emendrix

Electronic Identification and Trust Services Regulation

eIDAS · 32014R0910 · every event for this act · on EUR-Lex

Everything Regulation (EU) 2024/1183 amended

in force 2024-05-20

32014R0910 → 02014R0910-20240520

Amended by Regulation (EU) 2024/1183 32024R1183

Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework

detected 2026-08-12

86 provisions touched — 86 substantive, 0 date-only, 52 disputed · 15 changes without an explanation

Emendrix checks every change against three independent sources. Where they disagree it says so rather than picking a winner.

MODIFIED +568 −98 Art. 1 Subject matter

applies from: unchanged

The introductory sentence now states that the Regulation aims to ensure the proper functioning of the internal market and an adequate level of security of electronic identification means and trust services used across the Union, in order to enable natural and legal persons to participate in digital society and access online public and private services throughout the Union, whereas the earlier version simply stated the aim of ensuring the proper functioning of the internal market while aiming at an adequate level of such security.

Point (a) now also refers to Member States providing and recognising European Digital Identity Wallets, in addition to recognising notified electronic identification means.

Point (c) now lists additional items covered by the legal framework, namely electronic archiving, electronic attestation of attributes, electronic signature creation devices, electronic seal creation devices, and electronic ledgers, alongside the items already listed in the earlier version.

Cited: Art. 1, v1 · Art. 1, v2

text before / after

32014R091002014R0910-20240520

Article 1 Subject matter With a view This Regulation aims to ensuring ensure the proper functioning of the internal market while aiming at and the provision of an adequate level of security of electronic identification means and trust services used across the Union, in order to enable and facilitate the exercise by natural and legal persons of the right to participate in digital society safely and to access online public and private services throughout the Union. For those purposes, this Regulation: (a) lays down the conditions under which Member States are to recognise natural and legal persons’ electronic identification means of natural and legal persons falling under a notified electronic identification scheme of another Member State; State and provide and recognise European Digital Identity Wallets; (b) lays down rules for trust services, in particular for electronic transactions; and (c) establishes a legal framework for electronic signatures, electronic seals, electronic time stamps, electronic documents, electronic registered delivery services and services, certificate services for website authentication. authentication, electronic archiving, electronic attestation of attributes, electronic signature creation devices, electronic seal creation devices, and electronic ledgers.

MODIFIED +551 −42 Art. 2 Scope

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2016-04-27

Paragraph 1 now adds European Digital Identity Wallets provided by a Member State to the list of things the Regulation applies to, alongside notified electronic identification schemes and trust service providers established in the Union.

Paragraph 3 now also states that the Regulation does not affect sector-specific requirements relating to form, in addition to contracts and other legal or procedural obligations relating to form.

A new paragraph 4 has been added stating that the Regulation is without prejudice to Regulation (EU) 2016/679, a provision not present in the earlier text.

Cited: Art. 2, v2 · Art. 2, v1

text before / after

32014R091002014R0910-20240520

Article 2 Scope 1. This Regulation applies to electronic identification schemes that have been notified by a Member State, to European Digital Identity Wallets provided by a Member State and to trust service providers that are established in the Union. 2. This Regulation does not apply to the provision of trust services that are used exclusively within closed systems resulting from national law or from agreements between a defined set of participants. 3. This Regulation does not affect Union or national or Union law related to the conclusion and validity of contracts or contracts, other legal or procedural obligations relating to form, or sector-specific requirements relating to form.4. This Regulation is without prejudice to Regulation (EU) 2016/679 of the European Parliament and of the CouncilRegulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1)..

MODIFIED +6,439 −363 Art. 3 Definitions

applies from: unchanged

Several existing definitions in Article 3(1) are broadened, including those for electronic identification, electronic identification means, person identification data, electronic identification scheme, authentication, relying party, conformity assessment body, product, certificate for website authentication and validation, to also cover natural persons representing other natural persons, offline services, European Digital Identity Wallets, and additional attestation and archiving concepts.

The definition of trust service in point (16) is restructured from a three-part list into a fourteen-part list of activities such as issuance and validation of certificates, creation and validation of signatures, seals, timestamps, electronic registered delivery data, attestations of attributes, archiving and ledger recording.

New definitions are added, including point (5a) for user, points (23a) and (23b) for remote qualified electronic signature and seal creation devices, and points (42) through (57) covering terms such as European Digital Identity Wallet, attribute, authentic source, electronic archiving, electronic ledger, personal data, identity matching, data record and offline mode.

