with a description'. Art. 7, v1 Art. 7, v2
The cross-reference to the implementing acts governing procedural arrangements was changed from Article 12(7) to Article 12(6). Art. 7, v1 Art. 7, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 7Eligibility for notification of electronic identification schemesAn electronic identification scheme shall be eligible for notification pursuant to Article 9(1) provided that all of the following conditions are met:(a)the electronic identification means under the electronic identification scheme are issued:(i)by the notifying Member State;(ii)under a mandate from the notifying Member State; or(iii)independently of the notifying Member State and are recognised by that Member State;(b)the electronic identification means under the electronic identification scheme can be used to access at least one service which is provided by a public sector body and which requires electronic identification in the notifying Member State;(c)the electronic identification scheme and the electronic identification means issued thereunder meet the requirements of at least one of the assurance levels set out in the implementing act referred to in Article 8(3);(d)the notifying Member State ensures that the person identification data uniquely representing the person in question is attributed, in accordance with the technical specifications, standards and procedures for the relevant assurance level set out in the implementing act referred to in Article 8(3), to the natural or legal person referred to in point 1 of Article 3 at the time the electronic identification means under that scheme is issued;(e)the party issuing the electronic identification means under that scheme ensures that the electronic identification means is attributed to the person referred to in point (d) of this Article in accordance with the technical specifications, standards and procedures for the relevant assurance level set out in the implementing act referred to in Article 8(3);(f)the notifying Member State ensures the availability of authentication online, so that any relying party established in the territory of another Member State is able to confirm the person identification data received in electronic form.For relying parties other than public sector bodies the notifying Member State may define terms of access to that authentication. The cross-border authentication shall be provided free of charge when it is carried out in relation to a service online provided by a public sector body.Member States shall not impose any specific disproportionate technical requirements on relying parties intending to carry out such authentication, where such requirements prevent or significantly impede the interoperability of the notified electronic identification schemes;(g)at least six months prior to the notification pursuant to Article 9(1), the notifying Member State provides the other Member States States, for the purposes of the obligation under Article 12(5) 12(5), with a description of that scheme in accordance with the procedural arrangements established by the implementing acts referred adopted pursuant to in Article 12(7);(h)the 12(6);(h)the electronic identification scheme meets the requirements set out in the implementing act referred to in Article 12(8).
MODIFIED Art. 8 — Assurance levels of electronic identification schemes · applies from unchanged
In paragraph 3, the closing phrase referencing the purposes of paragraph 1 has been removed, so the sentence now ends after stating that assurance levels are specified for electronic identification means. Art. 8, v1 Art. 8, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 8Assurance levels of electronic identification schemes1.An electronic identification scheme notified pursuant to Article 9(1) shall specify assurance levels low, substantial and/or high for electronic identification means issued under that scheme.2.The assurance levels low, substantial and high shall meet respectively the following criteria:(a)assurance level low shall refer to an electronic identification means in the context of an electronic identification scheme, which provides a limited degree of confidence in the claimed or asserted identity of a person, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease the risk of misuse or alteration of the identity;(b)assurance level substantial shall refer to an electronic identification means in the context of an electronic identification scheme, which provides a substantial degree of confidence in the claimed or asserted identity of a person, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease substantially the risk of misuse or alteration of the identity;(c)assurance level high shall refer to an electronic identification means in the context of an electronic identification scheme, which provides a higher degree of confidence in the claimed or asserted identity of a person than electronic identification means with the assurance level substantial, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to prevent misuse or alteration of the identity.3.By 18 September 2015, taking into account relevant international standards and subject to paragraph 2, the Commission shall, by means of implementing acts, set out minimum technical specifications, standards and procedures with reference to which assurance levels low, substantial and high are specified for electronic identification means for the purposes of paragraph 1.Those means.Those minimum technical specifications, standards and procedures shall be set out by reference to the reliability and quality of the following elements:(a)the procedure to prove and verify the identity of natural or legal persons applying for the issuance of electronic identification means;(b)the procedure for the issuance of the requested electronic identification means;(c)the authentication mechanism, through which the natural or legal person uses the electronic identification means to confirm its identity to a relying party;(d)the entity issuing the electronic identification means;(e)any other body involved in the application for the issuance of the electronic identification means; and(f)the technical and security specifications of the issued electronic identification means.Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 9 — Notification · applies from unchanged
Paragraph 2 no longer ties publication of the list of notified electronic identification schemes to a date one year after the implementing acts under Articles 8(3) and 12(8) apply, instead requiring the Commission to publish that list without undue delay. Art. 9, v1 Art. 9, v2
Paragraph 3 no longer conditions publication of amendments to the list on receiving a notification after the expiry of the period referred to in paragraph 2, and shortens the publication deadline for such amendments from two months to one month from receipt of the notification. Art. 9, v1 Art. 9, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 9Notification1.The notifying Member State shall notify to the Commission the following information and, without undue delay, any subsequent changes thereto:(a)a description of the electronic identification scheme, including its assurance levels and the issuer or issuers of electronic identification means under the scheme;(b)the applicable supervisory regime and information on the liability regime with respect to the following:(i)the party issuing the electronic identification means; and(ii)the party operating the authentication procedure;(c)the authority or authorities responsible for the electronic identification scheme;(d)information on the entity or entities which manage the registration of the unique person identification data;(e)a description of how the requirements set out in the implementing acts referred to in Article 12(8) are met;(f)a description of the authentication referred to in point (f) of Article 7;(g)arrangements for suspension or revocation of either the notified electronic identification scheme or authentication or the compromised parts concerned.2.One year from the date of application of the implementing acts referred to in Articles 8(3) and 12(8), the concerned.2.The Commission shall shall, without undue delay, publish in the Official Journal of the European Union a list of the electronic identification schemes which were notified pursuant to paragraph 1 of this Article and the together with basic information thereon.3.If the about those schemes.3.The Commission receives a notification after the expiry of the period referred to in paragraph 2, it shall publish in the Official Journal of the European Union the amendments to the list referred to in paragraph 2 within two months from one month of the date of receipt of that notification.4.A Member State may submit to the Commission a request to remove an electronic identification scheme notified by that Member State from the list referred to in paragraph 2. The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list within one month from the date of receipt of the Member State’s request.5.The Commission may, by means of implementing acts, define the circumstances, formats and procedures of notifications under paragraph 1. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 10 — Security breach of electronic identification schemes · applies from unchanged
The only change is to the article's heading, which now reads 'Security breach of electronic identification schemes' instead of simply 'Security breach'. Art. 10, v1 Art. 10, v2
The operative text of paragraphs 1 through 3 is unchanged between the two versions. Art. 10, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 10Security breach1.Where breach of electronic identification schemes1.Where either the electronic identification scheme notified pursuant to Article 9(1) or the authentication referred to in point (f) of Article 7 is breached or partly compromised in a manner that affects the reliability of the cross-border authentication of that scheme, the notifying Member State shall, without delay, suspend or revoke that cross-border authentication or the compromised parts concerned, and shall inform other Member States and the Commission.2.When the breach or compromise referred to in paragraph 1 is remedied, the notifying Member State shall re-establish the cross-border authentication and shall inform other Member States and the Commission without undue delay.3.If the breach or compromise referred to in paragraph 1 is not remedied within three months of the suspension or revocation, the notifying Member State shall notify other Member States and the Commission of the withdrawal of the electronic identification scheme.The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list referred to in Article 9(2) without undue delay.
INSERTED Art. 11a — Cross-border identity matching · applies from unknown (an inserted provision states its own application date only in prose)
A new Article 11a is added, requiring Member States acting as relying parties for cross-border services to ensure unequivocal identity matching for natural persons who use notified electronic identification means or European Digital Identity Wallets. Art. 11a, v2
It further requires Member States to provide technical and organisational measures ensuring a high level of protection for personal data used in identity matching and preventing profiling of users, and it directs the Commission to establish a list of reference standards and, where necessary, specifications and procedures by implementing acts under the examination procedure of Article 48(2). Art. 11a, v2
text before / after
inserted text (02014R0910-20240520)
Article 11aCross-border identity matching1.When acting as relying parties for cross-border services, Member States shall ensure unequivocal identity matching for natural persons using notified electronic identification means or European Digital Identity Wallets.2.Member States shall provide for technical and organisational measures to ensure a high level of protection of personal data used for identity matching and to prevent the profiling of users.3.By 21 November 2024, the Commission shall establish a list of reference standards and, where necessary, establish specifications and procedures for the requirements referred to in paragraph 1 of this Article by means of implementing acts. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 12 — Interoperability · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
The heading of Article 12 has changed from a phrase referring to cooperation and interoperability to simply Interoperability. Art. 12, v1 Art. 12, v2
Criterion (c) of paragraph 3 no longer refers to privacy by design alone but to privacy and security by design, and the description of the person identification data set in paragraph 4(d) now covers data necessary to uniquely represent a natural or legal person, or a natural person representing another natural person or a legal person. Art. 12, v2
Paragraph 5, which previously described areas of Member State cooperation on interoperability and security, and paragraph 6, which previously listed forms that cooperation would take, have been replaced with text on Member States carrying out peer reviews of notified electronic identification schemes and a new deadline of 18 March 2025 for the Commission to establish procedural arrangements for those peer reviews, while paragraph 8's deadline has moved to 18 September 2025. Art. 12, v1 Art. 12, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 12Cooperation and interoperability1.The 12Interoperability1.The national electronic identification schemes notified pursuant to Article 9(1) shall be interoperable.2.For the purposes of paragraph 1, an interoperability framework shall be established.3.The interoperability framework shall meet the following criteria:(a)it aims to be technology neutral and does not discriminate between any specific national technical solutions for electronic identification within a Member State;(b)it follows European and international standards, where possible;(c)it facilitates the implementation of the principle of privacy and security by design; and(d)it design.(d)it ensures that personal data is processed in accordance with Directive 95/46/EC.4.The interoperability framework shall consist of:(a)a reference to minimum technical requirements related to the assurance levels under Article 8;(b)a mapping of national assurance levels of notified electronic identification schemes to the assurance levels under Article 8;(c)a reference to minimum technical requirements for interoperability;(d)a reference to a minimum set of person identification data necessary to uniquely representing represent a natural or legal person, or a natural person representing another natural person or a legal person, which is available from electronic identification schemes;(e)rules of procedure;(f)arrangements for dispute resolution; and(g)common operational security standards.5.Member States shall cooperate with regard to the following:(a)the interoperability carry out peer reviews of the electronic identification schemes that fall within the scope of this Regulation and that are to be notified pursuant to Article 9(1) 9(1), point (a).6.By 18 March 2025, the Commission shall, by means of implementing acts, establish the necessary procedural arrangements for the peer reviews referred to in paragraph 5 of this Article with a view to fostering a high level of trust and security appropriate to the electronic identification schemes which Member States intend degree of risk. Those implementing acts shall be adopted in accordance with the examination procedure referred to notify; and(b)the security of the electronic identification schemes.6.The cooperation between Member States shall consist of:(a)the exchange of information, experience and good practice as regards electronic identification schemes and in particular technical requirements related to interoperability and assurance levels;(b)the exchange of information, experience and good practice as regards working with assurance levels of electronic identification schemes under Article 8;(c)peer review of electronic identification schemes falling under this Regulation; and(d)examination of relevant developments in the electronic identification sector.7.By 48(2).7.By 18 March 2015, the Commission shall, by means of implementing acts, establish the necessary procedural arrangements to facilitate the cooperation between the Member States referred to in paragraphs 5 and 6 with a view to fostering a high level of trust and security appropriate to the degree of risk.8.By 18 September 2015, 2025, for the purpose of setting uniform conditions for the implementation of the requirement under paragraph 1, 1 of this Article, the Commission shall, subject to the criteria set out in paragraph 3 of this Article and taking into account the results of the cooperation between Member States, adopt implementing acts on the interoperability framework as set out in paragraph 4.9.The 4 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).9.The implementing acts referred to in paragraphs 7 and 8 of this Article shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 12a — Certification of electronic identification schemes · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This new provision introduces a certification process for electronic identification schemes, requiring conformity assessment bodies designated by Member States to certify that such schemes meet the cybersecurity requirements of the Regulation, including those tied to assurance levels under Article 8(2). Art. 12a, v2
It sets out that certification is to be carried out under a cybersecurity certification scheme under Regulation (EU) 2019/881, specifies a validity period of up to five years contingent on biennial vulnerability assessments and cancellation if a vulnerability is not remedied within three months, and describes how such certification interacts with peer review and information-sharing obligations among Member States and the Commission. Art. 12a, v2
text before / after
inserted text (02014R0910-20240520)
Article 12aCertification of electronic identification schemes1.The conformity of electronic identification schemes to be notified with the cybersecurity requirements laid down in this Regulation, including conformity with the cybersecurity relevant requirements set out in Article 8(2) regarding the assurance levels of electronic identification schemes, shall be certified by conformity assessment bodies designated by Member States.2.Certification pursuant to paragraph 1 of this Article shall be carried out under a relevant cybersecurity certification scheme pursuant to Regulation (EU) 2019/881 or parts thereof, insofar as the cybersecurity certificate or parts thereof cover those cybersecurity requirements.3.Certification pursuant to paragraph 1 shall be valid for up to five years, provided that a vulnerability assessment is carried out every two years. Where a vulnerability is identified and not remedied within three months of such identification, certification shall be cancelled.4.Notwithstanding paragraph 2, Member States may request, in accordance with that paragraph, additional information from a notifying Member State about electronic identification schemes or part thereof certified.5.The peer review of electronic identification schemes referred to in Article 12(5) shall not apply to electronic identification schemes or parts of such schemes certified in accordance with paragraph 1 of this Article. Member States may use a certificate or a statement of conformity, issued in accordance with a relevant certification scheme or parts of such schemes, with the non-cybersecurity-related requirements set out in Article 8(2) regarding the assurance level of electronic identification schemes.6.Member States shall communicate to the Commission the names and addresses of the conformity assessment bodies referred to in paragraph 1. The Commission shall make that information available to all Member States.
INSERTED Art. 12b — Access to hardware and software features · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
Article 12b is a newly added provision setting out that gatekeepers must allow providers of European Digital Identity Wallets and issuers of notified electronic identification means, when acting as business users under Regulation (EU) 2022/1925, effective interoperability with and access to the same operating system, hardware or software features used by the gatekeeper. Art. 12b, v2
The text specifies that this interoperability and access must be provided free of charge and regardless of whether the relevant hardware or software features form part of the operating system or are otherwise used by the gatekeeper, and states that the Article applies without prejudice to Article 5a(14) of the Regulation. Art. 12b, v2
text before / after
inserted text (02014R0910-20240520)
Article 12bAccess to hardware and software featuresWhere providers of European Digital Identity Wallets and issuers of notified electronic identification means that act in a commercial or professional capacity and use core platform services as defined in Article 2, point (2), of Regulation (EU) 2022/1925 of the European Parliament and of the CouncilRegulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) (OJ L 265, 12.10.2022, p. 1). for the purpose or in the course of providing European Digital Identity Wallet services and electronic identification means to end-users are business users as defined in Article 2, point (21), of that Regulation, gatekeepers shall in particular allow them effective interoperability with, and, for the purposes of interoperability, access to, the same operating system, hardware or software features. Such effective interoperability and access shall be allowed free of charge and regardless of whether the hardware or software features are part of the operating system, are available to, or are used by, that gatekeeper when providing such services, within the meaning of Article 6(7) of Regulation (EU) 2022/1925. This Article is without prejudice to Article 5a(14) of this Regulation.
MODIFIED Art. 13 — Liability and burden of proof · applies from unchanged
The opening qualifier changes from 'Without prejudice to paragraph 2' to 'Notwithstanding paragraph 2 of this Article and without prejudice to Regulation (EU) 2016/679', adding an explicit reference to the data protection regulation. Art. 13, v1 Art. 13, v2
A new sentence is added stating that any natural or legal person who has suffered material or non-material damage as a result of an infringement of this Regulation by a trust service provider has the right to seek compensation in accordance with Union and national law. Art. 13, v2
The second subparagraph's wording changes from 'proving intention or negligence' to 'proving the intention or negligence', adding the definite article before the term. Art. 13, v1 Art. 13, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 13Liability and burden of proof1.Without proof1.Notwithstanding paragraph 2 of this Article and without prejudice to paragraph 2, Regulation (EU) 2016/679, trust service providers shall be liable for damage caused intentionally or negligently to any natural or legal person due to a failure to comply with the obligations under this Regulation.The Regulation. Any natural or legal person who has suffered material or non-material damage as a result of an infringement of this Regulation by a trust service provider shall have the right to seek compensation in accordance with Union and national law.The burden of proving the intention or negligence of a non-qualified trust service provider shall lie with the natural or legal person claiming the damage referred to in the first subparagraph.The intention or negligence of a qualified trust service provider shall be presumed unless that qualified trust service provider proves that the damage referred to in the first subparagraph occurred without the intention or negligence of that qualified trust service provider.2.Where trust service providers duly inform their customers in advance of the limitations on the use of the services they provide and where those limitations are recognisable to third parties, trust service providers shall not be liable for damages arising from the use of services exceeding the indicated limitations.3.Paragraphs 1 and 2 shall be applied in accordance with national rules on liability.
MODIFIED Art. 14 — International aspects · applies from unchanged
The provision now allows recognition of trust services from a third country or an international organisation not only through an Article 218 TFEU agreement but also through implementing acts, and specifies that such implementing acts are to be adopted under the examination procedure referred to in Article 48(2). Art. 14, v2
The requirement that the third country or international organisation meet the same requirements as EU qualified trust service providers is now tied to both implementing acts and the agreement, and a new duty is added for third countries and international organisations to establish, maintain and publish a trusted list of recognised trust service providers, whereas the prior text only referenced an agreement and did not mention such a list. Art. 14, v1 Art. 14, v2
The rule on mutual recognition of EU qualified trust services as equivalent to those from the third country or international organisation, previously part of paragraph 2, is now set out as a separate paragraph 3 tied specifically to the agreement. Art. 14, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 14International aspects1.Trust services provided by trust service providers established in a third country or by an international organisation shall be recognised as legally equivalent to qualified trust services provided by qualified trust service providers established in the Union Union, where the trust services originating from the third country or from the international organisation are recognised under by means of implementing acts or an agreement concluded between the Union and the third country in question or an the international organisation pursuant to Article 218 TFEU.The implementing acts referred to in the first subparagraph shall be adopted in accordance with the examination procedure referred to in Article 218 TFEU.2.Agreements 48(2).2.The implementing acts and the agreement referred to in paragraph 1 shall ensure, in particular, that:(a)the ensure that the requirements applicable to qualified trust service providers established in the Union and the qualified trust services they provide are met by the trust service providers in the third country concerned or by the international organisations with which the agreement is concluded, organisation and by the trust services they provide;(b)the provide. Third countries and international organisations shall in particular establish, maintain and publish a trusted list of recognised trust service providers.3.The agreement referred to in paragraph 1 shall ensure that the qualified trust services provided by qualified trust service providers established in the Union are recognised as legally equivalent to trust services provided by trust service providers in the third country or by the international organisation with which the agreement is concluded.
MODIFIED Art. 15 — Accessibility for persons with disabilities and special needs · applies from unchanged
Disputed — seen by the structural diff, corpus metadata, not by the instruction parse.
The heading is expanded to add 'and special needs' alongside persons with disabilities. Art. 15, v2
The substantive text moves from a feasibility-qualified accessibility duty covering trust services and end-user products to a broader requirement covering electronic identification means, trust services and end-user products, requiring them to be made available in plain and intelligible language and in line with the United Nations Convention on the Rights of Persons with Disabilities and the accessibility requirements of Directive (EU) 2019/882. Art. 15, v1 Art. 15, v2
The revised text also adds language stating that this also benefits persons who experience functional limitations, such as elderly people, and persons with limited access to digital technologies. Art. 15, v2
text before / after
texts differ too much for an inline diff; shown separately
before (32014R0910)
Article 15Accessibility for persons with disabilitiesWhere feasible, trust services provided and end-user products used in the provision of those services shall be made accessible for persons with disabilities.
after (02014R0910-20240520)
Article 15Accessibility for persons with disabilities and special needsThe provision of electronic identification means, trust services and end-user products that are used in the provision of those services shall be made available in plain and intelligible language, in accordance with the United Nations Convention on the Rights of Persons with Disabilities and with the accessibility requirements of Directive (EU) 2019/882, thus also benefiting persons who experience functional limitations, such as elderly people, and persons with limited access to digital technologies.
MODIFIED Art. 16 — Penalties · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
Disputed — seen by the structural diff, corpus metadata, not by the instruction parse.
The provision is now split into three numbered paragraphs, with the original single sentence on Member States setting effective, proportionate and dissuasive penalty rules retained but made subject to Article 31 of Directive (EU) 2022/2555. Art. 16, v1 Art. 16, v2
New text requires Member States to ensure infringements by qualified and non-qualified trust service providers are subject to administrative fines with specified minimum maximum thresholds, either a fixed amount for natural persons or the higher of a fixed amount or a percentage of worldwide annual turnover for legal persons. Art. 16, v2
A further new paragraph addresses how, depending on a Member State's legal system, the fine may be initiated by a competent supervisory body and imposed by national courts, with a requirement that such remedies be effective and equivalent to administrative fines imposed directly by supervisory authorities. Art. 16, v2
text before / after
texts differ too much for an inline diff; shown separately
before (32014R0910)
Article 16PenaltiesMember States shall lay down the rules on penalties applicable to infringements of this Regulation. The penalties provided for shall be effective, proportionate and dissuasive.
after (02014R0910-20240520)
Article 16Penalties1.Without prejudice to Article 31 of Directive (EU) 2022/2555 of the European Parliament and of the CouncilDirective (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80)., Member States shall lay down the rules on penalties applicable to infringements of this Regulation. Those penalties shall be effective, proportionate and dissuasive.2.Member States shall ensure that infringements of this Regulation by qualified and non-qualified trust service providers be subject to administrative fines of a maximum of at least:(a)EUR 5000000 where the trust service provider is a natural person; or(b)where the trust service provider is a legal person, EUR 5000000 or 1 % of the total worldwide annual turnover of the undertaking to which the trust service provider belonged in the financial year preceding the year in which the infringement occurred, whichever is higher.3.Depending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fine is initiated by the competent supervisory body and imposed by competent national courts. The application of such rules in those Member States shall ensure that those legal remedies are effective and have an equivalent effect to administrative fines imposed directly by supervisory authorities.
DELETED Art. 17 · applies from unknown
Disputed — seen by corpus metadata, the instruction parse, not by the structural diff.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
DELETED Art. 18 · applies from unknown
Disputed — seen by corpus metadata, not by the structural diff, the instruction parse.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
INSERTED Art. 19a — Requirements for non-qualified trust service providers · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This is a newly inserted article setting out requirements for non-qualified trust service providers, covering risk-management policies and breach-notification duties, along with a Commission mandate to adopt implementing acts on standards and specifications by 21 May 2025. Art. 19a, v2
text before / after
inserted text (02014R0910-20240520)
Article 19aRequirements for non-qualified trust service providers1.A non-qualified trust service provider providing non-qualified trust services shall:(a)have appropriate policies and take corresponding measures to manage legal, business, operational and other direct or indirect risks to the provision of the non-qualified trust service, which shall, notwithstanding Article 21 of Directive (EU) 2022/2555, include at least measures relating to:(i)registration and onboarding procedures for a trust service;(ii)procedural or administrative checks needed to provide trust services;(iii)the management and implementation of trust services;(b)notifying the supervisory body, the identifiable affected individuals, the public if it is of public interest and, where applicable, other relevant competent authorities, of any security breaches or disruptions in the provision of the service or the implementation of the measures referred to in point (a) (i), (ii) or (iii), that have a significant impact on the trust service provided or on the personal data maintained therein, without undue delay and in any case no later than 24 hours of having become aware of any security breaches or disruptions.2.By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for paragraph 1, point (a), of this Article. Compliance with the requirements laid down in this Article shall be presumed where those standards, specifications and procedures are met. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 20 — Supervision of qualified trust service providers · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
The provision now requires audits under paragraph 1 to also confirm fulfilment of Article 21 of Directive (EU) 2022/2555, adds new paragraphs 1a and 1b requiring advance notice of planned audits with supervisory-body observer participation and Member State notification of conformity assessment body details to the Commission, and changes the personal-data-breach notification duty in paragraph 2 to specify informing the competent supervisory authorities under Article 51 of Regulation (EU) 2016/679 without undue delay. Art. 20, v2
Paragraph 3 is restructured to separate the requirement to remedy from the withdrawal decision, and new paragraphs 3a, 3b and 3c are added covering withdrawal triggered by notifications from authorities under Directive (EU) 2022/2555 and Regulation (EU) 2016/679, and detailing information duties to the trusted-list body and competent authorities. Art. 20, v2
Paragraph 4 is changed from a general mandate for implementing acts on standards to a mandate with a deadline of 21 May 2025 to establish reference standards and, where necessary, specifications and procedures, adding a new point (c) on conformity assessment schemes alongside the existing accreditation and auditing points, compared with the corresponding text in the earlier version. Art. 20, v1 Art. 20, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 20Supervision of qualified trust service providers1.Qualified trust service providers shall be audited at their own expense at least every 24 months by a conformity assessment body. The purpose of the audit shall be to confirm that the qualified trust service providers and the qualified trust services provided by them fulfil the requirements laid down in this Regulation. The qualified Regulation and in Article 21 of Directive (EU) 2022/2555. Qualified trust service providers shall submit the resulting conformity assessment report to the supervisory body within the period of three working days after receiving it.2.Without of receipt.1a.Qualified trust service providers shall inform the supervisory body at the latest one month before any planned audits and shall allow the supervisory body to participate as an observer upon request.1b.Member States shall, without undue delay, notify to the Commission the names, addresses and accreditation details of the conformity assessment bodies referred to in paragraph 1 and any subsequent changes thereto. The Commission shall make that information available to all Member States.2.Without prejudice to paragraph 1, the supervisory body may at any time audit or request a conformity assessment body to perform a conformity assessment of the qualified trust service providers, at the expense of those trust service providers, to confirm that they and the qualified trust services provided by them fulfil the requirements laid down in this Regulation. Where personal data protection rules appear to have been breached, the supervisory body shall shall, without undue delay, inform the data protection competent supervisory authorities established pursuant to Article 51 of the results of its audits.3.Where the supervisory body requires Regulation (EU) 2016/679.3.Where the qualified trust service provider to remedy any failure fails to fulfil any of the requirements under set out by this Regulation and where Regulation, the supervisory body shall require it to provide a remedy within a set time limit, if applicable.Where that provider does not act accordingly, and if provide a remedy and, where applicable within a the time limit set by the supervisory body, the supervisory body, taking into account, where justified in particular, particular by the extent, duration and consequences of that failure, may shall withdraw the qualified status of that provider or of the affected service it provides and inform provides.3a.Where the competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 informs the supervisory body referred that the qualified trust service provider fails to fulfil any of the requirements set out in Article 22(3) for 21 of that Directive, the purposes supervisory body, where justified in particular by the extent, duration and consequences of updating that failure, shall withdraw the trusted lists referred qualified status of that provider or of the affected service that it provides.3b.Where the supervisory authorities established pursuant to Article 51 of Regulation (EU) 2016/679 informs the supervisory body that the qualified trust service provider fails to fulfil any of the requirements set out in Article 22(1). The that Regulation, the supervisory body, where justified in particular by the extent, duration and consequences of that failure, shall withdraw the qualified status of that provider or of the affected service it provides.3c.The supervisory body shall inform the qualified trust service provider of the withdrawal of its qualified status or of the qualified status of the service concerned.4.The concerned. The supervisory body shall inform the body notified pursuant to Article 22(3) of this Regulation for the purposes of updating the trusted lists referred to in paragraph 1 of that Article and the competent authority designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555.4.By 21 May 2025, the Commission may, shall, by means of implementing acts, establish a list of reference number of standards and, where necessary, establish specifications and procedures for the following standards:(a)accreditation following:(a)the accreditation of the conformity assessment bodies and for the conformity assessment report referred to in paragraph 1;(b)auditing rules under which 1;(b)the auditing requirements for the conformity assessment bodies will to carry out their conformity assessment, including composite assessment, of the qualified trust service providers as referred to in paragraph 1;(c)the conformity assessment schemes for carrying out the conformity assessment of the qualified trust service providers as by the conformity assessment bodies and for the provision of the report referred to in paragraph 1.Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 21 — Initiation of a qualified trust service · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
No explanation shipped — UnexpectedModelBehavior: Exceeded maximum output retries (1).