Cited: Art. 3, v1 · Art. 3, v2

text before / after

32014R091002014R0910-20240520

Article 3 Definitions For the purposes of this Regulation, the following definitions apply: (1) electronic identification means the process of using person identification data in electronic form uniquely representing either a natural or legal person, or a natural person representing another natural person or a legal person; (2) electronic identification means means a material and/or immaterial unit containing person identification data and which is used for authentication for an online service or, where appropriate, for an offline service; (3) person identification data means a set of data enabling that is issued in accordance with Union or national law and that enables the establishment of the identity of a natural or legal person, or of a natural person representing another natural person or a legal person to be established; person. (4) electronic identification scheme means a system for electronic identification under which electronic identification means are issued to natural or legal persons, persons or natural persons representing other natural persons or legal persons; (5) authentication means an electronic process that enables the confirmation of the electronic identification of a natural or legal person, person or the confirmation of the origin and integrity of data in electronic form to be confirmed; form; (5a) user means a natural or legal person, or a natural person representing another natural person or a legal person, that uses trust services or electronic identification means provided in accordance with this Regulation; (6) relying party means a natural or legal person that relies upon an electronic identification, European Digital Identity Wallets or other electronic identification means, or upon a trust service; (7) public sector body means a state, regional or local authority, a body governed by public law or an association formed by one or several such authorities or one or several such bodies governed by public law, or a private entity mandated by at least one of those authorities, bodies or associations to provide public services, when acting under such a mandate; (8) body governed by public law means a body defined in point (4) of Article 2(1) of Directive 2014/24/EU of the European Parliament and of the CouncilDirective 2014/24/EU of the European Parliament and of the Council of 26 February 2014 on public procurement and repealing Directive 2004/18/EC (OJ L 94, 28.3.2014, p. 65).; (9) signatory means a natural person who creates an electronic signature; (10) electronic signature means data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign; (11) advanced electronic signature means an electronic signature which meets the requirements set out in Article 26; (12) qualified electronic signature means an advanced electronic signature that is created by a qualified electronic signature creation device, and which is based on a qualified certificate for electronic signatures; (13) electronic signature creation data means unique data which is used by the signatory to create an electronic signature; (14) certificate for electronic signature means an electronic attestation which links electronic signature validation data to a natural person and confirms at least the name or the pseudonym of that person; (15) qualified certificate for electronic signature means a certificate for electronic signatures, that is issued by a qualified trust service provider and meets the requirements laid down in Annex I; (16) trust service means an electronic service normally provided for remuneration which consists of: of any of the following: (a) the creation, verification, and issuance of certificates for electronic signatures, certificates for electronic seals, certificates for website authentication or certificates for the provision of other trust services; (b) the validation of certificates for electronic signatures, certificates for electronic seals, certificates for website authentication or certificates for the provision of other trust services; (c) the creation of electronic signatures or electronic seals; (d) the validation of electronic signatures or electronic seals; (e) the preservation of electronic signatures, electronic seals seals, certificates for electronic signatures or certificates for electronic time stamps, seals; (f) the management of remote electronic signature creation devices or remote electronic seal creation devices; (g) the issuance of electronic attestations of attributes; (h) the validation of electronic attestation of attributes; (i) the creation of electronic timestamps; (j) the validation of electronic timestamps; (k) the provision of electronic registered delivery services; (l) the validation of data transmitted through electronic registered delivery services and certificates related to those services, or (b) evidence; (m) the creation, verification and validation of certificates for website authentication; or (c) the preservation electronic archiving of electronic signatures, seals or certificates related to those services; data and electronic documents; (n) the recording of electronic data in an electronic ledger; (17) qualified trust service means a trust service that meets the applicable requirements laid down in this Regulation; (18) conformity assessment body means a conformity assessment body as defined in Article 2, point 13 of Article 2 13, of Regulation (EC) No 765/2008, which is accredited in accordance with that Regulation as competent to carry out conformity assessment of a qualified trust service provider and the qualified trust services it provides; provides, or as competent to carry out certification of European Digital Identity Wallets or electronic identification means; (19) trust service provider means a natural or a legal person who provides one or more trust services either as a qualified or as a non-qualified trust service provider; (20) qualified trust service provider means a trust service provider who provides one or more qualified trust services and is granted the qualified status by the supervisory body; (21) product means hardware or software, or relevant components of hardware or software, which are intended to be used for the provision of electronic identification and trust services; (22) electronic signature creation device means configured software or hardware used to create an electronic signature; (23) qualified electronic signature creation device means an electronic signature creation device that meets the requirements laid down in Annex II; (23a) remote qualified electronic signature creation device means a qualified electronic signature creation device that is managed by a qualified trust service provider in accordance with Article 29a on behalf of a signatory; (23b) remote qualified electronic seal creation device means a qualified electronic seal creation device that is managed by a qualified trust service provider in accordance with Article 39a on behalf of a seal creator; (24) creator of a seal means a legal person who creates an electronic seal; (25) electronic seal means data in electronic form, which is attached to or logically associated with other data in electronic form to ensure the latter’s origin and integrity; (26) advanced electronic seal means an electronic seal, which meets the requirements set out in Article 36; (27) qualified electronic seal means an advanced electronic seal, which is created by a qualified electronic seal creation device, and that is based on a qualified certificate for electronic seal; (28) electronic seal creation data means unique data, which is used by the creator of the electronic seal to create an electronic seal; (29) certificate for electronic seal means an electronic attestation that links electronic seal validation data to a legal person and confirms the name of that person; (30) qualified certificate for electronic seal means a certificate for an electronic seal, that is issued by a qualified trust service provider and meets the requirements laid down in Annex III; (31) electronic seal creation device means configured software or hardware used to create an electronic seal; (32) qualified electronic seal creation device means an electronic seal creation device that meets mutatis mutandis the requirements laid down in Annex II; (33) electronic time stamp means data in electronic form which binds other data in electronic form to a particular time establishing evidence that the latter data existed at that time; (34) qualified electronic time stamp means an electronic time stamp which meets the requirements laid down in Article 42; (35) electronic document means any content stored in electronic form, in particular text or sound, visual or audiovisual recording; (36) electronic registered delivery service means a service that makes it possible to transmit data between third parties by electronic means and provides evidence relating to the handling of the transmitted data, including proof of sending and receiving the data, and that protects transmitted data against the risk of loss, theft, damage or any unauthorised alterations; (37) qualified electronic registered delivery service means an electronic registered delivery service which meets the requirements laid down in Article 44; (38) certificate for website authentication means an electronic attestation that makes it possible to authenticate a website and links the website to the natural or legal person to whom the certificate is issued; (39) qualified certificate for website authentication means a certificate for website authentication, which is issued by a qualified trust service provider and meets the requirements laid down in Annex IV; (40) validation data means data that is used to validate an electronic signature or an electronic seal; (41) validation means the process of verifying and confirming that data in electronic form are valid in accordance with this Regulation; (42) European Digital Identity Wallet means an electronic signature identification means which allows the user to securely store, manage and validate person identification data and electronic attestations of attributes for the purpose of providing them to relying parties and other users of European Digital Identity Wallets, and to sign by means of qualified electronic signatures or to seal by means of qualified electronic seals; (43) attribute means a seal characteristic, quality, right or permission of a natural or legal person or of an object; (44) electronic attestation of attributes means an attestation in electronic form that allows attributes to be authenticated; (45) qualified electronic attestation of attributes means an electronic attestation of attributes which is valid. issued by a qualified trust service provider and meets the requirements laid down in Annex V; (46) electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source means an electronic attestation of attributes issued by a public sector body that is responsible for an authentic source or by a public sector body that is designated by the Member State to issue such attestations of attributes on behalf of the public sector bodies responsible for authentic sources in accordance with Article 45f and with Annex VII; (47) authentic source means a repository or system, held under the responsibility of a public sector body or private entity, that contains and provides attributes about a natural or legal person or object and that is considered to be a primary source of that information or recognised as authentic in accordance with Union or national law, including administrative practice; (48) electronic archiving means a service ensuring the receipt, storage, retrieval and deletion of electronic data and electronic documents in order to ensure their durability and legibility as well as to preserve their integrity, confidentiality and proof of origin throughout the preservation period; (49) qualified electronic archiving service means an electronic archiving service which is provided by a qualified trust service provider and which meets the requirements laid down in Article 45j; (50) EU Digital Identity Wallet Trust Mark means a verifiable, simple and recognisable indication which is communicated in a clear manner that a European Digital Identity Wallet has been provided in accordance with this Regulation; (51) strong user authentication means an authentication based on the use of at least two authentication factors from different categories of either knowledge, something only the user knows, possession, something only the user possesses or inherence, something the user is, that are independent, in that the breach of one does not compromise the reliability of the others, and is designed in such a way as to protect the confidentiality of the authentication data; (52) electronic ledger means a sequence of electronic data records, ensuring the integrity of those records and the accuracy of the chronological ordering of those records; (53) qualified electronic ledger means an electronic ledger which is provided by a qualified trust service provider and which meets the requirements laid down in Article 45l; (54) personal data means any information as defined in Article 4, point (1), of Regulation (EU) 2016/679; (55) identity matching means a process where person identification data, or electronic identification means are matched with or linked to an existing account belonging to the same person; (56) data record means electronic data recorded with related meta-data supporting the processing of the data; (57) offline mode means, as regards the use of European Digital Identity Wallets, an interaction between a user and a third party at a physical location using close proximity technologies, whereby the European Digital Identity Wallet is not required to access remote systems via electronic communication networks for the purpose of the interaction.

MODIFIED +143 −146 Art. 5 Pseudonyms in electronic transaction

applies from: unchanged

The heading changed from 'Data processing and protection' to 'Pseudonyms in electronic transaction', and the former paragraph 1 on processing personal data under Directive 95/46/EC has been removed entirely.

The remaining text, formerly paragraph 2, now adds an exception for specific rules of Union or national law requiring users to identify themselves, alongside the existing exception for the legal effect given to pseudonyms under national law, and specifies that the pseudonyms in question are those chosen by the user.

Cited: Art. 5, v1 · Art. 5, v2

text before / after

32014R091002014R0910-20240520

Article 5 Data processing and protection 1. Processing of personal data shall be carried out Pseudonyms in accordance with Directive 95/46/EC. 2. electronic transaction Without prejudice to specific rules of Union or national law requiring users to identify themselves or to the legal effect given to pseudonyms under national law, the use of pseudonyms in electronic transactions that are chosen by the user shall not be prohibited.

INSERTED +13,573 −0 Art. 5a European Digital Identity Wallets

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is an entirely new article, absent from the earlier version, setting out detailed provisions on the establishment, functionalities, security, and governance of European Digital Identity Wallets.

It covers matters such as Member States' obligation to provide wallets, open-source licensing of the source code, the functions wallets must enable for users, security breach notification, revocation grounds, data protection safeguards, accessibility requirements, and implementing acts to be adopted by the Commission.

Cited: Art. 5a, v2

text before / after

inserted text (02014R0910-20240520)

Article 5a
European Digital Identity Wallets
1. For the purpose of ensuring that all natural and legal persons in the Union have secure, trusted and seamless cross-border access to public and private services, while having full control over their data, each Member State shall provide at least one European Digital Identity Wallet within 24 months of the date of entry into force of the implementing acts referred to in paragraph 23 of this Article and in Article 5c(6).
2. European Digital Identity Wallets shall be provided in one or more of the following ways:
(a) directly by a Member State;
(b) under a mandate from a Member State;
(c) independently of a Member State but recognised by that Member State.
3. The source code of the application software components of European Digital Identity Wallets shall be open-source licensed. Member States may provide that, for duly justified reasons, the source code of specific components other than those installed on user devices shall not be disclosed.
4. European Digital Identity Wallets shall enable the user, in a manner that is user-friendly, transparent, and traceable by the user, to:
(a) securely request, obtain, select, combine, store, delete, share and present, under the sole control of the user, person identification data and, where applicable, in combination with electronic attestations of attributes, to authenticate to relying parties online and, where appropriate, in offline mode, in order to access public and private services, while ensuring that selective disclosure of data is possible;
(b) generate pseudonyms and store them encrypted and locally within the European Digital Identity Wallet;
(c) securely authenticate another person’s European Digital Identity Wallet, and receive and share person identification data and electronic attestations of attributes in a secured way between the two European Digital Identity Wallets;
(d) access a log of all transactions carried out through the European Digital Identity Wallet via a common dashboard enabling the user to:
(i) view an up-to-date list of relying parties with which the user has established a connection and, where applicable, all data exchanged;
(ii) easily request the erasure by a relying party of personal data pursuant to Article 17 of the Regulation (EU) 2016/679;
(iii) easily report a relying party to the competent national data protection authority, where an allegedly unlawful or suspicious request for data is received;
(e) sign by means of qualified electronic signatures or seal by means of qualified electronic seals;
(f) download, to the extent technically feasible, the user’s data, electronic attestation of attributes and configurations;
(g) exercise the user’s rights to data portability.
5. European Digital Identity Wallets shall, in particular:
(a) support common protocols and interfaces:
(i) for issuance of person identification data, qualified and non-qualified electronic attestations of attributes or qualified and non-qualified certificates to the European Digital Identity Wallet;
(ii) for relying parties to request and validate person identification data and electronic attestations of attributes;
(iii) for the sharing and presentation to relying parties of person identification data, electronic attestation of attributes or of selectively disclosed related data online and, where appropriate, in offline mode;
(iv) for the user to allow interaction with the European Digital Identity Wallet and display an EU Digital Identity Wallet Trust Mark;
(v) to securely onboard the user by using an electronic identification means in accordance with Article 5a(24);
(vi) for interaction between two persons’ European Digital Identity Wallets for the purpose of receiving, validating and sharing person identification data and electronic attestations of attributes in a secure manner;
(vii) for authenticating and identifying relying parties by implementing authentication mechanisms in accordance with Article 5b;
(viii) for relying parties to verify the authenticity and validity of European Digital Identity Wallets;
(ix) for requesting a relying party the erasure of personal data pursuant to Article 17 of Regulation (EU) 2016/679;
(x) for reporting a relying party to the competent national data protection authority where an allegedly unlawful or suspicious request for data is received;
(xi) for the creation of qualified electronic signatures or electronic seals by means of qualified electronic signature or electronic seal creation devices;
(b) not provide any information to trust service providers of electronic attestations of attributes about the use of those electronic attestations;
(c) ensure that the relying parties can be authenticated and identified by implementing authentication mechanisms in accordance with Article 5b;
(d) meet the requirements set out in Article 8 with regard to assurance level high, in particular as applied to the requirements for identity proofing and verification, and electronic identification means management and authentication;
(e) in the case of the electronic attestation of attributes with embedded disclosure policies, implement the appropriate mechanism to inform the user that the relying party or the user of the European Digital Identity Wallet requesting that electronic attestation of attributes has the permission to access such attestation;
(f) ensure that the person identification data, which is available from the electronic identification scheme under which the European Digital Identity Wallet is provided, uniquely represents the natural person, legal person or the natural person representing the natural or legal person, and is associated with that European Digital Identity Wallet;
(g) offer all natural persons the ability to sign by means of qualified electronic signatures by default and free of charge.
Notwithstanding point (g) of the first subparagraph, Member States may provide for proportionate measures to ensure that the use of qualified electronic signatures free-of-charge by natural persons is limited to non-professional purposes.
6. Member State shall inform users, without delay, of any security breach that could have entirely or partially compromised their European Digital Identity Wallet or its contents, in particular if their European Digital Identity Wallet has been suspended or revoked pursuant to Article 5e.
7. Without prejudice to Article 5f, Member States may provide, in accordance with national law, for additional functionalities of European Digital Identity Wallets, including interoperability with existing national electronic identification means. Those additional functionalities shall comply with this Article.
8. Member States shall provide validation mechanisms free-of-charge, in order to:
(a) ensure that the authenticity and validity of European Digital Identity Wallets can be verified;
(b) allow users to verify the authenticity and validity of the identity of relying parties registered in accordance with Article 5b.
9. Member States shall ensure that the validity of the European Digital Identity Wallet can be revoked in the following circumstances:
(a) upon the explicit request of the user;
(b) where the security of the European Digital Identity Wallet has been compromised;
(c) upon the death of the user or cease of activity of the legal person.
10. Providers of European Digital Identity Wallets shall ensure that users can easily request technical support and report technical problems or any other incidents having a negative impact on the use of European Digital Identity Wallets.
11. European Digital Identity Wallets shall be provided under an electronic identification scheme with assurance level high.
12. European Digital Identity Wallets shall ensure security-by-design.
13. The issuance, use and revocation of the European Digital Identity Wallets shall be free of charge to all natural persons.
14. Users shall have full control of the use of and of the data in their European Digital Identity Wallet. The provider of the European Digital Identity Wallet shall neither collect information about the use of the European Digital Identity Wallet which is not necessary for the provision of European Digital Identity Wallet services, nor combine person identification data or any other personal data stored or relating to the use of the European Digital Identity Wallet with personal data from any other services offered by that provider or from third-party services which are not necessary for the provision of European Digital Identity Wallet services, unless the user has expressly requested otherwise. Personal data relating to the provision of the European Digital Identity Wallet shall be kept logically separate from any other data held by the provider of the European Digital Identity Wallet. If the European Digital Identity Wallet is provided by private parties in accordance with paragraph 2, points (b) and (c), of this Article, the provisions of Article 45h(3) shall apply mutatis mutandis.
15. The use of European Digital Identity Wallets shall be voluntary. Access to public and private services, access to the labour market and freedom to conduct business shall not in any way be restricted or made disadvantageous to natural or legal persons that do not use European Digital Identity Wallets. It shall remain possible to access public and private services by other existing identification and authentication means.
16. The technical framework of the European Digital Identity Wallet shall:
(a) not allow providers of electronic attestations of attributes or any other party, after the issuance of the attestation of attributes, to obtain data that allows transactions or user behaviour to be tracked, linked or correlated, or knowledge of transactions or user behaviour to be otherwise obtained, unless explicitly authorised by the user;
(b) enable privacy preserving techniques which ensure unlikeability, where the attestation of attributes does not require the identification of the user.
17. Any processing of personal data carried out by the Member States or on their behalf by bodies or parties responsible for the provision of European Digital Identity Wallets as electronic identification means shall be carried out in accordance with appropriate and effective data protection measures. Compliance of such processing with Regulation (EU) 2016/679 shall be demonstrated. Member States may introduce national provisions to further specify the application of such measures.
18. Member States shall, without undue delay, notify the Commission of information about:
(a) the body responsible for establishing and maintaining the list of registered relying parties that rely on European Digital Identity Wallets in accordance with Article 5b(5) and the location of that list;
(b) the bodies responsible for the provision of European Digital Identity Wallets in accordance with Article 5a(1);
(c) the bodies responsible for ensuring that the person identification data is associated with the European Digital Identity Wallet in accordance with Article 5a(5), point (f);
(d) the mechanism allowing for the validation of the person identification data referred to in Article 5a(5), point (f), and of the identity of the relying parties;
(e) the mechanism by which to validate the authenticity and validity of European Digital Identity Wallets.
The Commission shall make available the information notified pursuant to the first subparagraph to the public through a secure channel, in electronically signed or sealed form suitable for automated processing.
19. Without prejudice to paragraph 22 of this Article, Article 11 shall apply mutatis mutandis to the European Digital Identity Wallet.
20. Article 24(2), points (b), and (d) to (h), shall apply mutatis mutandis to providers of European Digital Identity Wallets.
21. European Digital Identity Wallets shall be made accessible for use, by persons with disabilities, on an equal basis with other users, in accordance with Directive (EU) 2019/882 of the European Parliament and of the CouncilDirective (EU) 2019/882 of the European Parliament and of the Council of 17 April 2019on the accessibility requirements for products and services (OJ L 151, 7.6.2019, p. 70)..
22. For the purposes of the provision of European Digital Identity Wallets, European Digital Identity Wallets and the electronic identification schemes under which they are provided shall not be subject to the requirements laid down in Articles 7, 9, 10, 12 and 12a.
23. By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the requirements referred to in paragraphs 4, 5, 8 and 18 of this Article on the implementation of the European Digital Identity Wallet. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
24. The Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures in order to facilitate the onboarding of users to the European Digital Identity Wallet either by electronic identification means conforming to assurance level high or by electronic identification means conforming to assurance level substantial in conjunction with additional remote onboarding procedures that together meet the requirements of assurance level high. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +2,803 −0 Art. 5b European Digital Identity Wallet-Relying Parties

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This article is new, establishing registration, disclosure, and identification requirements for relying parties that intend to use European Digital Identity Wallets.

It sets out obligations covering registration in the Member State of establishment, the minimum information to be provided, limits on data requested from users, public availability of registration details, notification of changes, a common authentication mechanism, identification of relying parties to users, responsibility for authentication and validation procedures, treatment of intermediaries, and a Commission deadline for technical specifications.

Cited: Art. 5b, v2

text before / after

inserted text (02014R0910-20240520)

Article 5b
European Digital Identity Wallet-Relying Parties
1. Where a relying party intends to rely upon European Digital Identity Wallets for the provision of public or private services by means of digital interaction, the relying party shall register in the Member State where it is established.
2. The registration process shall be cost-effective and proportionate-to-risk. The relying party shall provide at least:
(a) the information necessary to authenticate to European Digital Identity Wallets, which as a minimum includes:
(i) the Member State in which the relying party is established; and
(ii) the name of the relying party and, where applicable, its registration number as stated in an official record together with identification data of that official record;
(b) the contact details of the relying party;
(c) the intended use of European Digital Identity Wallets, including an indication of the data to be requested by the relying party from users.
3. Relying parties shall not request users to provide any data other than that indicated pursuant to paragraph 2, point (c).
4. Paragraphs 1 and 2 shall be without prejudice to Union or national law that is applicable to the provision of specific services.
5. Member States shall make the information referred to in paragraph 2 publicly available online in electronically signed or sealed form suitable for automated processing.
6. Relying parties registered in accordance with this Article shall inform Member States without delay about any changes to the information provided in the registration pursuant to paragraph 2.
7. Member States shall provide a common mechanism for allowing the identification and authentication of relying parties, as referred to in Article 5a(5), point (c).
8. Where relying parties intend to rely upon European Digital Identity Wallets, they shall identify themselves to the user.
9. Relying parties shall be responsible for carrying out the procedure for authenticating and validating person identification data and electronic attestation of attributes requested from European Digital Identity Wallets. Relying parties shall not refuse the use of pseudonyms, where the identification of the user is not required by Union or national law.
10. Intermediaries acting on behalf of relying parties shall be deemed to be relying parties and shall not store data about the content of the transaction.
11. By 21 November 2024, the Commission shall establish technical specifications and procedures for the requirements referred to in paragraphs 2, 5 and 6 to 9 of this Article by means of implementing acts on the implementation of European Digital Identity Wallets as referred to in Article 5a(23). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +3,357 −0 Art. 5c Certification of European Digital Identity Wallets

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is a newly inserted article setting out requirements for certifying European Digital Identity Wallets, covering conformity assessment by designated bodies, cybersecurity certification schemes, national certification schemes, certification validity periods, data-processing certification, Commission implementing and delegated acts, and communication of assessment-body details.