text before / after
32014R0910 → 02014R0910-20240520
Article 21Initiation of a qualified trust service1.Where trust service providers, without qualified status, providers intend to start providing a qualified trust services, service, they shall submit to notify the supervisory body a notification of their intention together with a conformity assessment report issued by a conformity assessment body.2.The body confirming the fulfilment of the requirements laid down in this Regulation and in Article 21 of Directive (EU) 2022/2555.2.The supervisory body shall verify whether the trust service provider and the trust services provided by it comply with the requirements laid down in this Regulation, and Regulation and, in particular, with the requirements for qualified trust service providers and for the qualified trust services they provide.If provide.In order to verify the compliance of the trust service provider with the requirements laid down in Article 21 of Directive (EU) 2022/2555, the supervisory body shall request the competent authorities designated or established pursuant to Article 8(1) of that Directive to carry out supervisory actions in that regard and to provide information about the outcome without undue delay and in any event within two months of receipt of that request. If the verification is not concluded within two months of the notification, those competent authorities shall inform the supervisory body specifying the reasons for the delay and the period within which the verification is to be concluded.Where the supervisory body concludes that the trust service provider and the trust services provided by it comply with the requirements referred to laid down in the first subparagraph, this Regulation, the supervisory body shall grant qualified status to the trust service provider and the trust services it provides and inform the body referred to in Article 22(3) for the purposes of updating the trusted lists referred to in Article 22(1), not later than three months after notification in accordance with paragraph 1 of this Article.If Article.Where the verification is not concluded within three months of notification, the supervisory body shall inform the trust service provider specifying the reasons for the delay and the period within which the verification is to be concluded.3.Qualified trust service providers may begin to provide the qualified trust service after the qualified status has been indicated in the trusted lists referred to in Article 22(1).4.The 22(1).4.By 21 May 2025, the Commission may, shall, by means of implementing acts, define establish the formats and procedures of the notification and verification for the purpose purposes of paragraphs 1 and 2. 2 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 24 — Requirements for qualified trust service providers · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
The identity and attribute verification obligations previously placed in paragraph 1 for qualified certificates have been expanded to also cover qualified electronic attestations of attributes, and separate detailed verification methods for identity and for attributes are now set out in new paragraphs 1a and 1b, with a new paragraph 1c requiring the Commission to adopt implementing acts on standards and procedures by 21 May 2025. Art. 24, v2
Paragraph 2 now adds timing requirements for notifying the supervisory body of changes or cessation, introduces new points (fa) and (fb) on risk-management measures and breach notification, broadens the anti-forgery point to include misappropriation and unauthorised deletion or alteration of data, changes the retention duration wording, updates the internal cross-reference for the termination plan, and adds a new subparagraph on supervisory body information requests and verification timelines. Art. 24, v2
New paragraphs 4a and 4b extend the revocation rules to qualified electronic attestations of attributes and empower the Commission to adopt delegated acts on additional measures under point (fa), while paragraph 5 now requires the Commission, by 21 May 2025, to establish reference standards, specifications and procedures for the paragraph 2 requirements instead of merely reference numbers of standards. Art. 24, v2 Art. 24, v1
text before / after
32014R0910 → 02014R0910-20240520
Article 24Requirements for qualified trust service providers1.When issuing a qualified certificate for or a trust service, qualified electronic attestation of attributes, a qualified trust service provider shall verify, by appropriate means and in accordance with national law, verify the identity and, if applicable, any specific attributes of the natural or legal person to whom the qualified certificate or the qualified electronic attestation of attributes is issued.The information to be issued.1a.The verification of the identity referred to in the first subparagraph paragraph 1 shall be verified performed, by appropriate means, by the qualified trust service provider provider, either directly or by relying means of a third party, on the basis of one of the following methods or, when needed, on a third party combination thereof in accordance with national law:(a)by the implementing acts referred to in paragraph 1c:(a)by means of the European Digital Identity Wallet or a notified electronic identification means which meets the requirements set out in Article 8 with regard to assurance level high;(b)by means of a certificate of a qualified electronic signature or of a qualified electronic seal, issued in compliance with point (a), (c) or (d);(c)by using other identification methods which ensure the identification of the person with a high level of confidence, the conformity of which shall be confirmed by a conformity assessment body;(d)through the physical presence of the natural person or of an authorised representative of the legal person; or(b)remotely, using person, by means of appropriate evidence and procedures, in accordance with national law.1b.The verification of the attributes referred to in paragraph 1 shall be performed, by appropriate means, by the qualified trust service provider, either directly or by means of a third party, on the basis of one of the following methods or, where necessary, on a combination thereof, in accordance with the implementing acts referred to in paragraph 1c:(a)by means of the European Digital Identity Wallet or a notified electronic identification means, for means which prior meets the requirements set out in Article 8 with regard to assurance level high;(b)by means of a certificate of a qualified electronic signature or of a qualified electronic seal, issued in accordance with paragraph 1a, point (a), (c) or (d);(c)by means of a qualified electronic attestation of attributes;(d)by using other methods, which ensure the issuance verification of the qualified certificate, attributes with a high level of confidence, the conformity of which shall be confirmed by a conformity assessment body;(e)by means of the physical presence of the natural person or of an authorised representative of the legal person was ensured person, by means of appropriate evidence and which meets procedures, in accordance with national law.1c.By 21 May 2025, the requirements set out Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the verification of identity and attributes in accordance with paragraphs 1, 1a and 1b of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 8 with regard to the assurance levels substantial or high; or(c)by means of a certificate of a qualified electronic signature or of a qualified electronic seal issued in compliance with point (a) or (b); or(d)by using other identification methods recognised at national level which provide equivalent assurance in terms of reliability to physical presence. The equivalent assurance shall be confirmed by a conformity assessment body.2.A 48(2).2.A qualified trust service provider providing qualified trust services shall:(a)inform the supervisory body of at least one month before implementing any change in the provision of its qualified trust services and or at least three months in case of an intention to cease those activities;(b)employ staff and, if applicable, subcontractors who possess the necessary expertise, reliability, experience, and qualifications and who have received appropriate training regarding security and personal data protection rules and shall apply administrative and management procedures which correspond to European or international standards;(c)with regard to the risk of liability for damages in accordance with Article 13, maintain sufficient financial resources and/or obtain appropriate liability insurance, in accordance with national law;(d)before entering into a contractual relationship, inform, in a clear clear, comprehensive and comprehensive easily accessible manner, in a publicly accessible space and individually any person seeking to use a qualified trust service of the precise terms and conditions regarding the use of that service, including any limitations on its use;(e)use trustworthy systems and products that are protected against modification and ensure the technical security and reliability of the processes supported by them;(f)use them, including using suitable cryptographic techniques;(f)use trustworthy systems to store data provided to it, in a verifiable form so that:(i)they are publicly available for retrieval only where the consent of the person to whom the data relates has been obtained,(ii)only authorised persons can make entries and changes to the stored data,(iii)the data can be checked for authenticity;(g)take authenticity;(fa)notwithstanding Article 21 of Directive (EU) 2022/2555, have appropriate policies and take corresponding measures to manage legal, business, operational and other direct or indirect risks to the provision of the qualified trust service, including at least measures related to the following:(i)registration and onboarding procedures for a service;(ii)procedural or administrative checks;(iii)the management and implementation of services;(fb)notify the supervisory body, the identifiable affected individuals, other relevant competent bodies where applicable and, at the request of the supervisory body, the public if it is of public interest, of any security breaches or disruptions in the provision of the service or the implementation of the measures referred to in point (fa)(i), (ii) or (iii) that have a significant impact on the trust service provided or on the personal data maintained therein, without undue delay and in any event within 24 hours of the incident;(g)take appropriate measures against forgery and forgery, theft or misappropriation of data;(h)record data or, without right, deleting, altering or rendering data inaccessible;(h)record and keep accessible for an appropriate period of time, including as long as necessary after the activities of the qualified trust service provider have ceased, all relevant information concerning data issued and received by the qualified trust service provider, in particular, for the purpose of providing evidence in legal proceedings and for the purpose of ensuring continuity of the service. Such recording may be done electronically;(i)have an up-to-date termination plan to ensure the continuity of service in accordance with provisions that are verified by the supervisory body under pursuant to Article 46b(4), point (i) of Article 17(4);(j)ensure (i);(j)ensure lawful processing of personal data in accordance with Directive 95/46/EC;(k)in case of qualified trust service providers issuing qualified certificates, establish and keep updated a certificate database.3.If database.The supervisory body may request information in addition to the information notified pursuant to point (a) of the first subparagraph or the result of a conformity assessment and may condition the granting of the permission to implement the intended changes to the qualified trust services. If the verification is not concluded within three months of notification, the supervisory body shall inform the trust service provider, specifying the reasons for the delay and the period within which the verification is to be concluded.3.If a qualified trust service provider issuing qualified certificates decides to revoke a certificate, it shall register such revocation in its certificate database and publish the revocation status of the certificate in a timely manner, and in any event within 24 hours after the receipt of the request. The revocation shall become effective immediately upon its publication.4.With regard to paragraph 3, qualified trust service providers issuing qualified certificates shall provide to any relying party information on the validity or revocation status of qualified certificates issued by them. This information shall be made available at least on a per certificate basis at any time and beyond the validity period of the certificate in an automated manner that is reliable, free of charge and efficient.5.The efficient.4a.Paragraphs 3 and 4 shall apply accordingly to the revocation of qualified electronic attestations of attributes.4b.The Commission may, shall be empowered to adopt delegated acts in accordance with Article 47, establishing additional measures referred to in paragraph 2, point (fa), of this Article.5.By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference numbers of standards and, where necessary, establish specifications and procedures for trustworthy systems and products, which comply with the requirements under points (e) and (f) of referred to in paragraph 2 of this Article. Compliance with the requirements laid down in this Article paragraph shall be presumed where trustworthy systems those standards, specifications and products meet those standards. procedures are met. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 24a — Recognition of qualified trust services · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
A new Article 24a has been added, stating that qualified electronic signatures, seals, certificates, creation devices, validation and preservation services, time stamps, website authentication certificates, registered delivery services, electronic attestations of attributes, archiving services, and electronic ledgers issued or provided in one Member State are to be recognised as such in all other Member States. Art. 24a, v2
text before / after
inserted text (02014R0910-20240520)
Article 24aRecognition of qualified trust services1.Qualified electronic signatures based on a qualified certificate issued in one Member State and qualified electronic seals based on a qualified certificate issued in one Member State shall be recognised, respectively, as qualified electronic signatures and qualified electronic seals in all other Member States.2.Qualified electronic signature creation devices and qualified electronic seal creation devices certified in one Member State shall be recognised, respectively, as qualified electronic signature creation devices and qualified electronic seal creation devices in all other Member States.3.A qualified certificate for electronic signatures, a qualified certificate for electronic seals, a qualified trust service for the management of remote qualified electronic signature creation devices and a qualified trust service for the management of remote qualified electronic seal creation devices provided in one Member State shall be recognised, respectively, as a qualified certificate for electronic signatures, a qualified certificate for electronic seals, a qualified trust service for the management of remote qualified electronic signature creation devices and a qualified trust service for the management of remote qualified electronic seal creation devices in all other Member States.4.A qualified validation service for qualified electronic signatures and a qualified validation service for qualified electronic seals provided in one Member State shall be recognised, respectively, as a qualified validation service for qualified electronic signatures and a qualified validation service for qualified electronic seals in all other Member States.5.A qualified preservation service for qualified electronic signatures and a qualified preservation service for qualified electronic seals provided in one Member State shall be recognised, respectively, as a qualified preservation service for qualified electronic signatures and a qualified preservation service for qualified electronic seals in all other Member States.6.A qualified electronic time stamp provided in one Member State shall be recognised as a qualified electronic time stamp in all other Member States.7.A qualified certificate for website authentication issued in one Member State shall be recognised as a qualified certificate for website authentication in all other Member States.8.A qualified electronic registered delivery service provided in one Member State shall be recognised as a qualified electronic registered delivery service in all other Member States.9.A qualified electronic attestation of attributes issued in one Member State shall be recognised as a qualified electronic attestation of attributes in all other Member States.10.A qualified electronic archiving service provided in one Member State shall be recognised as a qualified electronic archiving service in all other Member States.11.A qualified electronic ledger provided in one Member State shall be recognised as a qualified electronic ledger in all other Member States.
MODIFIED Art. 25 · applies from unknown
Disputed — seen by corpus metadata, the instruction parse, not by the structural diff.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED Art. 26 — Requirements for advanced electronic signatures · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
Disputed — seen by the structural diff, corpus metadata, not by the instruction parse.
The list of requirements for advanced electronic signatures is now numbered as paragraph 1, with the substantive text otherwise unchanged. Art. 26, v1 Art. 26, v2
A new paragraph 2 is added directing the Commission to assess by 21 May 2026 whether implementing acts establishing a list of reference standards and, where necessary, specifications and procedures are needed, allowing the Commission to adopt such acts on that basis, stating that compliance with those standards, specifications and procedures gives rise to a presumption of compliance with the requirements for advanced electronic signatures, and specifying that any such implementing acts follow the examination procedure referred to in Article 48(2). Art. 26, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 26Requirements for advanced electronic signaturesAn signatures1.An advanced electronic signature shall meet the following requirements:(a)it is uniquely linked to the signatory;(b)it is capable of identifying the signatory;(c)it is created using electronic signature creation data that the signatory can, with a high level of confidence, use under his sole control; and(d)it is linked to the data signed therewith in such a way that any subsequent change in the data is detectable. detectable.2.By 21 May 2026, the Commission shall assess whether it is necessary to adopt implementing acts to establish a list of reference standards and, where necessary, establish specifications and procedures for advanced electronic signatures. On the basis of that assessment, the Commission may adopt such implementing acts. Compliance with the requirements for advanced electronic signatures shall be presumed where an advanced electronic signature complies with the standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 27 · applies from unknown
Disputed — seen by corpus metadata, the instruction parse, not by the structural diff.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED Art. 28 — Qualified certificates for electronic signatures · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
Paragraph 6 now sets a deadline of 21 May 2025 for the Commission to act, whereas the earlier text stated no such deadline. Art. 28, v2
The Commission's task is expanded from establishing reference numbers of standards to establishing a list of reference standards and, where necessary, specifications and procedures for qualified certificates for electronic signature. Art. 28, v2 Art. 28, v1
The compliance-presumption sentence is correspondingly reworded to refer to compliance with standards, specifications and procedures rather than merely meeting those standards. Art. 28, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 28Qualified certificates for electronic signatures1.Qualified certificates for electronic signatures shall meet the requirements laid down in Annex I.2.Qualified certificates for electronic signatures shall not be subject to any mandatory requirement exceeding the requirements laid down in Annex I.3.Qualified certificates for electronic signatures may include non-mandatory additional specific attributes. Those attributes shall not affect the interoperability and recognition of qualified electronic signatures.4.If a qualified certificate for electronic signatures has been revoked after initial activation, it shall lose its validity from the moment of its revocation, and its status shall not in any circumstances be reverted.5.Subject to the following conditions, Member States may lay down national rules on temporary suspension of a qualified certificate for electronic signature:(a)if a qualified certificate for electronic signature has been temporarily suspended that certificate shall lose its validity for the period of suspension;(b)the period of suspension shall be clearly indicated in the certificate database and the suspension status shall be visible, during the period of suspension, from the service providing information on the status of the certificate.6.The certificate.6.By 21 May 2025, the Commission may, shall, by means of implementing acts, establish a list of reference numbers of standards and, where necessary, establish specifications and procedures for qualified certificates for electronic signature. Compliance with the requirements laid down in Annex I shall be presumed where a qualified certificate for electronic signature meets complies with those standards. standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 29 — Requirements for qualified electronic signature creation devices · applies from unchanged
A new paragraph 1a has been added stating that generating or managing electronic signature creation data, or duplicating such data for back-up purposes, is to be carried out only on behalf of the signatory, at the signatory's request, and by a qualified trust service provider that provides a qualified trust service for managing a remote qualified electronic signature creation device. Art. 29, v2
The remaining paragraphs, numbered 1 and 2, are unchanged in wording from the earlier version of the article. Art. 29, v1 Art. 29, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 29Requirements for qualified electronic signature creation devices1.Qualified electronic signature creation devices shall meet the requirements laid down in Annex II.2.The II.1a.Generating or managing electronic signature creation data or duplicating such signature creation data for back-up purposes shall be carried out only on behalf of the signatory, at the request of the signatory, and by a qualified trust service provider providing a qualified trust service for the management of a remote qualified electronic signature creation device.2.The Commission may, by means of implementing acts, establish reference numbers of standards for qualified electronic signature creation devices. Compliance with the requirements laid down in Annex II shall be presumed where a qualified electronic signature creation device meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 29a — Requirements for a qualified service for the management of remote qualified electronic signature creation devices · applies from unknown (an inserted provision states its own application date only in prose)
This new article sets out conditions that a qualified trust service provider must meet to offer the management of remote qualified electronic signature creation devices as a qualified service, including generating or managing signature creation data on behalf of the signatory, duplicating such data only for back-up purposes under stated security and quantity conditions, and complying with requirements identified in the relevant certification report. Art. 29a, v2
It also directs the Commission to adopt implementing acts by 21 May 2025 establishing a list of reference standards and, where necessary, specifications and procedures for these purposes, following the examination procedure referred to in the text. Art. 29a, v2
text before / after
inserted text (02014R0910-20240520)
Article 29aRequirements for a qualified service for the management of remote qualified electronic signature creation devices1.The management of remote qualified electronic signature creation devices as a qualified service shall be carried out only by a qualified trust service provider that:(a)generates or manages electronic signature creation data on behalf of the signatory;(b)notwithstanding point (1)(d) of Annex II, duplicates the electronic signature creation data for back-up purposes only, provided that the following requirements are met:(i)the security of the duplicated datasets must be at the same level as for the original datasets;(ii)the number of duplicated datasets must not exceed the minimum needed to ensure continuity of the service;(c)complies with any requirements identified in the certification report of the specific remote qualified electronic signature creation device issued pursuant to Article 30.2.By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, specifications and procedures for the purposes of paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 30 — Certification of qualified electronic signature creation devices · applies from unchanged
A new paragraph 3a has been added stating that the validity of a certification referred to in paragraph 1 shall not exceed five years, subject to vulnerability assessments being carried out every two years. Art. 30, v2
The added paragraph also states that where vulnerabilities are identified and not remedied, the certification shall be cancelled. Art. 30, v2
This paragraph 3a did not appear in the earlier version of Article 30. Art. 30, v1
text before / after
32014R0910 → 02014R0910-20240520
Article 30Certification of qualified electronic signature creation devices1.Conformity of qualified electronic signature creation devices with the requirements laid down in Annex II shall be certified by appropriate public or private bodies designated by Member States.2.Member States shall notify to the Commission the names and addresses of the public or private body referred to in paragraph 1. The Commission shall make that information available to Member States.3.The certification referred to in paragraph 1 shall be based on one of the following:(a)a security evaluation process carried out in accordance with one of the standards for the security assessment of information technology products included in the list established in accordance with the second subparagraph; or(b)a process other than the process referred to in point (a), provided that it uses comparable security levels and provided that the public or private body referred to in paragraph 1 notifies that process to the Commission. That process may be used only in the absence of standards referred to in point (a) or when a security evaluation process referred to in point (a) is ongoing.The Commission shall, by means of implementing acts, establish a list of standards for the security assessment of information technology products referred to in point (a). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).4.The 48(2).3aThe validity of a certification referred to in paragraph 1 shall not exceed five years, provided that vulnerabilities assessments are carried out every two years. Where vulnerabilities are identified and not remedied, the certification shall be cancelled.4.The Commission shall be empowered to adopt delegated acts in accordance with Article 47 concerning the establishment of specific criteria to be met by the designated bodies referred to in paragraph 1 of this Article.
MODIFIED Art. 31 — Publication of a list of certified qualified electronic signature creation devices · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
The provision changes from an optional power for the Commission to define formats and procedures for paragraph 1 to a requirement that the Commission establish those formats and procedures by a stated deadline of 21 May 2025. Art. 31, v1 Art. 31, v2
The wording also changes from referring to defining formats and procedures generally to establishing the formats and procedures applicable for the purpose of paragraph 1 of this Article. Art. 31, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 31Publication of a list of certified qualified electronic signature creation devices1.Member States shall notify to the Commission without undue delay and no later than one month after the certification is concluded, information on qualified electronic signature creation devices that have been certified by the bodies referred to in Article 30(1). They shall also notify to the Commission, without undue delay and no later than one month after the certification is cancelled, information on electronic signature creation devices that are no longer certified.2.On the basis of the information received, the Commission shall establish, publish and maintain a list of certified qualified electronic signature creation devices.3.The devices.3.By 21 May 2025, the Commission may, shall, by means of implementing acts, define establish the formats and procedures applicable for the purpose of paragraph 1. 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 32 — Requirements for the validation of qualified electronic signatures · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
The list of conditions in paragraph 1 now includes an added sentence stating that compliance with those requirements is presumed where validation complies with the standards, specifications and procedures referred to in paragraph 3, whereas the earlier text placed that presumption in paragraph 3 itself and tied it to reference numbers of standards. Art. 32, v1 Art. 32, v2
Paragraph 3 now requires the Commission, by 21 May 2025, to establish by implementing acts a list of reference standards and, where necessary, specifications and procedures for validation, replacing the earlier wording that only allowed the Commission to establish reference numbers of standards without a deadline. Art. 32, v1 Art. 32, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 32Requirements for the validation of qualified electronic signatures1.The process for the validation of a qualified electronic signature shall confirm the validity of a qualified electronic signature provided that:(a)the certificate that supports the signature was, at the time of signing, a qualified certificate for electronic signature complying with Annex I;(b)the qualified certificate was issued by a qualified trust service provider and was valid at the time of signing;(c)the signature validation data corresponds to the data provided to the relying party;(d)the unique set of data representing the signatory in the certificate is correctly provided to the relying party;(e)the use of any pseudonym is clearly indicated to the relying party if a pseudonym was used at the time of signing;(f)the electronic signature was created by a qualified electronic signature creation device;(g)the integrity of the signed data has not been compromised;(h)the requirements provided for in Article 26 were met at the time of signing.2.The signing.Compliance with the requirements laid down in the first subparagraph of this paragraph shall be presumed where the validation of qualified electronic signatures complies with the standards, specifications and procedures referred to in paragraph 3.2.The system used for validating the qualified electronic signature shall provide to the relying party the correct result of the validation process and shall allow the relying party to detect any security relevant issues.3.The issues.3.By 21 May 2025, the Commission may, shall, by means of implementing acts, establish a list of reference numbers of standards and, where necessary, establish specifications and procedures for the validation of qualified electronic signatures. Compliance with the requirements laid down in paragraph 1 shall be presumed where the validation of qualified electronic signatures meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 32a — Requirements for the validation of advanced electronic signatures based on qualified certificates · applies from unknown (an inserted provision states its own application date only in prose)
A new Article 32a sets out conditions that must be met for the validation process to confirm the validity of an advanced electronic signature based on a qualified certificate, covering matters such as the certificate's qualification status, the identity of the qualified trust service provider, correspondence of validation data, disclosure of pseudonym use, and integrity of the signed data. Art. 32a, v2
It also requires the validation system to give the relying party the correct result and to allow detection of security relevant issues, and it directs the Commission to establish, by way of implementing acts, a list of reference standards and any necessary specifications and procedures for such validation. Art. 32a, v2
By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the validation of advanced electronic signatures based on qualified certificates. Art. 32a, v2
text before / after
inserted text (02014R0910-20240520)
Article 32aRequirements for the validation of advanced electronic signatures based on qualified certificates1.The process for the validation of an advanced electronic signature based on a qualified certificate shall confirm the validity of an advanced electronic signature based on a qualified certificate, provided that:(a)the certificate that supports the signature was, at the time of signing, a qualified certificate for electronic signature complying with Annex I;(b)the qualified certificate was issued by a qualified trust service provider and was valid at the time of signing;(c)the signature validation data corresponds to the data provided to the relying party;(d)the unique set of data representing the signatory in the certificate is correctly provided to the relying party;(e)the use of any pseudonym is clearly indicated to the relying party if a pseudonym was used at the time of signing;(f)the integrity of the signed data has not been compromised;(g)the requirements provided for in Article 26 were met at the time of signing.2.The system used for validating the advanced electronic signature based on qualified certificate shall provide to the relying party the correct result of the validation process and shall allow the relying party to detect any security relevant issues.3.By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the validation of advanced electronic signatures based on qualified certificates. Compliance with the requirements laid down in paragraph 1 of this Article shall be presumed where the validation of advanced electronic signature based on qualified certificates complies with those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 33 — Qualified validation service for qualified electronic signatures · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
The provision changes the Commission's implementing act mandate from a discretionary power to establish reference numbers of standards into an obligation to establish, by a stated deadline, a list of reference standards and, where necessary, specifications and procedures for the qualified validation service. Art. 33, v1 Art. 33, v2
The compliance presumption is reworded so that it now applies where the qualified validation service complies with those standards, specifications and procedures, rather than where the validation service meets standards referenced by number. Art. 33, v1 Art. 33, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 33Qualified validation service for qualified electronic signatures1.A qualified validation service for qualified electronic signatures may only be provided by a qualified trust service provider who:(a)provides validation in compliance with Article 32(1); and(b)allows relying parties to receive the result of the validation process in an automated manner, which is reliable, efficient and bears the advanced electronic signature or advanced electronic seal of the provider of the qualified validation service.2.The service.2.By 21 May 2025, the Commission may, shall, by means of implementing acts, establish a list of reference numbers of standards and, where necessary, establish specifications and procedures for qualified validation service referred to in paragraph 1. 1 of this Article. Compliance with the requirements laid down in paragraph 1 of this Article shall be presumed where the qualified validation service for a qualified electronic signature meets signatures complies with those standards. standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 34 — Qualified preservation service for qualified electronic signatures · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
A new paragraph 1a has been added stating that compliance with paragraph 1's requirements is presumed where the preservation arrangements comply with the standards, specifications and procedures referred to in paragraph 2, moving this presumption out of paragraph 2 where it previously appeared. Art. 34, v2 Art. 34, v1
Paragraph 2 now requires the Commission, by 21 May 2025, to establish by implementing acts a list of reference standards and, where necessary, specifications and procedures, replacing the earlier wording that merely allowed the Commission to establish reference numbers of standards without a deadline. Art. 34, v2 Art. 34, v1
text before / after
32014R0910 → 02014R0910-20240520
Article 34Qualified preservation service for qualified electronic signatures1.A qualified preservation service for qualified electronic signatures may only be provided by a qualified trust service provider that uses procedures and technologies capable of extending the trustworthiness of the qualified electronic signature beyond the technological validity period.2.The Commission may, by means of implementing acts, establish reference numbers of standards for the qualified preservation service for qualified electronic signatures. Compliance period.1a.Compliance with the requirements laid down in paragraph 1 shall be presumed where the arrangements for the qualified preservation service for qualified electronic signatures meet those standards. complies with the standards, specifications and procedures referred to in paragraph 2.2.By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the qualified preservation service for qualified electronic signatures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 35 · applies from unknown
Disputed — seen by corpus metadata, the instruction parse, not by the structural diff.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED Art. 36 — Requirements for advanced electronic seals · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
The original list of requirements for advanced electronic seals is now numbered as paragraph 1, with its content otherwise unchanged. Art. 36, v1 Art. 36, v2
A new paragraph 2 has been added directing the Commission to assess by 21 May 2026 whether implementing acts establishing reference standards, specifications and procedures for advanced electronic seals are necessary, allowing the Commission to adopt such acts on that basis, providing that compliance with those standards, specifications and procedures gives rise to a presumption of compliance with the seal requirements, and specifying that any such implementing acts follow the examination procedure in Article 48(2). Art. 36, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 36Requirements for advanced electronic sealsAn seals1.An advanced electronic seal shall meet the following requirements:(a)it is uniquely linked to the creator of the seal;(b)it is capable of identifying the creator of the seal;(c)it is created using electronic seal creation data that the creator of the seal can, with a high level of confidence under its control, use for electronic seal creation; and(d)it is linked to the data to which it relates in such a way that any subsequent change in the data is detectable. detectable.2.By 21 May 2026, the Commission shall assess whether it is necessary to adopt implementing acts to establish a list of reference standards and, where necessary, establish specifications and procedures for advanced electronic seals. On the basis of that assessment, the Commission may adopt such implementing acts. Compliance with the requirements for advanced electronic seals shall be presumed where an advanced electronic seal complies with those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 37 · applies from unknown
Disputed — seen by corpus metadata, the instruction parse, not by the structural diff.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED Art. 38 — Qualified certificates for electronic seals · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
Paragraph 6 now sets a deadline of 21 May 2025 by which the Commission is to act, whereas the earlier text stated no such date. Art. 38, v2
The task itself is reworded from establishing reference numbers of standards to establishing a list of reference standards and, where necessary, specifications and procedures. Art. 38, v1 Art. 38, v2
The compliance presumption is correspondingly rephrased from meeting those standards to complying with those standards, specifications and procedures. Art. 38, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 38Qualified certificates for electronic seals1.Qualified certificates for electronic seals shall meet the requirements laid down in Annex III.2.Qualified certificates for electronic seals shall not be subject to any mandatory requirements exceeding the requirements laid down in Annex III.3.Qualified certificates for electronic seals may include non-mandatory additional specific attributes. Those attributes shall not affect the interoperability and recognition of qualified electronic seals.4.If a qualified certificate for an electronic seal has been revoked after initial activation, it shall lose its validity from the moment of its revocation, and its status shall not in any circumstances be reverted.5.Subject to the following conditions, Member States may lay down national rules on temporary suspension of qualified certificates for electronic seals:(a)if a qualified certificate for electronic seal has been temporarily suspended, that certificate shall lose its validity for the period of suspension;(b)the period of suspension shall be clearly indicated in the certificate database and the suspension status shall be visible, during the period of suspension, from the service providing information on the status of the certificate.6.The certificate.6.By 21 May 2025, the Commission may, shall, by means of implementing acts, establish a list of reference numbers of standards and, where necessary, establish specifications and procedures for qualified certificates for electronic seals. Compliance with the requirements laid down in Annex III shall be presumed where a qualified certificate for electronic seal meets complies with those standards. standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 39a — Requirements for a qualified service for the management of remote qualified electronic seal creation devices · applies from unknown (an inserted provision states its own application date only in prose)
This new provision applies Article 29a mutatis mutandis to a qualified service for the management of remote qualified electronic seal creation devices. Art. 39a, v2
text before / after
inserted text (02014R0910-20240520)
Article 39aRequirements for a qualified service for the management of remote qualified electronic seal creation devicesArticle 29a shall apply mutatis mutandis to a qualified service for the management of remote qualified electronic seal creation devices.