Cited: Art. 5c, v2

text before / after

inserted text (02014R0910-20240520)

Article 5c
Certification of European Digital Identity Wallets
1. The conformity of European Digital Identity Wallets and the electronic identification scheme under which they are provided with the requirements laid down in Article 5a(4), (5), (8), the requirement for logical separation laid down in Article 5a(14) and, where applicable, with the standards and technical specifications referred to in Article 5a(24), shall be certified by conformity assessment bodies designated by Member States.
2. Certification of the conformity of European Digital Identity Wallets with requirements referred to in paragraph 1 of this Article, or parts thereof, that are relevant for cybersecurity shall be carried out in accordance with European cybersecurity certification schemes adopted pursuant to Regulation (EU) 2019/881 of the European Parliament and of the CouncilRegulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ L 151, 7.6.2019, p. 15). and referred to in the implementing acts referred to in paragraph 6 of this Article.
3. For requirements referred to in paragraph 1 of this Article that are not relevant for cybersecurity, and, for requirements referred to in paragraph 1 of this Article that are relevant for cybersecurity, to the extent that cybersecurity certification schemes as referred to in paragraph 2 of this Article do not, or only partially, cover those cybersecurity requirements, also for those requirements, Member States shall establish national certification schemes following the requirements set out in the implementing acts referred to in paragraph 6 of this Article. Member States shall transmit their draft national certification schemes to the European Digital Identity Cooperation Group established pursuant to Article 46e(1) (the Cooperation Group). The Cooperation Group may issue opinions and recommendations.
4. Certification pursuant to paragraph 1 shall be valid for up to five years, provided that a vulnerability assessment is carried out every two years. Where a vulnerability is identified and not remedied in a timely manner, certification shall be cancelled.
5. Compliance with the requirements set out in Article 5a of this Regulation related to the personal data processing operations may be certified pursuant to Regulation(EU) 2016/679.
6. By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the certification of European Digital Identity Wallets referred to in paragraph 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
7. Member States shall communicate to the Commission the names and addresses of the conformity assessment bodies referred to in paragraph 1. The Commission shall make that information available to all Member States.
8. The Commission shall be empowered to adopt delegated acts in accordance with Article 47 establishing specific criteria to be met by the designated conformity assessment bodies referred to in paragraph 1 of this Article.

INSERTED +2,626 −0 Art. 5d Publication of a list of certified European Digital Identity Wallets

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

Article 5d is a newly inserted provision setting out obligations for Member States to inform the Commission and the Cooperation Group about certified European Digital Identity Wallets, including cancellations, and specifying the categories of information to be provided.

It further describes the Commission's role in establishing, publishing and maintaining a machine-readable list of certified wallets in the Official Journal, the process for Member States to request removal from that list, the duty to supply updated information, and the timeline for the Commission to update the list and to adopt implementing acts on formats and procedures.

By 21 November 2024, the Commission shall establish the formats and procedures applicable for the purposes of paragraphs 1, 4 and 5 of this Article by means of implementing acts on the implementation of European Digital Identity Wallets as referred to in Article 5a(23).

Cited: Art. 5d, v2

text before / after

inserted text (02014R0910-20240520)

Article 5d
Publication of a list of certified European Digital Identity Wallets
1. Member States shall inform the Commission and the Cooperation Group established pursuant to Article 46e(1) without undue delay of European Digital Identity Wallets that have been provided pursuant to Article 5a and certified by the conformity assessment bodies referred to in Article 5c(1). They shall inform the Commission and the Cooperation Group established pursuant to Article 46e(1), without undue delay if a certification is cancelled and shall state the reasons for the cancellation.
2. Without prejudice to Article 5a(18), the information provided by Member States referred to in paragraph 1 of this Article shall include at least:
(a) the certificate and certification assessment report of the certified European Digital Identity Wallet;
(b) a description of the electronic identification scheme under which the European Digital Identity Wallet is provided;
(c) the applicable supervisory regime and information on the liability regime with respect to the party providing the European Digital Identity Wallet;
(d) the authority or authorities responsible for the electronic identification scheme;
(e) arrangements for suspension or revocation of the electronic identification scheme or authentication or of the compromised parts concerned.
3. On the basis of the information received pursuant to paragraph 1, the Commission shall establish, publish in the Official Journal of the European Union and maintain in a machine-readable form a list of certified European Digital Identity Wallets.
4. A Member State may submit a request to the Commission to remove a European Digital Identity Wallet and the electronic identification scheme under which it is provided from the list referred to in paragraph 3.
5. Where there are changes to the information provided pursuant to paragraph 1, the Member State shall provide the Commission with updated information.
6. The Commission shall keep the list referred to in paragraph 3 updated by publishing in the Official Journal of the European Union the corresponding amendments to the list within one month of receipt of a request pursuant to paragraph 4 or of updated information pursuant to paragraph 5.
7. By 21 November 2024, the Commission shall establish the formats and procedures applicable for the purposes of paragraphs 1, 4 and 5 of this Article by means of implementing acts on the implementation of European Digital Identity Wallets as referred to in Article 5a(23). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +2,383 −0 Art. 5e Security breach of European Digital Identity Wallets

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

Article 5e is a newly inserted provision setting out obligations for Member States when European Digital Identity Wallets, their validation mechanisms, or the underlying electronic identification scheme are breached or partly compromised, including suspension, withdrawal, notification, re-establishment and revocation of validity.

It also directs the Commission to publish corresponding amendments to the list referred to in Article 5d and to adopt implementing acts establishing reference standards and, where necessary, specifications and procedures for the measures described.

Cited: Art. 5e, v2

text before / after

inserted text (02014R0910-20240520)

Article 5e
Security breach of European Digital Identity Wallets
1. Where European Digital Identity Wallets provided pursuant to Article 5a, the validation mechanisms referred to in Article 5a(8) or the electronic identification scheme under which the European Digital Identity Wallets are provided are breached or partly compromised in a manner that affects their reliability or the reliability of other European Digital Identity Wallets, the Member State that provided the European Digital Identity Wallets shall, without undue delay, suspend the provision and the use of European Digital Identity Wallets.
Where justified by the severity of the security breach or compromise referred to in the first subparagraph, the Member State shall withdraw European Digital Identity Wallets without undue delay.
The Member State shall inform the users affected, the single points of contact designated pursuant to Article 46c(1), the relying parties and the Commission accordingly.
2. If the security breach or compromise referred to in paragraph 1, first subparagraph, of this Article is not remedied within three months of the suspension, the Member State that provided the European Digital Identity Wallets shall withdraw European Digital Identity Wallets and revoke their validity. The Member State shall inform the users affected, the single points of contact designated pursuant to Article 46c(1), the relying parties and the Commission of the withdrawal accordingly.
3. Where the security breach or compromise referred to in paragraph 1, first subparagraph, of this Article is remedied, the providing Member State shall re-establish the provision and the use of European Digital Identity Wallets and inform the affected users and relying parties, the single points of contact designated pursuant to Article 46c(1) and the Commission without undue delay.
4. The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list referred to in Article 5d without undue delay.
5. By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the measures referred to in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +2,894 −0 Art. 5f Cross-border reliance on European Digital Identity Wallets

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is a newly inserted article setting out obligations for public sector bodies, certain private relying parties, and providers of very large online platforms to accept European Digital Identity Wallets under specified conditions.

It also directs the Commission to work with Member States on codes of conduct to support the availability and usability of the Wallets, and to assess demand, availability and usability within a stated period after deployment.