INSERTED Art. 40a — Requirements for the validation of advanced electronic seals based on qualified certificates · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This new Article 40a states that Article 32a is to apply mutatis mutandis to the validation of advanced electronic seals based on qualified certificates. Art. 40a, v2
text before / after
inserted text (02014R0910-20240520)
Article 40aRequirements for the validation of advanced electronic seals based on qualified certificatesArticle 32a shall apply mutatis mutandis to the validation of advanced electronic seals based on qualified certificates.
MODIFIED Art. 41 · applies from unknown
Disputed — seen by corpus metadata, the instruction parse, not by the structural diff.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED Art. 42 — Requirements for qualified electronic time stamps · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
A new paragraph 1a now states the presumption of compliance with paragraph 1, tying it to standards, specifications and procedures referred to in paragraph 2, whereas that presumption language previously sat within paragraph 2 itself. Art. 42, v1 Art. 42, v2
Paragraph 2 now sets a deadline of 21 May 2025 for the Commission to establish, by implementing acts, a list of reference standards and, where necessary, specifications and procedures for binding date and time to data and for establishing the accuracy of time sources, replacing the earlier wording that allowed the Commission to establish reference numbers of standards for binding date and time and for accurate time sources without a stated deadline. Art. 42, v1 Art. 42, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 42Requirements for qualified electronic time stamps1.A qualified electronic time stamp shall meet the following requirements:(a)it binds the date and time to data in such a manner as to reasonably preclude the possibility of the data being changed undetectably;(b)it is based on an accurate time source linked to Coordinated Universal Time; and(c)it is signed using an advanced electronic signature or sealed with an advanced electronic seal of the qualified trust service provider, or by some equivalent method.2.The Commission may, by means of implementing acts, establish reference numbers of standards for the binding of date and time to data and for accurate time sources. Compliance method.1a.Compliance with the requirements laid down in paragraph 1 shall be presumed where the binding of date and time to data and the accurate accuracy of the time source meets those standards. comply with the standards, specifications and procedures referred to in paragraph 2.2.By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the binding of date and time to data and for establishing the accuracy of time sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 44 — Requirements for qualified electronic registered delivery services · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
A new paragraph 1a states that compliance with the paragraph 1 requirements is presumed where the sending and receiving process complies with the standards, specifications and procedures referred to in paragraph 2, replacing the prior presumption wording tied directly to Commission-established standards. Art. 44, v1
Paragraph 2 now sets a deadline of 21 May 2025 for the Commission to establish, by implementing acts, a list of reference standards and, where necessary, specifications and procedures, rather than simply establishing reference numbers of standards without a deadline. Art. 44, v1
Two new paragraphs, 2a and 2b, are added: 2a allows providers of qualified electronic registered delivery services to agree on interoperability between the services they provide, with compliance to be confirmed by a conformity assessment body, and 2b allows the Commission to establish by implementing acts a list of reference standards and, where necessary, specifications and procedures for that interoperability framework, with a requirement that technical specifications and content of standards be cost-effective and proportionate. Art. 44, v1
text before / after
32014R0910 → 02014R0910-20240520
Article 44Requirements for qualified electronic registered delivery services1.Qualified electronic registered delivery services shall meet the following requirements:(a)they are provided by one or more qualified trust service provider(s);(b)they ensure with a high level of confidence the identification of the sender;(c)they ensure the identification of the addressee before the delivery of the data;(d)the sending and receiving of data is secured by an advanced electronic signature or an advanced electronic seal of a qualified trust service provider in such a manner as to preclude the possibility of the data being changed undetectably;(e)any change of the data needed for the purpose of sending or receiving the data is clearly indicated to the sender and addressee of the data;(f)the date and time of sending, receiving and any change of data are indicated by a qualified electronic time stamp.In the event of the data being transferred between two or more qualified trust service providers, the requirements in points (a) to (f) shall apply to all the qualified trust service providers.2.The Commission may, by means of implementing acts, establish reference numbers of standards for processes for sending and receiving data. Compliance providers.1a.Compliance with the requirements laid down in paragraph 1 shall be presumed where the process for sending and receiving data meets those standards. complies with the standards, specifications and procedures referred to in paragraph 2.2.By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for processes for sending and receiving data. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).2a.Providers of qualified electronic registered delivery services may agree on interoperability between qualified electronic registered delivery services which they provide. Such interoperability framework shall comply with the requirements laid down in paragraph 1 and such compliance shall be confirmed by a conformity assessment body.2b.The Commission may, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the interoperability framework referred to in paragraph 2a of this Article. The technical specifications and content of standards shall be cost-effective and proportionate. The implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 45 — Requirements for qualified certificates for website authentication · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
The provision now adds that compliance evaluation for qualified certificates for website authentication is to be carried out according to standards, specifications and procedures referred to in paragraph 2, and it introduces new paragraphs requiring web-browser providers to recognise such certificates, display identity data and additional attested attributes in a user-friendly manner, and ensure support and interoperability, with an exception for microenterprises and small enterprises during their first five years of operating web-browsing services. Art. 45, v2
A new paragraph states that qualified certificates for website authentication are not subject to any mandatory requirements other than those in paragraph 1, and paragraph 2 is changed from allowing the Commission to establish reference numbers of standards to requiring it, by 21 May 2025, to establish a list of reference standards and, where necessary, specifications and procedures. Art. 45, v1 Art. 45, v2
text before / after
texts differ too much for an inline diff; shown separately
before (32014R0910)
Article 45Requirements for qualified certificates for website authentication1.Qualified certificates for website authentication shall meet the requirements laid down in Annex IV.2.The Commission may, by means of implementing acts, establish reference numbers of standards for qualified certificates for website authentication. Compliance with the requirements laid down in Annex IV shall be presumed where a qualified certificate for website authentication meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
after (02014R0910-20240520)
Article 45Requirements for qualified certificates for website authentication1.Qualified certificates for website authentication shall meet the requirements laid down in Annex IV. The evaluation of compliance with those requirements shall be carried out in accordance with the standards, specifications and procedures referred to in paragraph 2 of this Article.1a.Qualified certificates for website authentication issued in accordance with paragraph 1 of this Article shall be recognised by providers of web-browsers. Providers of web-browsers shall ensure that the identity data attested in the certificate and additional attested attributes are displayed in a user-friendly manner. Providers of web-browsers shall ensure support and interoperability with qualified certificates for website authentication referred to in paragraph 1 of this Article, with the exception of microenterprises or small enterprises as defined in Article 2 of the Annex to Recommendation 2003/361/EC during the first five years of operating as providers of web-browsing services.1b.Qualified certificates for website authentication shall not be subject to any mandatory requirements other than the requirements laid down in paragraph 1.2.By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for qualified certificates for website authentication, referred to in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 45a — Cybersecurity precautionary measures · applies from unknown (an inserted provision states its own application date only in prose)
A new Article 45a is added, setting out obligations for providers of web-browsers regarding qualified certificates for website authentication, including a general duty not to act contrary to Article 45 and a limited derogation allowing precautionary measures only where there are substantiated concerns about security breaches or loss of integrity of a certificate. Art. 45a, v2
The new provision also describes notification duties toward the Commission, the competent supervisory body, the certificate holder and the issuing qualified trust service provider when such precautionary measures are taken, and describes the supervisory body's role in investigating the notified concerns and in requesting an end to the measures if the qualified status of the certificate is not withdrawn. Art. 45a, v2
text before / after
inserted text (02014R0910-20240520)
Article 45aCybersecurity precautionary measures1.Providers of web-browsers shall not take any measures contrary to their obligations set out in Article 45, in particular the requirements to recognise qualified certificates for website authentication and to display the identity data provided in a user-friendly manner.2.By way of derogation from paragraph 1 and only in the event of substantiated concerns related to security breaches or the loss of integrity of an identified certificate or set of certificates, providers of web-browsers may take precautionary measures in relation to that certificate or set of certificates.3.Where a provider of a web-browser takes precautionary measures pursuant to paragraph 2, the provider of the web-browser shall notify its concerns in writing, without undue delay, together with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory body, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory body shall issue an acknowledgement of receipt to the provider of the web-browser in question.4.The competent supervisory body shall investigate the issues raised in the notification in accordance with Article 46b(4), point (k). Where the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate, the supervisory body shall inform the provider of the web-browser accordingly and shall request that provider to put an end to the precautionary measures referred to in paragraph 2 of this Article.
INSERTED Art. 45b — Legal effects of electronic attestation of attributes · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This is a new provision establishing that an electronic attestation of attributes cannot be denied legal effect or admissibility as evidence purely because it is electronic or because it fails to meet the requirements for qualified electronic attestations of attributes. Art. 45b, v2
It further states that a qualified electronic attestation of attributes, and attestations issued by or on behalf of a public sector body responsible for an authentic source, have the same legal effect as lawfully issued paper attestations, and that such attestations issued in one Member State are to be recognised as such in all Member States. Art. 45b, v2
text before / after
inserted text (02014R0910-20240520)
Article 45bLegal effects of electronic attestation of attributes1.An electronic attestation of attributes shall not be denied legal effect or admissibility as evidence in legal proceedings on the sole ground that it is in electronic form or that it does not meet the requirements for qualified electronic attestations of attributes.2.A qualified electronic attestation of attributes and attestations of attributes issued by, or on behalf of, a public sector body responsible for an authentic source shall have the same legal effect as lawfully issued attestations in paper form.3.An attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source in one Member State shall be recognised as an attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source in all Member States.
INSERTED Art. 45c — Electronic attestation of attributes in public services · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
Article 45c is a new provision stating that where national law requires electronic identification and authentication to access an online service from a public sector body, person identification data in an electronic attestation of attributes cannot be used in place of that electronic identification and authentication unless a Member State specifically allows it. Art. 45c, v2
It further states that where such use is allowed, qualified electronic attestations of attributes issued from other Member States are also to be accepted. Art. 45c, v2
text before / after
inserted text (02014R0910-20240520)
Article 45cElectronic attestation of attributes in public servicesWhere an electronic identification using an electronic identification means and authentication is required under national law to access an online service provided by a public sector body, person identification data in the electronic attestation of attributes shall not substitute electronic identification using an electronic identification means and authentication for electronic identification unless specifically allowed by the Member State. In such a case, qualified electronic attestation of attributes from other Member States shall also be accepted.