Cited: Art. 5f, v2

text before / after

inserted text (02014R0910-20240520)

Article 5f
Cross-border reliance on European Digital Identity Wallets
1. Where Member States require electronic identification and authentication to access an online service provided by a public sector body, they shall also accept European Digital Identity Wallets that are provided in accordance with this Regulation.
2. Where private relying parties that provide services, with the exception of microenterprises and small enterprises as defined in Article 2 of the Annex to Commission Recommendation 2003/361/ECCommission Recommendation 2003/361/EC of 6 May 2003concerning the definition of micro, small and medium-sized enterprises (OJ L 124, 20.5.2003, p. 36)., are required by Union or national law to use strong user authentication for online identification or where strong user authentication for online identification is required by contractual obligation, including in the areas of transport, energy, banking, financial services, social security, health, drinking water, postal services, digital infrastructure, education or telecommunications, those private relying parties shall, no later than 36 months from the date of entry into force of the implementing acts referred to in Article 5a(23) and Article 5c(6) and only upon the voluntary request of the user, also accept European Digital Identity Wallets that are provided in accordance with this Regulation.
3. Where providers of very large online platforms as referred to in Article 33 of Regulation (EU) 2022/2065 of the European Parliament and of the CouncilRegulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) (OJ L 277, 27.10.2022, p. 1). require user authentication for access to online services, they shall also accept and facilitate the use of European Digital Identity Wallets that are provided in accordance with this Regulation for user authentication only upon the voluntary request of the user and in respect of the minimum data necessary for the specific online service for which authentication is requested.
4. In cooperation with Member States, the Commission shall facilitate the development of codes of conduct in close collaboration with all relevant stakeholders, including civil society, in order to contribute to the wide availability and usability of European Digital Identity Wallets within the scope of this Regulation, and to encourage service providers to complete the development of codes of conduct.
5. Within 24 months after deployment of the European Digital Identity Wallets, the Commission shall assess the demand for, and the availability and usability of, European Digital Identity Wallets, taking into account criteria such as user take-up, cross-border presence of service providers, technological developments, evolution in usage patterns and consumer demand.

MODIFIED ±0 Art. 6

applies from: unknown

Sources disagree — the amending act's instructions found this change; the text comparison finds no difference in the provision's text and the EU's own amendment metadata does not list it. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

MODIFIED +40 −50 Art. 7 Eligibility for notification of electronic identification schemes

applies from: unchanged

Point (g) now refers to the description being provided under the procedural arrangements established by implementing acts adopted pursuant to Article 12(6), whereas the earlier version referred to Article 12(7) for that purpose.

The wording was also tightened slightly, changing phrasing such as "prior to the notification" to "prior to notification" and "for the purposes of the obligation under Article 12(5)" to "for the purposes of Article 12(5)", without altering the substance of the obligation described.

Cited: Art. 7, v1 · Art. 7, v2

text before / after

32014R091002014R0910-20240520

Article 7 Eligibility for notification of electronic identification schemes An electronic identification scheme shall be eligible for notification pursuant to Article 9(1) provided that all of the following conditions are met: (a) the electronic identification means under the electronic identification scheme are issued: (i) by the notifying Member State; (ii) under a mandate from the notifying Member State; or (iii) independently of the notifying Member State and are recognised by that Member State; (b) the electronic identification means under the electronic identification scheme can be used to access at least one service which is provided by a public sector body and which requires electronic identification in the notifying Member State; (c) the electronic identification scheme and the electronic identification means issued thereunder meet the requirements of at least one of the assurance levels set out in the implementing act referred to in Article 8(3); (d) the notifying Member State ensures that the person identification data uniquely representing the person in question is attributed, in accordance with the technical specifications, standards and procedures for the relevant assurance level set out in the implementing act referred to in Article 8(3), to the natural or legal person referred to in point 1 of Article 3 at the time the electronic identification means under that scheme is issued; (e) the party issuing the electronic identification means under that scheme ensures that the electronic identification means is attributed to the person referred to in point (d) of this Article in accordance with the technical specifications, standards and procedures for the relevant assurance level set out in the implementing act referred to in Article 8(3); (f) the notifying Member State ensures the availability of authentication online, so that any relying party established in the territory of another Member State is able to confirm the person identification data received in electronic form. For relying parties other than public sector bodies the notifying Member State may define terms of access to that authentication. The cross-border authentication shall be provided free of charge when it is carried out in relation to a service online provided by a public sector body. Member States shall not impose any specific disproportionate technical requirements on relying parties intending to carry out such authentication, where such requirements prevent or significantly impede the interoperability of the notified electronic identification schemes; (g) at least six months prior to the notification pursuant to Article 9(1), the notifying Member State provides the other Member States States, for the purposes of the obligation under Article 12(5) 12(5), with a description of that scheme in accordance with the procedural arrangements established by the implementing acts referred adopted pursuant to in Article 12(7); 12(6); (h) the electronic identification scheme meets the requirements set out in the implementing act referred to in Article 12(8).

MODIFIED +6 −38 Art. 8 Assurance levels of electronic identification schemes

applies from: unchanged

The only change in Article 8(3) is the removal of the closing phrase referencing paragraph 1 as the purpose for which the minimum technical specifications, standards and procedures are set out.

Cited: Art. 8, v1 · Art. 8, v2

text before / after

32014R091002014R0910-20240520

Article 8 Assurance levels of electronic identification schemes 1. An electronic identification scheme notified pursuant to Article 9(1) shall specify assurance levels low, substantial and/or high for electronic identification means issued under that scheme. 2. The assurance levels low, substantial and high shall meet respectively the following criteria: (a) assurance level low shall refer to an electronic identification means in the context of an electronic identification scheme, which provides a limited degree of confidence in the claimed or asserted identity of a person, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease the risk of misuse or alteration of the identity; (b) assurance level substantial shall refer to an electronic identification means in the context of an electronic identification scheme, which provides a substantial degree of confidence in the claimed or asserted identity of a person, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease substantially the risk of misuse or alteration of the identity; (c) assurance level high shall refer to an electronic identification means in the context of an electronic identification scheme, which provides a higher degree of confidence in the claimed or asserted identity of a person than electronic identification means with the assurance level substantial, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to prevent misuse or alteration of the identity. 3. By 18 September 2015, taking into account relevant international standards and subject to paragraph 2, the Commission shall, by means of implementing acts, set out minimum technical specifications, standards and procedures with reference to which assurance levels low, substantial and high are specified for electronic identification means for the purposes of paragraph 1. means. Those minimum technical specifications, standards and procedures shall be set out by reference to the reliability and quality of the following elements: (a) the procedure to prove and verify the identity of natural or legal persons applying for the issuance of electronic identification means; (b) the procedure for the issuance of the requested electronic identification means; (c) the authentication mechanism, through which the natural or legal person uses the electronic identification means to confirm its identity to a relying party; (d) the entity issuing the electronic identification means; (e) any other body involved in the application for the issuance of the electronic identification means; and (f) the technical and security specifications of the issued electronic identification means. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +78 −248 Art. 9 Notification

applies from: unchanged

Paragraph 2 no longer ties publication of the list of notified electronic identification schemes to a date one year after the application of the implementing acts referred to in Articles 8(3) and 12(8), and instead requires the Commission to publish that list without undue delay.

Paragraph 3 removes the earlier condition limiting its rule to notifications received after expiry of the period in paragraph 2, and shortens the time given to the Commission to publish amendments to the list from two months to one month from receipt of a notification.

Cited: Art. 9, v1 · Art. 9, v2

text before / after

32014R091002014R0910-20240520

Article 9 Notification 1. The notifying Member State shall notify to the Commission the following information and, without undue delay, any subsequent changes thereto: (a) a description of the electronic identification scheme, including its assurance levels and the issuer or issuers of electronic identification means under the scheme; (b) the applicable supervisory regime and information on the liability regime with respect to the following: (i) the party issuing the electronic identification means; and (ii) the party operating the authentication procedure; (c) the authority or authorities responsible for the electronic identification scheme; (d) information on the entity or entities which manage the registration of the unique person identification data; (e) a description of how the requirements set out in the implementing acts referred to in Article 12(8) are met; (f) a description of the authentication referred to in point (f) of Article 7; (g) arrangements for suspension or revocation of either the notified electronic identification scheme or authentication or the compromised parts concerned. 2. One year from the date of application of the implementing acts referred to in Articles 8(3) and 12(8), the The Commission shall shall, without undue delay, publish in the Official Journal of the European Union a list of the electronic identification schemes which were notified pursuant to paragraph 1 of this Article and the together with basic information thereon. about those schemes. 3. If the The Commission receives a notification after the expiry of the period referred to in paragraph 2, it shall publish in the Official Journal of the European Union the amendments to the list referred to in paragraph 2 within two months from one month of the date of receipt of that notification. 4. A Member State may submit to the Commission a request to remove an electronic identification scheme notified by that Member State from the list referred to in paragraph 2. The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list within one month from the date of receipt of the Member State’s request. 5. The Commission may, by means of implementing acts, define the circumstances, formats and procedures of notifications under paragraph 1. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +36 −0 Art. 10 Security breach of electronic identification schemes

applies from: unchanged

The article heading changed from "Security breach" to "Security breach of electronic identification schemes", while the operative text of paragraphs 1 through 3 remains the same.

Cited: Art. 10, v1 · Art. 10, v2

text before / after

32014R091002014R0910-20240520

Article 10 Security breach of electronic identification schemes 1. Where either the electronic identification scheme notified pursuant to Article 9(1) or the authentication referred to in point (f) of Article 7 is breached or partly compromised in a manner that affects the reliability of the cross-border authentication of that scheme, the notifying Member State shall, without delay, suspend or revoke that cross-border authentication or the compromised parts concerned, and shall inform other Member States and the Commission. 2. When the breach or compromise referred to in paragraph 1 is remedied, the notifying Member State shall re-establish the cross-border authentication and shall inform other Member States and the Commission without undue delay. 3. If the breach or compromise referred to in paragraph 1 is not remedied within three months of the suspension or revocation, the notifying Member State shall notify other Member States and the Commission of the withdrawal of the electronic identification scheme. The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list referred to in Article 9(2) without undue delay.

INSERTED +816 −0 Art. 11a Cross-border identity matching

applies from: unknown (an inserted provision states its own application date only in prose)

A new Article 11a is added, requiring Member States acting as relying parties for cross-border services to ensure unequivocal identity matching for natural persons using notified electronic identification means or European Digital Identity Wallets.

It also requires Member States to put in place technical and organisational measures protecting personal data used for identity matching and preventing profiling of users, and it directs the Commission to establish a list of reference standards and, where necessary, specifications and procedures by implementing acts under the examination procedure of Article 48(2).

By 21 November 2024, the Commission shall establish a list of reference standards and, where necessary, establish specifications and procedures for the requirements referred to in paragraph 1 of this Article by means of implementing acts.

Cited: Art. 11a, v2

text before / after

inserted text (02014R0910-20240520)

Article 11a
Cross-border identity matching
1. When acting as relying parties for cross-border services, Member States shall ensure unequivocal identity matching for natural persons using notified electronic identification means or European Digital Identity Wallets.
2. Member States shall provide for technical and organisational measures to ensure a high level of protection of personal data used for identity matching and to prevent the profiling of users.
3. By 21 November 2024, the Commission shall establish a list of reference standards and, where necessary, establish specifications and procedures for the requirements referred to in paragraph 1 of this Article by means of implementing acts. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +776 −849 Art. 12 Interoperability

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-03-18, 2025-09-18 · dates removed: 2015-09-18

The article's heading is shortened from "Cooperation and interoperability" to "Interoperability", and the privacy-by-design criterion in paragraph 3 is reworded to refer to privacy and security by design.

Paragraph 4's description of the minimum set of person identification data is expanded to also cover a natural person representing another natural person or a legal person, and paragraphs 5 and 6, which previously listed cooperation and security duties for Member States, are replaced with a duty for Member States to carry out peer reviews of notified schemes and a new deadline of 18 March 2025 for the Commission to adopt implementing acts on procedural arrangements for those peer reviews.

Paragraph 8's deadline for the Commission to adopt implementing acts on the interoperability framework is changed from 18 September 2015 to 18 September 2025, and that paragraph now also states directly that such implementing acts shall be adopted under the examination procedure referred to in Article 48(2).

Cited: Art. 12, v1 · Art. 12, v2

text before / after

32014R091002014R0910-20240520

Article 12 Cooperation and interoperability Interoperability 1. The national electronic identification schemes notified pursuant to Article 9(1) shall be interoperable. 2. For the purposes of paragraph 1, an interoperability framework shall be established. 3. The interoperability framework shall meet the following criteria: (a) it aims to be technology neutral and does not discriminate between any specific national technical solutions for electronic identification within a Member State; (b) it follows European and international standards, where possible; (c) it facilitates the implementation of the principle of privacy and security by design; and design. (d) it ensures that personal data is processed in accordance with Directive 95/46/EC. 4. The interoperability framework shall consist of: (a) a reference to minimum technical requirements related to the assurance levels under Article 8; (b) a mapping of national assurance levels of notified electronic identification schemes to the assurance levels under Article 8; (c) a reference to minimum technical requirements for interoperability; (d) a reference to a minimum set of person identification data necessary to uniquely representing represent a natural or legal person, or a natural person representing another natural person or a legal person, which is available from electronic identification schemes; (e) rules of procedure; (f) arrangements for dispute resolution; and (g) common operational security standards. 5. Member States shall cooperate with regard to the following: (a) the interoperability carry out peer reviews of the electronic identification schemes that fall within the scope of this Regulation and that are to be notified pursuant to Article 9(1) 9(1), point (a). 6. By 18 March 2025, the Commission shall, by means of implementing acts, establish the necessary procedural arrangements for the peer reviews referred to in paragraph 5 of this Article with a view to fostering a high level of trust and security appropriate to the electronic identification schemes which Member States intend degree of risk. Those implementing acts shall be adopted in accordance with the examination procedure referred to notify; and (b) the security of the electronic identification schemes. 6. The cooperation between Member States shall consist of: (a) the exchange of information, experience and good practice as regards electronic identification schemes and in particular technical requirements related to interoperability and assurance levels; (b) the exchange of information, experience and good practice as regards working with assurance levels of electronic identification schemes under Article 8; (c) peer review of electronic identification schemes falling under this Regulation; and (d) examination of relevant developments in the electronic identification sector. 48(2). 7. By 18 March 2015, the Commission shall, by means of implementing acts, establish the necessary procedural arrangements to facilitate the cooperation between the Member States referred to in paragraphs 5 and 6 with a view to fostering a high level of trust and security appropriate to the degree of risk. 8. By 18 September 2015, 2025, for the purpose of setting uniform conditions for the implementation of the requirement under paragraph 1, 1 of this Article, the Commission shall, subject to the criteria set out in paragraph 3 of this Article and taking into account the results of the cooperation between Member States, adopt implementing acts on the interoperability framework as set out in paragraph 4. 4 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2). 9. The implementing acts referred to in paragraphs 7 and 8 of this Article shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +1,943 −0 Art. 12a Certification of electronic identification schemes

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is a newly inserted article setting out that conformity of notified electronic identification schemes with the Regulation's cybersecurity requirements, including those tied to assurance levels under Article 8(2), is to be certified by conformity assessment bodies designated by Member States.

The new text specifies that such certification is carried out under a cybersecurity certification scheme under Regulation (EU) 2019/881, is valid for up to five years subject to biennial vulnerability assessments with cancellation if a vulnerability is not remedied within three months, allows Member States to request additional information, exempts certified schemes from the peer review process referred to in Article 12(5), and requires Member States to communicate the names and addresses of the relevant conformity assessment bodies to the Commission.

Cited: Art. 12a, v2

text before / after

inserted text (02014R0910-20240520)

Article 12a
Certification of electronic identification schemes
1. The conformity of electronic identification schemes to be notified with the cybersecurity requirements laid down in this Regulation, including conformity with the cybersecurity relevant requirements set out in Article 8(2) regarding the assurance levels of electronic identification schemes, shall be certified by conformity assessment bodies designated by Member States.
2. Certification pursuant to paragraph 1 of this Article shall be carried out under a relevant cybersecurity certification scheme pursuant to Regulation (EU) 2019/881 or parts thereof, insofar as the cybersecurity certificate or parts thereof cover those cybersecurity requirements.
3. Certification pursuant to paragraph 1 shall be valid for up to five years, provided that a vulnerability assessment is carried out every two years. Where a vulnerability is identified and not remedied within three months of such identification, certification shall be cancelled.
4. Notwithstanding paragraph 2, Member States may request, in accordance with that paragraph, additional information from a notifying Member State about electronic identification schemes or part thereof certified.
5. The peer review of electronic identification schemes referred to in Article 12(5) shall not apply to electronic identification schemes or parts of such schemes certified in accordance with paragraph 1 of this Article. Member States may use a certificate or a statement of conformity, issued in accordance with a relevant certification scheme or parts of such schemes, with the non-cybersecurity-related requirements set out in Article 8(2) regarding the assurance level of electronic identification schemes.
6. Member States shall communicate to the Commission the names and addresses of the conformity assessment bodies referred to in paragraph 1. The Commission shall make that information available to all Member States.

INSERTED +1,395 −0 Art. 12b Access to hardware and software features

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

Article 12b is a new provision addressing access to hardware and software features for providers of European Digital Identity Wallets and issuers of notified electronic identification means that use core platform services covered by the Digital Markets Act.

It states that gatekeepers must allow such providers and issuers, when they qualify as business users under that Regulation, effective interoperability with, and access to, the same operating system, hardware or software features, free of charge and regardless of whether those features are part of the gatekeeper's own operating system or are used by the gatekeeper, referencing Article 6(7) of Regulation (EU) 2022/1925.

The text also states that this Article applies without prejudice to Article 5a(14) of the same Regulation.