INSERTED Art. 45d — Requirements for qualified electronic attestation of attributes · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This new article sets out requirements for qualified electronic attestation of attributes, stating that such attestations must meet the requirements in Annex V and that compliance with those requirements is to be evaluated under standards, specifications and procedures the Commission is to establish. Art. 45d, v2
It further provides that no additional mandatory requirements may be imposed beyond Annex V, that a revoked attestation loses validity from the moment of revocation and cannot have its status reverted, and that the Commission is to adopt implementing acts on reference standards, specifications and procedures by 21 November 2024, consistent with the implementing acts on the European Digital Identity Wallet and following the examination procedure. Art. 45d, v2
text before / after
inserted text (02014R0910-20240520)
Article 45dRequirements for qualified electronic attestation of attributes1.Qualified electronic attestation of attributes shall meet the requirements laid down in Annex V.2.The evaluation of compliance with the requirements laid down in Annex V shall be carried out in accordance with the standards, specifications and procedures referred to in paragraph 5 of this Article.3.Qualified electronic attestations of attributes shall not be subject to any mandatory requirement in addition to the requirements laid down in Annex V.4.Where a qualified electronic attestation of attributes has been revoked after initial issuance, it shall lose its validity from the moment of its revocation and its status shall not in any circumstances be reverted.5.By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for qualified electronic attestations of attributes. Those implementing acts shall be consistent with the implementing acts referred to in Article 5a(23) on the implementation of the European Digital Identity Wallet. They shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 45e — Verification of attributes against authentic sources · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
Article 45e is a newly added provision requiring Member States to ensure, within 24 months of the entry into force of the implementing acts referenced in Articles 5a(23) and 5c(6), that measures allow qualified trust service providers of electronic attestations of attributes to verify certain attributes listed in Annex VI against authentic public-sector sources at a user's request. Art. 45e, v2
It also sets out that, by 21 November 2024, the Commission is to adopt implementing acts establishing reference standards and, where necessary, specifications and procedures for the attribute catalogue, attestation schemes, and verification procedures, consistent with the implementing acts on the European Digital Identity Wallet under Article 5a(23) and adopted under the examination procedure of Article 48(2). Art. 45e, v2
text before / after
inserted text (02014R0910-20240520)
Article 45eVerification of attributes against authentic sources1.Member States shall ensure, within 24 months of the date of entry into force of the implementing acts referred to in Articles 5a(23) and 5c(6), that, at least for the attributes listed in Annex VI, wherever those attributes rely on authentic sources within the public sector, measures are taken to allow qualified trust service providers of electronic attestations of attributes to verify those attributes by electronic means at the request of the user, in accordance with Union or national law.2.By 21 November 2024, the Commission shall, taking into account relevant international standards, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the catalogue of attributes, as well as schemes for the attestation of attributes and verification procedures for qualified electronic attestations of attributes for the purposes of paragraph 1 of this Article. Those implementing acts shall be consistent with the implementing acts referred to in Article 5a(23) on the implementation of the European Digital Identity Wallet. They shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 45f — Requirements for electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
A new Article 45f sets out requirements for electronic attestations of attributes issued by or on behalf of a public sector body responsible for an authentic source, including conformity with Annex VII, qualified certificate requirements, and Member State obligations on reliability and notification. Art. 45f, v2
The provision also addresses revocation of such attestations, compliance through Commission-established standards and specifications, and a requirement that issuing public sector bodies provide an interface with European Digital Identity Wallets. Art. 45f, v2
text before / after
inserted text (02014R0910-20240520)
Article 45fRequirements for electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source1.An electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source shall meet the following requirements:(a)those set out in Annex VII;(b)the qualified certificate supporting the qualified electronic signature or qualified electronic seal of the public sector body referred to in Article 3, point (46), identified as the issuer referred to in point (b), of Annex VII, containing a specific set of certified attributes in a form suitable for automated processing and:(i)indicating that the issuing body is established in accordance with Union or national law as the responsible for the authentic source on the basis of which the electronic attestation of attributes is issued or as the body designated to act on its behalf;(ii)providing a set of data unambiguously representing the authentic source referred to in point (i); and(iii)identifying the Union or national law referred to in point (i).2.The Member State where public sector bodies referred to in Article 3, point (46), are established shall ensure that the public sector bodies that issue electronic attestations of attributes meet a level of reliability and trustworthiness equivalent to qualified trust service providers in accordance with Article 24.3.Member States shall notify public sector bodies referred to in Article 3, point (46), to the Commission. That notification shall include a conformity assessment report issued by a conformity assessment body confirming that the requirements set out in paragraphs 1, 2 and 6 of this Article are met. The Commission shall make available to the public, through a secure channel, the list of public sector bodies referred to in Article 3, point (46), in electronically signed or sealed form suitable for automated processing.4.Where an electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source has been revoked after initial issuance, it shall lose its validity from the moment of its revocation and its status shall not be reverted.5.An electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source shall be deemed to be compliant with the requirements laid down in paragraph 1, where it complies with the standards, specifications and procedures referred to in paragraph 6.6.By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source. Those implementing acts shall be consistent with the implementing acts referred to in Article 5a(23) on the implementation of the European Digital Identity Wallet. They shall be adopted in accordance with the examination procedure referred to in Article 48(2).7.By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the purposes of paragraph 3 of this Article. Those implementing acts shall be consistent with the implementing acts referred to in Article 5a(23) on the implementation of the European Digital Identity Wallet. They shall be adopted in accordance with the examination procedure referred to in Article 48(2).8.Public sector bodies referred to in Article 3, point (46), issuing electronic attestation of attributes shall provide an interface with European Digital Identity Wallets that are provided in accordance with Article 5a.
INSERTED Art. 45g — Issuing of electronic attestation of attributes to European Digital Identity Wallets · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This new provision requires providers of electronic attestations of attributes to let European Digital Identity Wallet users request, obtain, store and manage such attestations regardless of the Member State that provides the wallet. Art. 45g, v2
It further requires providers of qualified electronic attestations of attributes to provide an interface with European Digital Identity Wallets provided in accordance with Article 5a. Art. 45g, v2
text before / after
inserted text (02014R0910-20240520)
Article 45gIssuing of electronic attestation of attributes to European Digital Identity Wallets1.Providers of electronic attestations of attributes shall provide European Digital Identity Wallet users with the possibility to request, obtain, store and manage the electronic attestation of attributes irrespective of the Member State where the European Digital Identity Wallet is provided.2.Providers of qualified electronic attestations of attributes shall provide an interface with European Digital Identity Wallets that are provided in accordance in Article 5a.
INSERTED Art. 45h — Additional rules for the provision of electronic attestation of attributes services · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This is a new Article 45h, setting out three separate rules for providers of electronic attestation of attributes services: a prohibition on combining personal data from those services with personal data from other services offered by them or their commercial partners, a requirement to keep such personal data logically separate from other data held by the provider, and a requirement for providers of qualified electronic attestation of attributes services to provide that trust service in a manner functionally separate from their other services. Art. 45h, v2
text before / after
inserted text (02014R0910-20240520)
Article 45hAdditional rules for the provision of electronic attestation of attributes services1.Providers of qualified and non-qualified electronic attestation of attributes services shall not combine personal data relating to the provision of those services with personal data from any other services offered by them or their commercial partners.2.Personal data relating to the provision of electronic attestation of attributes services shall be kept logically separate from other data held by the provider of electronic attestation of attributes.3.Providers of qualified electronic attestation of attributes’ services shall implement the provision of such qualified trust services in a manner that is functionally separate from other services provided by them.
INSERTED Art. 45i — Legal effect of electronic archiving services · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
A new Article 45i has been added, providing that electronic data and electronic documents preserved through an electronic archiving service cannot be denied legal effect or admissibility as evidence in legal proceedings solely because they are electronic or because the archiving service used is not a qualified one. Art. 45i, v2
The new article also states that electronic data and electronic documents preserved using a qualified electronic archiving service enjoy a presumption of integrity and of origin for the duration of the preservation period maintained by the qualified trust service provider. Art. 45i, v2
text before / after
inserted text (02014R0910-20240520)
Article 45iLegal effect of electronic archiving services1.Electronic data and electronic documents preserved using an electronic archiving service shall not be denied legal effect or admissibility as evidence in legal proceedings on the sole ground that they are in electronic form or that they are not preserved using a qualified electronic archiving service.2.Electronic data and electronic documents preserved using a qualified electronic archiving service shall enjoy the presumption of their integrity and of their origin for the duration of the preservation period by the qualified trust service provider.
INSERTED Art. 45j — Requirements for qualified electronic archiving services · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
Article 45j is a new provision setting out requirements that qualified electronic archiving services must meet, including that they be provided by qualified trust service providers, that they use procedures and technologies preserving durability, legibility, integrity and origin accuracy of electronic data and documents, that they safeguard against loss and alteration except for medium or format changes, and that they allow authorised relying parties to obtain an automated report on the presumption of integrity, signed or sealed by the provider. Art. 45j, v2
It also newly provides for the Commission to adopt implementing acts establishing a list of reference standards and, where necessary, specifications and procedures for such services, with compliance with those standards, specifications and procedures giving rise to a presumption of compliance with the requirements, following the examination procedure referred to in Article 48(2). Art. 45j, v2
text before / after
inserted text (02014R0910-20240520)
Article 45jRequirements for qualified electronic archiving services1.Qualified electronic archive services shall meet the following requirements:(a)they are provided by qualified trust service providers;(b)they use procedures and technologies capable of ensuring the durability and legibility of electronic data and electronic documents beyond the technological validity period and at least throughout the legal or contractual preservation period, while maintaining their integrity and the accuracy of their origin;(c)they ensure that those electronic data and those electronic documents are preserved in such a way that they are safeguarded against loss and alteration, except for changes concerning their medium or electronic format;(d)they shall allow authorised relying parties to receive a report in an automated manner that confirms that electronic data and electronic documents retrieved from a qualified electronic archive enjoy the presumption of integrity of the data from the beginning of the preservation period to the moment of retrieval.The report referred to in point (d) of the first subparagraph shall be provided in a reliable and efficient way and shall bear the qualified electronic signature or qualified electronic seal of the provider of the qualified electronic archiving service.2.By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for qualified electronic archiving services. Compliance with the requirements for qualified electronic archive services shall be presumed where a qualified electronic archive service complies with those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 45k — Legal effects of electronic ledgers · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This is a new provision establishing that an electronic ledger cannot be denied legal effect or admissibility as evidence in legal proceedings merely because it is electronic or does not meet the requirements for qualified electronic ledgers. Art. 45k, v2
It also states that data records held in a qualified electronic ledger benefit from a presumption of unique and accurate sequential chronological ordering and of integrity. Art. 45k, v2
text before / after
inserted text (02014R0910-20240520)
Article 45kLegal effects of electronic ledgers1.An electronic ledger shall not be denied legal effect or admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements for qualified electronic ledgers.2.Data records contained in a qualified electronic ledger shall enjoy the presumption of their unique and accurate sequential chronological ordering and of their integrity.
INSERTED Art. 45l — Requirements for qualified electronic ledgers · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This new provision sets out requirements that qualified electronic ledgers must meet, including creation and management by one or more qualified trust service providers, establishment of the origin of data records, unique sequential chronological ordering of records, and detectability of any subsequent change to the data. Art. 45l, v2
It also provides that compliance is presumed where a ledger meets standards, specifications and procedures the Commission is to establish by implementing acts, following the examination procedure referred to in Article 48(2). Art. 45l, v2
text before / after
inserted text (02014R0910-20240520)
Article 45lRequirements for qualified electronic ledgers1.Qualified electronic ledgers shall meet the following requirements:(a)they are created and managed by one or more qualified trust service providers;(b)they establish the origin of data records in the ledger;(c)they ensure the unique sequential chronological ordering of data records in the ledger;(d)they record data in such a way that any subsequent change to the data is immediately detectable, ensuring their integrity over time.2.Compliance with the requirements laid down in paragraph 1 shall be presumed where an electronic ledger complies with the standards, specifications and procedures referred to in paragraph 3.3.By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the requirements laid down in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 46a — Supervision of the European Digital Identity Wallet Framework · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
A new Article 46a is added, requiring Member States to designate one or more supervisory bodies for the European Digital Identity Wallet Framework and setting out their notification duties, roles, tasks, and powers to require remedial action or suspension of a wallet provider. Art. 46a, v2
The article also sets an annual reporting cycle for supervisory bodies, with reports due to the Commission by 31 March each year, and directs the Commission to adopt implementing acts on report formats and procedures. Art. 46a, v2
text before / after
inserted text (02014R0910-20240520)
Article 46aSupervision of the European Digital Identity Wallet Framework1.Member States shall designate one or more supervisory bodies established in their territory.The supervisory bodies designated pursuant to the first subparagraph shall be given the necessary powers and adequate resources for the exercise of their tasks in an effective, efficient and independent manner.2.Member States shall notify to the Commission the names and the addresses of their supervisory bodies designated pursuant to paragraph 1 and any subsequent changes thereto. The Commission shall publish a list of the notified supervisory bodies.3.The role of the supervisory bodies designated pursuant to paragraph 1 shall be:(a)to supervise providers of European Digital Identity Wallets established in the designating Member State and to ensure, by means of ex ante and ex post supervisory activities, that those providers and European Digital Identity Wallets they provide meet the requirements laid down in this Regulation;(b)to take action, if necessary, in relation to providers of European Digital Identity Wallets established in the territory of the designating Member State, by means of ex post supervisory activities, when informed that providers or European Digital Identity Wallets that they provide infringe this Regulation.4.The tasks of the supervisory bodies designated pursuant to paragraph 1 shall include, in particular, the following:(a)to cooperate with other supervisory bodies and to provide them with assistance in accordance with Articles 46c and 46e;(b)to request information necessary to monitor compliance with this Regulation;(c)to inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant security breaches or loss of integrity of which they become aware in the performance of their tasks and, in the case of a significant security breach or loss of integrity which concerns other Member States, to inform the single point of contact designated or established pursuant to Article 8(3) of Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of this Regulation in the other Member States concerned, and to inform the public or require providers of European Digital Identity Wallet to do so where the supervisory body determines that disclosure of the security breach or of the loss of integrity would be in the public interest;(d)to carry out on-site inspections and off-site supervision;(e)to require that providers of European Digital Identity Wallets remedy any failure to fulfil the requirements laid down in this Regulation;(f)to suspend or cancel the registration and inclusion of relying parties in the mechanism referred to in Article 5b(7) in the case of illegal or fraudulent use of the European Digital Identity Wallet;(g)to cooperate with competent supervisory authorities established pursuant to Article 51 of Regulation (EU) 2016/679, in particular, by informing them without undue delay, where personal data protection rules appear to have been infringed and about security breaches which appear to constitute personal data breaches.5.Where the supervisory body designated pursuant to paragraph 1 requires the provider of a European Digital Identity Wallet to remedy any failure to fulfil requirements under this Regulation pursuant to paragraph 4, point (e), and that provider does not act accordingly and, if applicable, within a time limit set by that supervisory body, the supervisory body designated pursuant to paragraph 1 may, taking into account, in particular, the extent, duration and consequences of that failure, order the provider to suspend or to cease the provision of the European Digital Identity Wallet. The supervisory body shall inform the supervisory bodies of other Member States, the Commission, relying parties and users of the European Digital Identity Wallet without undue delay of the decision to require the suspension or cessation of the provision of the European Digital Identity Wallet.6.By 31 March each year, each supervisory body designated pursuant to paragraph 1 shall submit to the Commission a report on its main activities in the previous calendar year. The Commission shall make those annual reports available to the European Parliament and the Council.7.By 21 May 2025, the Commission shall, by means of implementing acts, establish the formats and procedures for the report referred to in paragraph 6 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 46b — Supervision of trust services · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