Cited: Art. 12b, v2

text before / after

inserted text (02014R0910-20240520)

Article 12b
Access to hardware and software features
Where providers of European Digital Identity Wallets and issuers of notified electronic identification means that act in a commercial or professional capacity and use core platform services as defined in Article 2, point (2), of Regulation (EU) 2022/1925 of the European Parliament and of the CouncilRegulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) (OJ L 265, 12.10.2022, p. 1). for the purpose or in the course of providing European Digital Identity Wallet services and electronic identification means to end-users are business users as defined in Article 2, point (21), of that Regulation, gatekeepers shall in particular allow them effective interoperability with, and, for the purposes of interoperability, access to, the same operating system, hardware or software features. Such effective interoperability and access shall be allowed free of charge and regardless of whether the hardware or software features are part of the operating system, are available to, or are used by, that gatekeeper when providing such services, within the meaning of Article 6(7) of Regulation (EU) 2022/1925. This Article is without prejudice to Article 5a(14) of this Regulation.

MODIFIED +322 −19 Art. 13 Liability and burden of proof

applies from: unchanged

The opening phrase of paragraph 1 changes from a plain reference to paragraph 2 into a wording that says the article applies notwithstanding paragraph 2 and without prejudice to Regulation (EU) 2016/679, whereas the earlier text referred only to paragraph 2 with no mention of that Regulation.

Paragraph 1 also gains a new sentence stating that any natural or legal person who has suffered material or non-material damage from an infringement of the Regulation by a trust service provider has the right to seek compensation in accordance with Union and national law, a sentence absent from the earlier text.

The second subparagraph is reworded slightly, now referring to proving the intention or negligence rather than proving intention or negligence, with no other change to that sentence.

Cited: Art. 13, v1 · Art. 13, v2

text before / after

32014R091002014R0910-20240520

Article 13 Liability and burden of proof 1. Without Notwithstanding paragraph 2 of this Article and without prejudice to paragraph 2, Regulation (EU) 2016/679, trust service providers shall be liable for damage caused intentionally or negligently to any natural or legal person due to a failure to comply with the obligations under this Regulation. Any natural or legal person who has suffered material or non-material damage as a result of an infringement of this Regulation by a trust service provider shall have the right to seek compensation in accordance with Union and national law. The burden of proving the intention or negligence of a non-qualified trust service provider shall lie with the natural or legal person claiming the damage referred to in the first subparagraph. The intention or negligence of a qualified trust service provider shall be presumed unless that qualified trust service provider proves that the damage referred to in the first subparagraph occurred without the intention or negligence of that qualified trust service provider. 2. Where trust service providers duly inform their customers in advance of the limitations on the use of the services they provide and where those limitations are recognisable to third parties, trust service providers shall not be liable for damages arising from the use of services exceeding the indicated limitations. 3. Paragraphs 1 and 2 shall be applied in accordance with national rules on liability.

MODIFIED +573 −138 Art. 14 International aspects

applies from: unchanged

The provision now extends to trust services provided by an international organisation, not only by third-country providers, and recognition can occur through implementing acts adopted under the examination procedure in Article 48(2), in addition to an agreement concluded under Article 218 TFEU.

Paragraph 2 is reworded to state that the requirements applicable to qualified trust service providers established in the Union must be met by the trust service providers in the third country or international organisation concerned, and adds a requirement that third countries and international organisations establish, maintain and publish a trusted list of recognised trust service providers.

The former point (b) of paragraph 2 is moved into a new paragraph 3, restating that qualified trust services from Union providers are recognised as legally equivalent to those from the third country or international organisation party to the agreement.

Cited: Art. 14, v1 · Art. 14, v2

text before / after

32014R091002014R0910-20240520

Article 14 International aspects 1. Trust services provided by trust service providers established in a third country or by an international organisation shall be recognised as legally equivalent to qualified trust services provided by qualified trust service providers established in the Union Union, where the trust services originating from the third country or from the international organisation are recognised under by means of implementing acts or an agreement concluded between the Union and the third country in question or an the international organisation pursuant to Article 218 TFEU. The implementing acts referred to in the first subparagraph shall be adopted in accordance with the examination procedure referred to in Article 218 TFEU. 48(2). 2. Agreements The implementing acts and the agreement referred to in paragraph 1 shall ensure, in particular, that: (a) ensure that the requirements applicable to qualified trust service providers established in the Union and the qualified trust services they provide are met by the trust service providers in the third country concerned or by the international organisations with which the agreement is concluded, organisation and by the trust services they provide; (b) provide. Third countries and international organisations shall in particular establish, maintain and publish a trusted list of recognised trust service providers. 3. The agreement referred to in paragraph 1 shall ensure that the qualified trust services provided by qualified trust service providers established in the Union are recognised as legally equivalent to trust services provided by trust service providers in the third country or by the international organisation with which the agreement is concluded.

MODIFIED +415 −50 Art. 15 Accessibility for persons with disabilities and special needs

applies from: unchanged

Sources disagree — the text comparison and the EU's own amendment metadata found this change; the amending act's instructions do not mention it. All are shown; none is overruled.

The heading now adds a reference to special needs alongside persons with disabilities.

The operative sentence changes from a feasibility-qualified accessibility requirement for trust services and end-user products to a requirement that electronic identification means, trust services and end-user products be made available in plain and intelligible language, referencing the United Nations Convention on the Rights of Persons with Disabilities and the accessibility requirements of Directive (EU) 2019/882, and mentioning benefit to persons with functional limitations, elderly people, and persons with limited access to digital technologies.

Cited: Art. 15, v2 · Art. 15, v1

text before / after

texts differ too much for an inline diff; shown separately

before (32014R0910)

Article 15
Accessibility for persons with disabilities
Where feasible, trust services provided and end-user products used in the provision of those services shall be made accessible for persons with disabilities.

after (02014R0910-20240520)

Article 15
Accessibility for persons with disabilities and special needs
The provision of electronic identification means, trust services and end-user products that are used in the provision of those services shall be made available in plain and intelligible language, in accordance with the United Nations Convention on the Rights of Persons with Disabilities and with the accessibility requirements of Directive (EU) 2019/882, thus also benefiting persons who experience functional limitations, such as elderly people, and persons with limited access to digital technologies.

MODIFIED +1,390 −15 Art. 16 Penalties

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2022-12-14

Sources disagree — the text comparison and the EU's own amendment metadata found this change; the amending act's instructions do not mention it. All are shown; none is overruled.

The single sentence on penalties in the earlier text is replaced by a numbered structure with three paragraphs, the first stating that Member States shall lay down penalty rules without prejudice to Article 31 of Directive (EU) 2022/2555, the second setting minimum maximum administrative fine amounts for qualified and non-qualified trust service providers, and the third addressing how fines may be initiated and imposed under national legal systems.

The earlier text contained no reference to Directive (EU) 2022/2555, no fine amounts, and no provision on the division of roles between supervisory bodies and courts, all of which appear only in the later text.

Cited: Art. 16, v2 · Art. 16, v1

text before / after

texts differ too much for an inline diff; shown separately

before (32014R0910)

Article 16
Penalties
Member States shall lay down the rules on penalties applicable to infringements of this Regulation. The penalties provided for shall be effective, proportionate and dissuasive.

after (02014R0910-20240520)

Article 16
Penalties
1. Without prejudice to Article 31 of Directive (EU) 2022/2555 of the European Parliament and of the CouncilDirective (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80)., Member States shall lay down the rules on penalties applicable to infringements of this Regulation. Those penalties shall be effective, proportionate and dissuasive.
2. Member States shall ensure that infringements of this Regulation by qualified and non-qualified trust service providers be subject to administrative fines of a maximum of at least:
(a) EUR 5000000 where the trust service provider is a natural person; or
(b) where the trust service provider is a legal person, EUR 5000000 or 1 % of the total worldwide annual turnover of the undertaking to which the trust service provider belonged in the financial year preceding the year in which the infringement occurred, whichever is higher.
3. Depending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fine is initiated by the competent supervisory body and imposed by competent national courts. The application of such rules in those Member States shall ensure that those legal remedies are effective and have an equivalent effect to administrative fines imposed directly by supervisory authorities.

DELETED ±0 Art. 17

applies from: unknown

Sources disagree — the EU's own amendment metadata and the amending act's instructions found this change; the text comparison finds no difference in the provision's text. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

DELETED ±0 Art. 18

applies from: unknown

Sources disagree — the EU's own amendment metadata found this change; the text comparison finds no difference in the provision's text and the amending act's instructions do not mention it. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

INSERTED +1,681 −0 Art. 19a Requirements for non-qualified trust service providers

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is a new article setting out obligations for non-qualified trust service providers, including maintaining policies to manage risks around registration, onboarding, procedural checks and management of trust services, and notifying supervisory bodies, affected individuals, the public where relevant, and other competent authorities of significant security breaches or disruptions within 24 hours of becoming aware of them.

It also directs the Commission to adopt implementing acts establishing reference standards and, where needed, specifications and procedures for the risk-management requirement, with compliance presumed where those standards are met.