A new Article 46b is added, setting out a system for supervision of trust services, including designation of supervisory bodies by Member States, their powers, tasks, reporting duties, and a deadline for the Commission to adopt guidelines and implementing acts on those tasks. Art. 46b, v2
text before / after
inserted text (02014R0910-20240520)
Article 46bSupervision of trust services1.Member States shall designate a supervisory body established in their territory or designate, upon mutual agreement with another Member State, a supervisory body established in that other Member State. That supervisory body shall be responsible for supervisory tasks in the designating Member State as regards trust services.The supervisory bodies designated pursuant to the first subparagraph shall be given the necessary powers and adequate resources for the exercise of their tasks.2.Member States shall notify to the Commission the names and addresses of their supervisory bodies designated pursuant to paragraph 1 and any subsequent changes thereto. The Commission shall publish a list of the notified supervisory bodies.3.The role of the supervisory bodies designated pursuant to paragraph 1 shall be:(a)to supervise qualified trust service providers established in the territory of the designating Member State and to ensure, by means of ex ante and ex post supervisory activities, that those qualified trust service providers and the qualified trust services that they provide meet the requirements laid down in this Regulation;(b)to take action, if necessary, in relation to non-qualified trust service providers established in the territory of the designating Member State, by means of ex post supervisory activities, when informed that those non-qualified trust service providers or the trust services they provide allegedly do not meet the requirements laid down in this Regulation.4.The tasks of the supervisory body designated pursuant to paragraph 1 shall include in particular the following:(a)to inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant security breach or loss of integrity of which it becomes aware in the performance of its tasks and, in the case of a significant security breach or loss of integrity which concerns other Member States, to inform the single point of contact designated or established pursuant to Article 8(3) Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of this Regulation in the other Member States concerned, and to inform the public or require the trust service provider to do so where the supervisory body determines that disclosure of the breach of security or loss of integrity would be in the public interest;(b)to cooperate with other supervisory bodies and to provide them with assistance in accordance with Articles 46c and 46e;(c)to analyse the conformity assessment reports referred to in Article 20(1) and Article 21(1);(d)to report to the Commission about its main activities in accordance with paragraph 6 of this Article;(e)to carry out audits or request a conformity assessment body to perform a conformity assessment of the qualified trust service providers in accordance with Article 20(2);(f)to cooperate with competent supervisory authorities established pursuant to Article 51 of Regulation (EU) 2016/679, in particular, by informing them, without undue delay, where personal data protection rules appear to have been breached and about security breaches which appear to constitute personal data breaches;(g)to grant qualified status to trust service providers and to the services they provide, and to withdraw that status in accordance with Articles 20 and 21;(h)to inform the body responsible for the national trusted list referred to in Article 22(3) of its decisions to grant or withdraw qualified status, unless that body is also the supervisory body designated pursuant to paragraph 1 of this Article;(i)to verify the existence and correct application of provisions on termination plans where the qualified trust service provider ceases its activities, including how information is kept accessible in accordance with Article 24(2), point (h);(j)to require that trust service providers remedy any failure to fulfil the requirements laid down in this Regulation;(k)to investigate claims made by providers of web-browsers pursuant to Article 45a and to take action if necessary.5.Member States may require the supervisory body designated pursuant to paragraph 1 to establish, maintain and update a trust infrastructure in accordance with national law.6.By 31 March each year, each supervisory body designated pursuant to paragraph 1 shall submit to the Commission a report on its main activities in the previous calendar year. The Commission shall make those annual reports available to the European Parliament and the Council.7.By 21 May 2025, the Commission shall adopt guidelines on the exercise by the supervisory bodies designated pursuant to paragraph 1 of this Article of the tasks referred to in paragraph 4 of this Article, and, by means of implementing acts, establish the formats and procedures for the report referred to in paragraph 6 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
INSERTED Art. 46c — Single points of contact · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
A new Article 46c is added, requiring each Member State to designate a single point of contact for trust services, European Digital Identity Wallets and notified electronic identification schemes. Art. 46c, v2
The provision describes the liaison function of that contact point in facilitating cross-border cooperation among supervisory bodies and with the Commission and ENISA, and sets out obligations to publish and notify the contact point's details and for the Commission to publish a list of all such contact points. Art. 46c, v2
text before / after
inserted text (02014R0910-20240520)
Article 46cSingle points of contact1.Each Member State shall designate a single point of contact for trust services, European Digital Identity Wallets and notified electronic identification schemes.2.Each single point of contact shall exercise a liaison function to facilitate cross-border cooperation between the supervisory bodies for trust service providers and between the supervisory bodies for the providers of European Digital Identity Wallets and, where appropriate, with the Commission and European Union Agency for Cybersecurity (ENISA) and with other competent authorities within its Member State.3.Each Member State shall make public and, without undue delay, notify to the Commission the names and the addresses of the single point of contact designated pursuant to paragraph 1 and any subsequent change thereto.4.The Commission shall publish a list of the single points of contact notified pursuant to paragraph 3.
INSERTED Art. 46d — Mutual assistance · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This is a newly inserted Article 46d setting out a mutual assistance mechanism among supervisory bodies designated under Articles 46a and 46b, including requests for assistance, joint investigations, and grounds on which a request may be refused. Art. 46d, v2
It also directs the Cooperation Group established under Article 46e(1) to issue guidance on the organisational aspects and procedures for this mutual assistance by a stated date and every two years thereafter. Art. 46d, v2
text before / after
inserted text (02014R0910-20240520)
Article 46dMutual assistance1.In order to facilitate the supervision and enforcement of obligations under this Regulation, the supervisory bodies designated pursuant to Article 46a(1) and Article 46b(1) may seek, including through the Cooperation Group established pursuant to Article 46e(1), mutual assistance from the supervisory bodies of another Member State where the provider of the European Digital Identity Wallet or the trust service provider is established, or where its network and information systems are located or its services are provided.2.The mutual assistance shall at least entail that:(a)the supervisory body applying supervisory and enforcement measures in one Member State shall inform and consult the supervisory body from the other Member State concerned;(b)a supervisory body may request the supervisory body of another Member State concerned to take supervisory or enforcement measures, including, for instance, requests to carry out inspections related to the conformity assessment reports as referred to in Articles 20 and 21 regarding the provision of trust services;(c)where appropriate, supervisory bodies may carry out joint investigations with the supervisory bodies of other Member States.The arrangements and procedures for joint actions under the first subparagraph shall be agreed upon and established by the Member States concerned in accordance with their national law.3.A supervisory body to which a request for assistance is addressed may refuse that request on any of the following grounds:(a)the assistance requested is not proportionate to the supervisory activities of the supervisory body carried out in accordance with Articles 46a and 46b;(b)the supervisory body is not competent to provide the requested assistance;(c)providing the requested assistance would be incompatible with this Regulation.4.By 21 May 2025 and every two years thereafter, the Cooperation Group established pursuant to Article 46e(1) shall issue guidance on the organisational aspects and procedures for the mutual assistance referred to in paragraphs 1 and 2 of this Article.
INSERTED Art. 46e — The European Digital Identity Cooperation Group · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
This is a newly inserted article establishing the European Digital Identity Cooperation Group, to be set up by the Commission to support Member States' cross-border cooperation and information exchange on trust services, European Digital Identity Wallets and notified electronic identification schemes. Art. 46e, v2
The text sets out the Group's composition, chairing and secretariat arrangements, provisions for observer participation by stakeholders and ENISA, a list of tasks including advising the Commission, exchanging best practices, organising joint meetings and peer reviews, and a duty on Member States to ensure effective cooperation of their appointed representatives. Art. 46e, v2
It also directs the Commission to adopt implementing acts establishing procedural arrangements for the peer review cooperation described in paragraph 5, point (d), following the examination procedure referred to in Article 48(2). Art. 46e, v2
text before / after
inserted text (02014R0910-20240520)
Article 46eThe European Digital Identity Cooperation Group1.In order to support and facilitate Member States’ cross-border cooperation and exchange of information on trust services, European Digital Identity Wallets and notified electronic identification schemes, the Commission shall establish a European Digital Identity Cooperation Group (the Cooperation Group).2.The Cooperation Group shall be composed of representatives appointed by the Member States and of the Commission. The Cooperation Group shall be chaired by the Commission. The Commission shall provide the Cooperation Group’s Secretariat.3.Representatives of relevant stakeholders may, on an ad hoc basis, be invited to attend meetings of the Cooperation Group and to participate in its work as observers.4.ENISA shall be invited to participate as observer in the workings of the Cooperation Group when it exchanges views, best practices and information on relevant cybersecurity aspects such as notification of security breaches, and when the use of cybersecurity certificates or standards are addressed.5.The Cooperation Group shall have the following tasks:(a)exchange advice and cooperate with the Commission on emerging policy initiatives in the field of digital identity wallets, electronic identification means and trust services;(b)advise the Commission, as appropriate, in the early preparation of draft implementing and delegated acts to be adopted pursuant to this Regulation;(c)in order to support the supervisory bodies in the implementation of the provisions of this Regulation:(i)exchange best practices and information regarding the implementation of the provisions of this Regulation;(ii)assess the relevant developments in the digital identity wallet, electronic identification and trust services sectors;(iii)organise joint meetings with relevant interested parties from across the Union to discuss activities carried out by the cooperation group and gather input on emerging policy challenges;(iv)with the support of ENISA, exchange views, best practices and information on relevant cybersecurity aspects concerning European Digital Identity Wallets, electronic identification schemes and trust services;(v)exchange best practices in relation to the development and implementation of policies on the notification of security breaches, and common measures as referred to in Articles 5e and 10;(vi)organise joint meetings with the NIS Cooperation Group established pursuant to Article 14(1) of Directive (EU) 2022/2555 to exchange relevant information in relation to trust services and electronic identification related cyber threats, incidents, vulnerabilities, awareness raising initiatives, trainings, exercises and skills, capacity building, standards and technical specifications capacity as well as standards and technical specifications;(vii)discuss, upon a request of a supervisory body, specific requests for mutual assistance as referred to in Article 46d;(viii)facilitate the exchange of information between the supervisory bodies by providing guidance on the organisational aspects and procedures for the mutual assistance referred to in Article 46d;(d)organise peer reviews of electronic identification schemes to be notified under this Regulation.6.Member States shall ensure effective and efficient cooperation of their designated representatives in the Cooperation Group.7.By 21 May 2025, the Commission shall, by means of implementing acts, establish the necessary procedural arrangements to facilitate the cooperation between the Member States referred to in paragraph 5, point (d), of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
MODIFIED Art. 47 — Exercise of the delegation · applies from unchanged
Paragraphs 2, 3 and 5 now also reference Article 5c(7) and Article 24(4b) alongside Article 30(4) as the sources of the delegated power being conferred, revocable, and subject to non-objection, whereas the earlier version referenced only Article 30(4) in each of those paragraphs. Art. 47, v1 Art. 47, v2
text before / after
32014R0910 → 02014R0910-20240520
Article 47Exercise of the delegation1.The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.2.The power to adopt delegated acts referred to in Article 5c(7), Article 24(4b) and Article 30(4) shall be conferred on the Commission for an indeterminate period of time from 17 September 2014.3.The delegation of power referred to in Article 5c(7), Article 24(4b) and Article 30(4) may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.4.As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.5.A delegated act adopted pursuant to Article 5c(7), Article 24(4b) or Article 30(4) shall enter into force only if no objection has been expressed either by the European Parliament or the Council within a period of two months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by two months at the initiative of the European Parliament or of the Council.
INSERTED Art. 48a — Reporting requirements · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, the instruction parse, not by corpus metadata.
Article 48a is a newly added provision requiring Member States to collect statistics on the functioning of European Digital Identity Wallets and qualified trust services provided within their territory. Art. 48a, v2
It lists specific categories of statistics to be gathered, including numbers of wallet holders, accepting services, complaints and incidents, and security or data breach summaries, and requires that these statistics be published in an open, machine-readable format and reported to the Commission by 31 March each year. Art. 48a, v2
text before / after
inserted text (02014R0910-20240520)
Article 48aReporting requirements1.Member States shall ensure the collection of statistics in relation to the functioning of European Digital Identity Wallets and the qualified trust services provided on their territory.2.The statistics collected in accordance with paragraph 1 shall include the following:(a)the number of natural and legal persons having a valid European Digital Identity Wallet;(b)the type and number of services accepting the use of the European Digital Identity Wallet;(c)the number of user complaints and consumer protection or data protection incidents relating to relying parties and qualified trust services;(d)a summary report including data on incidents preventing the use of the European Digital Identity Wallet;(e)a summary of significant security incidents, data breaches and affected users of European Digital Identity Wallets or of qualified trust services.3.The statistics referred to in paragraph 2 shall be made available to the public in an open and commonly used, machine-readable format.4.By 31 March each year, Member States shall submit to the Commission a report on the statistics collected in accordance with paragraph 2.
MODIFIED Art. 49 — Review · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
No explanation shipped — UnexpectedModelBehavior: Exceeded maximum output retries (1).
text before / after
32014R0910 → 02014R0910-20240520
Article 49ReviewThe 49Review1.The Commission shall review the application of this Regulation and shall shall, by 21 May 2026, submit a report to the European Parliament and to the Council no later than 1 July 2020. The Council. In that report, the Commission shall shall, in particular, evaluate in particular whether it is appropriate to modify the scope of this Regulation or its specific provisions, including provisions including, in particular, the provisions included in Article 6, point (f) of Article 7 and Articles 34, 43, 44 and 45, 5c(5), taking into account the experience gained in the application of this Regulation, as well as technological, market and legal developments.The developments. Where necessary, that report shall be accompanied by a proposal to amend this Regulation.2.The report referred to in paragraph 1 shall include an assessment of the first paragraph availability, security and usability of the notified electronic identification means and European Digital Identity Wallets that fall within the scope of this Regulation and assess whether all online private service providers relying on third-party electronic identification services for users authentication, shall be accompanied, where appropriate, by legislative proposals.In addition, required to accept the use of notified electronic identification means and European Digital Identity Wallet.3.By 21 May 2030 and every four years thereafter, the Commission shall submit a report to the European Parliament and the Council every four years after the report referred to in the first paragraph on the progress made towards achieving the objectives of this Regulation.
MODIFIED Art. 51 — Transitional measures · applies from unknown (the text changed beyond its dates; the applicability binding is prose)
Paragraph 1 now states that secure signature creation devices meeting the earlier Directive's conformity determination continue to be treated as qualified electronic signature creation devices only until 21 May 2027, whereas the earlier version stated this recognition without any end date. Art. 51, v2 Art. 51, v1
Paragraph 2 now limits the continued recognition of qualified certificates issued to natural persons under the earlier Directive to 21 May 2026, replacing the earlier open-ended wording that such certificates remained qualified until they expire. Art. 51, v2 Art. 51, v1
Paragraphs 3 and 4 no longer address certification-service-provider conformity assessment reports tied to the 1 July 2017 and 2 July 2017 deadlines from the earlier text; instead paragraph 3 now addresses management of remote qualified electronic signature and seal creation devices with a 21 May 2026 date, and paragraph 4 now addresses conformity assessment reports for qualified trust service providers granted status before 20 May 2024, with a submission deadline of 21 May 2026. Art. 51, v2 Art. 51, v1
text before / after
texts differ too much for an inline diff; shown separately
before (32014R0910)
Article 51Transitional measures1.Secure signature creation devices of which the conformity has been determined in accordance with Article 3(4) of Directive 1999/93/EC shall be considered as qualified electronic signature creation devices under this Regulation.2.Qualified certificates issued to natural persons under Directive 1999/93/EC shall be considered as qualified certificates for electronic signatures under this Regulation until they expire.3.A certification-service-provider issuing qualified certificates under Directive 1999/93/EC shall submit a conformity assessment report to the supervisory body as soon as possible but not later than 1 July 2017. Until the submission of such a conformity assessment report and the completion of its assessment by the supervisory body, that certification-service-provider shall be considered as qualified trust service provider under this Regulation.4.If a certification-service-provider issuing qualified certificates under Directive 1999/93/EC does not submit a conformity assessment report to the supervisory body within the time limit referred to in paragraph 3, that certification-service-provider shall not be considered as qualified trust service provider under this Regulation from 2 July 2017.
after (02014R0910-20240520)
Article 51Transitional measures1.Secure signature creation devices of which the conformity has been determined in accordance with Article 3(4) of Directive 1999/93/EC shall continue to be considered to be qualified electronic signature creation devices under this Regulation until 21 May 2027.2.Qualified certificates issued to natural persons under Directive 1999/93/EC shall continue to be considered as qualified certificates for electronic signatures under this Regulation until 21 May 2026.3.The management of remote qualified electronic signature and seal creation devices by qualified trust service providers other than qualified trust service providers providing qualified trust services for the management of remote qualified electronic signature and seal creation devices in accordance with Articles 29a and 39a may be carried out without the need to obtain the qualified status for the provision of these management services until 21 May 2026.4.Qualified trust service providers that have been granted their qualified status under this Regulation before 20 May 2024 shall submit a conformity assessment report to the supervisory body proving compliance with Article 24(1), (1a) and (1b) as soon as possible and in any event by 21 May 2026.
INSERTED TIT · applies from unknown
Disputed — seen by corpus metadata, not by the structural diff, the instruction parse.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED SCT 2 · applies from unknown
Disputed — seen by the instruction parse, not by the structural diff, corpus metadata.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED Annex I — ANNEX I · applies from unchanged
Disputed — seen by the structural diff, corpus metadata, not by the instruction parse.
Point (i) of Annex I now refers to the information or the location of the services that can be used to enquire about the validity status of the qualified certificate, whereas the earlier version referred only to the location of those services. Annex I, v1 Annex I, v2
text before / after
32014R0910 → 02014R0910-20240520
ANNEX IREQUIREMENTS FOR QUALIFIED CERTIFICATES FOR ELECTRONIC SIGNATURESQualified certificates for electronic signatures shall contain:(a)an indication, at least in a form suitable for automated processing, that the certificate has been issued as a qualified certificate for electronic signature;(b)a set of data unambiguously representing the qualified trust service provider issuing the qualified certificates including at least, the Member State in which that provider is established and:for a legal person: the name and, where applicable, registration number as stated in the official records,for a natural person: the person’s name;(c)at least the name of the signatory, or a pseudonym; if a pseudonym is used, it shall be clearly indicated;(d)electronic signature validation data that corresponds to the electronic signature creation data;(e)details of the beginning and end of the certificate’s period of validity;(f)the certificate identity code, which must be unique for the qualified trust service provider;(g)the advanced electronic signature or advanced electronic seal of the issuing qualified trust service provider;(h)the location where the certificate supporting the advanced electronic signature or advanced electronic seal referred to in point (g) is available free of charge;(i)the information or the location of the services that can be used to enquire about the validity status of the qualified certificate;(j)where the electronic signature creation data related to the electronic signature validation data is located in a qualified electronic signature creation device, an appropriate indication of this, at least in a form suitable for automated processing.
MODIFIED Annex II · applies from unknown
Disputed — seen by corpus metadata, not by the structural diff, the instruction parse.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED Annex III — ANNEX III · applies from unchanged
Disputed — seen by the structural diff, corpus metadata, not by the instruction parse.
Point (i) now refers to the information or the location of the services that can be used to enquire about the validity status of the qualified certificate, whereas the earlier version referred only to the location of such services and to enquiring as to that status. Annex III, v1 Annex III, v2
text before / after
32014R0910 → 02014R0910-20240520
ANNEX IIIREQUIREMENTS FOR QUALIFIED CERTIFICATES FOR ELECTRONIC SEALSQualified certificates for electronic seals shall contain:(a)an indication, at least in a form suitable for automated processing, that the certificate has been issued as a qualified certificate for electronic seal;(b)a set of data unambiguously representing the qualified trust service provider issuing the qualified certificates including at least the Member State in which that provider is established and:for a legal person: the name and, where applicable, registration number as stated in the official records,for a natural person: the person’s name;(c)at least the name of the creator of the seal and, where applicable, registration number as stated in the official records;(d)electronic seal validation data, which corresponds to the electronic seal creation data;(e)details of the beginning and end of the certificate’s period of validity;(f)the certificate identity code, which must be unique for the qualified trust service provider;(g)the advanced electronic signature or advanced electronic seal of the issuing qualified trust service provider;(h)the location where the certificate supporting the advanced electronic signature or advanced electronic seal referred to in point (g) is available free of charge;(i)the information or the location of the services that can be used to enquire as to about the validity status of the qualified certificate;(j)where the electronic seal creation data related to the electronic seal validation data is located in a qualified electronic seal creation device, an appropriate indication of this, at least in a form suitable for automated processing.
MODIFIED Annex IV — ANNEX IV · applies from unchanged
Disputed — seen by the structural diff, corpus metadata, not by the instruction parse.
Point (c) now covers only natural persons, ending with the pseudonym clause and no longer including the separate provision for legal persons. Annex IV, v1 Annex IV, v2
A new point (ca) is added for legal persons, describing a unique set of data unambiguously representing the legal person, including at least the name and, where applicable, the registration number as stated in the official records. Annex IV, v2
Point (j) now refers to the information or the location of the certificate validity status services and to enquiring about the validity status, whereas before it referred only to the location of those services and to enquiring as to the validity status. Annex IV, v1 Annex IV, v2
text before / after
32014R0910 → 02014R0910-20240520
ANNEX IVREQUIREMENTS FOR QUALIFIED CERTIFICATES FOR WEBSITE AUTHENTICATIONQualified certificates for website authentication shall contain:(a)an indication, at least in a form suitable for automated processing, that the certificate has been issued as a qualified certificate for website authentication;(b)a set of data unambiguously representing the qualified trust service provider issuing the qualified certificates including at least the Member State in which that provider is established and:for a legal person: the name and, where applicable, registration number as stated in the official records,for a natural person: the person’s name;(c)for natural persons: at least the name of the person to whom the certificate has been issued, or a pseudonym. If pseudonym; if a pseudonym is used, it shall be clearly indicated;for indicated;(ca)for legal persons: a unique set of data unambiguously representing the legal person to whom the certificate is issued, with at least the name of the legal person to whom the certificate is issued and, where applicable, the registration number as stated in the official records;(d)elements of the address, including at least city and State, of the natural or legal person to whom the certificate is issued and, where applicable, as stated in the official records;(e)the domain name(s) operated by the natural or legal person to whom the certificate is issued;(f)details of the beginning and end of the certificate’s period of validity;(g)the certificate identity code, which must be unique for the qualified trust service provider;(h)the advanced electronic signature or advanced electronic seal of the issuing qualified trust service provider;(i)the location where the certificate supporting the advanced electronic signature or advanced electronic seal referred to in point (h) is available free of charge;(j)the information or the location of the certificate validity status services that can be used to enquire as to about the validity status of the qualified certificate.
INSERTED Annex V — REQUIREMENTS FOR QUALIFIED ELECTRONIC ATTESTATION OF ATTRIBUTES · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — the signals disagree on the kind of change — the structural diff says INSERTED, corpus metadata says INSERTED, the instruction parse says MODIFIED.
Annex V is newly added and sets out a list of items that qualified electronic attestation of attributes must contain, covering an indication of its qualified status, identification data for the issuing qualified trust service provider and for the entity to which attributes refer, the attested attributes and their scope, validity period details, an attestation identity code, the qualified electronic signature or seal of the issuer, the location of the supporting certificate, and information or a location for checking validity status. Annex V, v2
text before / after
inserted text (02014R0910-20240520)
ANNEX VREQUIREMENTS FOR QUALIFIED ELECTRONIC ATTESTATION OF ATTRIBUTESQualified electronic attestation of attributes shall contain:(a)an indication, at least in a form suitable for automated processing, that the attestation has been issued as a qualified electronic attestation of attributes;(b)a set of data unambiguously representing the qualified trust service provider issuing the qualified electronic attestation of attributes including at least, the Member State in which that provider is established and:(i)for a legal person: the name and, where applicable, registration number as stated in the official records;(ii)for a natural person: the person’s name;(c)a set of data unambiguously representing the entity to which the attested attributes refer; if a pseudonym is used, it shall be clearly indicated;(d)the attested attribute or attributes, including, where applicable, the information necessary to identify the scope of those attributes;(e)details of the beginning and end of the attestation’s period of validity;(f)the attestation identity code, which must be unique for the qualified trust service provider and, if applicable, the indication of the scheme of attestations that the attestation of attributes is part of;(g)the qualified electronic signature or qualified electronic seal of the issuing qualified trust service provider;(h)the location where the certificate supporting the qualified electronic signature or qualified electronic seal referred to in point (g) is available free of charge;(i)the information or location of the services that can be used to enquire about the validity status of the qualified attestation..
INSERTED Annex VI — MINIMUM LIST OF ATTRIBUTES · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, corpus metadata, not by the instruction parse.
Annex VI is a newly added annex setting out a minimum list of attributes that Member States must ensure can be verified electronically by qualified trust service providers of electronic attestations of attributes, at a user's request, against relevant authentic sources or designated intermediaries at national level. Annex VI, v2
The list itself enumerates eleven attribute categories, including address, age, gender, civil status, family composition, nationality or citizenship, educational and professional qualifications, powers and mandates to represent persons, public permits and licences, and financial and company data for legal persons. Annex VI, v2
text before / after
inserted text (02014R0910-20240520)
ANNEX VIMINIMUM LIST OF ATTRIBUTESPursuant to Article 45e, Member States shall ensure that measures are taken to allow qualified trust service providers of electronic attestations of attributes to verify by electronic means at the request of the user, the authenticity of the following attributes against the relevant authentic source at national level or via designated intermediaries recognised at national level, in accordance with Union or national law and where these attributes rely on authentic sources within the public sector:1.Address;2.Age;3.Gender;4.Civil status;5.Family composition;6.Nationality or citizenship;7.Educational qualifications, titles and licences;8.Professional qualifications, titles and licences;9.Powers and mandates to represent natural or legal persons;10.Public permits and licences;11.For legal persons, financial and company data.
INSERTED Annex VII — REQUIREMENTS FOR ELECTRONIC ATTESTATION OF ATTRIBUTES ISSUED BY OR ON BEHALF OF A PUBLIC BODY RESPONSIBLE FOR AN AUTHENTIC SOURCE · applies from unknown (an inserted provision states its own application date only in prose)
Disputed — seen by the structural diff, corpus metadata, not by the instruction parse.
Annex VII is newly added and sets out the list of elements that an electronic attestation of attributes issued by or on behalf of a public body responsible for an authentic source must contain. Annex VII, v2
The listed elements cover an indication that the attestation was issued as such, data identifying the issuing public body and the entity to which the attributes refer, the attested attribute or attributes, validity period, a unique attestation identity code, the issuing body's qualified electronic signature or seal, the location of the supporting certificate, and information or a location for checking the attestation's validity status. Annex VII, v2
text before / after
inserted text (02014R0910-20240520)
ANNEX VIIREQUIREMENTS FOR ELECTRONIC ATTESTATION OF ATTRIBUTES ISSUED BY OR ON BEHALF OF A PUBLIC BODY RESPONSIBLE FOR AN AUTHENTIC SOURCEAn electronic attestation of attributes issued by or on behalf of a public body responsible for an authentic source shall contain:(a)an indication, at least in a form suitable for automated processing, that the attestation has been issued as an electronic attestation of attributes issued by or on behalf of a public body responsible for an authentic source;(b)a set of data unambiguously representing the public body issuing the electronic attestation of attributes, including at least, the Member State in which that public body is established and its name and, where applicable, its registration number as stated in the official records;(c)a set of data unambiguously representing the entity to which the attested attributes refer; if a pseudonym is used, it shall be clearly indicated;(d)the attested attribute or attributes, including, where applicable, the information necessary to identify the scope of those attributes;(e)details of the beginning and end of the attestation’s period of validity;(f)the attestation identity code, which must be unique for the issuing public body and, if applicable, an indication of the scheme of attestations that the attestation of attributes is part of;(g)the qualified electronic signature or qualified electronic seal of the issuing body;(h)the location where the certificate supporting the qualified electronic signature or qualified electronic seal referred to in point (g) is available free of charge;(i)the information or location of the services that can be used to enquire about the validity status of the attestation.
MODIFIED CHA II · applies from unknown
Disputed — seen by corpus metadata, not by the structural diff, the instruction parse.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED CHA III · applies from unknown
Disputed — seen by corpus metadata, not by the structural diff, the instruction parse.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED CHA VI · applies from unknown
Disputed — seen by corpus metadata, not by the structural diff, the instruction parse.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
INSERTED CHA IVa · applies from unknown
Disputed — seen by corpus metadata, not by the structural diff, the instruction parse.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
The full entry, with the citation mapping v1 = 32014R0910, v2 = 02014R0910-20240520, is committed at eu/32014R0910/CHANGELOG.md.