Cited: Art. 19a, v2

text before / after

inserted text (02014R0910-20240520)

Article 19a
Requirements for non-qualified trust service providers
1. A non-qualified trust service provider providing non-qualified trust services shall:
(a) have appropriate policies and take corresponding measures to manage legal, business, operational and other direct or indirect risks to the provision of the non-qualified trust service, which shall, notwithstanding Article 21 of Directive (EU) 2022/2555, include at least measures relating to:
(i) registration and onboarding procedures for a trust service;
(ii) procedural or administrative checks needed to provide trust services;
(iii) the management and implementation of trust services;
(b) notifying the supervisory body, the identifiable affected individuals, the public if it is of public interest and, where applicable, other relevant competent authorities, of any security breaches or disruptions in the provision of the service or the implementation of the measures referred to in point (a) (i), (ii) or (iii), that have a significant impact on the trust service provided or on the personal data maintained therein, without undue delay and in any case no later than 24 hours of having become aware of any security breaches or disruptions.
2. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for paragraph 1, point (a), of this Article. Compliance with the requirements laid down in this Article shall be presumed where those standards, specifications and procedures are met. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +2,462 −402 Art. 20 Supervision of qualified trust service providers

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

Paragraph 1 now ties the audit's confirmation to Article 21 of Directive (EU) 2022/2555 as well as the Regulation itself, and new paragraphs 1a and 1b add a duty to notify the supervisory body a month before planned audits, allow it to observe, and require Member States to notify the Commission of conformity assessment bodies' details.

Paragraph 2's data-breach notification now names the competent supervisory authorities under Article 51 of Regulation (EU) 2016/679 rather than generic data protection authorities, and paragraph 3 rewrites the remedy and withdrawal process while new paragraphs 3a, 3b and 3c add withdrawal triggers linked to notices from authorities under Directive (EU) 2022/2555 and Regulation (EU) 2016/679 and expand who the supervisory body must inform after a withdrawal.

Paragraph 4 now sets a deadline of 21 May 2025 for the Commission's implementing acts, changes the earlier reference to 'reference number of...standards' into establishing a list of reference standards with specifications and procedures, and adds a new point (c) on conformity assessment schemes alongside reworded points (a) and (b).

Cited: Art. 20, v2 · Art. 20, v1

text before / after

32014R091002014R0910-20240520

Article 20 Supervision of qualified trust service providers 1. Qualified trust service providers shall be audited at their own expense at least every 24 months by a conformity assessment body. The purpose of the audit shall be to confirm that the qualified trust service providers and the qualified trust services provided by them fulfil the requirements laid down in this Regulation. The qualified Regulation and in Article 21 of Directive (EU) 2022/2555. Qualified trust service providers shall submit the resulting conformity assessment report to the supervisory body within the period of three working days after receiving it. of receipt. 1a. Qualified trust service providers shall inform the supervisory body at the latest one month before any planned audits and shall allow the supervisory body to participate as an observer upon request. 1b. Member States shall, without undue delay, notify to the Commission the names, addresses and accreditation details of the conformity assessment bodies referred to in paragraph 1 and any subsequent changes thereto. The Commission shall make that information available to all Member States. 2. Without prejudice to paragraph 1, the supervisory body may at any time audit or request a conformity assessment body to perform a conformity assessment of the qualified trust service providers, at the expense of those trust service providers, to confirm that they and the qualified trust services provided by them fulfil the requirements laid down in this Regulation. Where personal data protection rules appear to have been breached, the supervisory body shall shall, without undue delay, inform the data protection competent supervisory authorities established pursuant to Article 51 of the results of its audits. Regulation (EU) 2016/679. 3. Where the supervisory body requires the qualified trust service provider to remedy any failure fails to fulfil any of the requirements under set out by this Regulation and where Regulation, the supervisory body shall require it to provide a remedy within a set time limit, if applicable. Where that provider does not act accordingly, and if provide a remedy and, where applicable within a the time limit set by the supervisory body, the supervisory body, taking into account, where justified in particular, particular by the extent, duration and consequences of that failure, may shall withdraw the qualified status of that provider or of the affected service it provides and inform provides. 3a. Where the competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 informs the supervisory body referred that the qualified trust service provider fails to fulfil any of the requirements set out in Article 22(3) for 21 of that Directive, the purposes supervisory body, where justified in particular by the extent, duration and consequences of updating that failure, shall withdraw the trusted lists referred qualified status of that provider or of the affected service that it provides. 3b. Where the supervisory authorities established pursuant to Article 51 of Regulation (EU) 2016/679 informs the supervisory body that the qualified trust service provider fails to fulfil any of the requirements set out in Article 22(1). that Regulation, the supervisory body, where justified in particular by the extent, duration and consequences of that failure, shall withdraw the qualified status of that provider or of the affected service it provides. 3c. The supervisory body shall inform the qualified trust service provider of the withdrawal of its qualified status or of the qualified status of the service concerned. The supervisory body shall inform the body notified pursuant to Article 22(3) of this Regulation for the purposes of updating the trusted lists referred to in paragraph 1 of that Article and the competent authority designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555. 4. The By 21 May 2025, the Commission may, shall, by means of implementing acts, establish a list of reference number of standards and, where necessary, establish specifications and procedures for the following standards: following: (a) the accreditation of the conformity assessment bodies and for the conformity assessment report referred to in paragraph 1; (b) the auditing rules under which requirements for the conformity assessment bodies will to carry out their conformity assessment, including composite assessment, of the qualified trust service providers as referred to in paragraph 1; (c) the conformity assessment schemes for carrying out the conformity assessment of the qualified trust service providers as by the conformity assessment bodies and for the provision of the report referred to in paragraph 1. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +977 −146 Art. 21 Initiation of a qualified trust service

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

The notification requirement in paragraph 1 no longer refers to providers 'without qualified status' and now requires the conformity assessment report to confirm fulfilment of requirements laid down both in this Regulation and in Article 21 of Directive (EU) 2022/2555.

Paragraph 2 adds a new procedure requiring the supervisory body to ask competent authorities designated under Article 8(1) of that Directive to carry out supervisory actions and report within two months, with a duty on those authorities to explain delays, before restating the three-month qualified-status determination and delay-notification rules that appeared before.

Paragraph 4 now sets a deadline of 21 May 2025 for the Commission to establish, rather than merely define, the formats and procedures of notification and verification by implementing acts.

Cited: Art. 21, v2 · Art. 21, v1

text before / after

32014R091002014R0910-20240520

Article 21 Initiation of a qualified trust service 1. Where trust service providers, without qualified status, providers intend to start providing a qualified trust services, service, they shall submit to notify the supervisory body a notification of their intention together with a conformity assessment report issued by a conformity assessment body. body confirming the fulfilment of the requirements laid down in this Regulation and in Article 21 of Directive (EU) 2022/2555. 2. The supervisory body shall verify whether the trust service provider and the trust services provided by it comply with the requirements laid down in this Regulation, and Regulation and, in particular, with the requirements for qualified trust service providers and for the qualified trust services they provide. In order to verify the compliance of the trust service provider with the requirements laid down in Article 21 of Directive (EU) 2022/2555, the supervisory body shall request the competent authorities designated or established pursuant to Article 8(1) of that Directive to carry out supervisory actions in that regard and to provide information about the outcome without undue delay and in any event within two months of receipt of that request. If the verification is not concluded within two months of the notification, those competent authorities shall inform the supervisory body specifying the reasons for the delay and the period within which the verification is to be concluded. Where the supervisory body concludes that the trust service provider and the trust services provided by it comply with the requirements referred to laid down in the first subparagraph, this Regulation, the supervisory body shall grant qualified status to the trust service provider and the trust services it provides and inform the body referred to in Article 22(3) for the purposes of updating the trusted lists referred to in Article 22(1), not later than three months after notification in accordance with paragraph 1 of this Article. If Where the verification is not concluded within three months of notification, the supervisory body shall inform the trust service provider specifying the reasons for the delay and the period within which the verification is to be concluded. 3. Qualified trust service providers may begin to provide the qualified trust service after the qualified status has been indicated in the trusted lists referred to in Article 22(1). 4. The By 21 May 2025, the Commission may, shall, by means of implementing acts, define establish the formats and procedures of the notification and verification for the purpose purposes of paragraphs 1 and 2. 2 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +4,571 −846 Art. 24 Requirements for qualified trust service providers

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

The identity and attribute verification requirement now covers qualified electronic attestations of attributes as well as qualified certificates, and the single verification method previously set out in paragraph 1 has been split into separate new paragraphs 1a, 1b and 1c covering identity verification, attribute verification, and Commission implementing acts on standards, respectively, with references to the European Digital Identity Wallet and assurance level high replacing the prior list of methods.

Paragraph 2 adds new obligations on notification timing before changes or cessation of service, on managing operational risks and notifying security breaches (new points fa and fb), broadens the anti-forgery point to cover misappropriation and unauthorised deletion or alteration of data, and updates the termination-plan cross-reference from Article 17(4) to Article 46b(4), while adding a new subparagraph on supervisory body requests for further information and timelines for verifying notified changes.

New paragraphs 4a and 4b extend the revocation-information rules to qualified electronic attestations of attributes and empower the Commission to adopt delegated acts on additional risk-management measures, and paragraph 5 is rewritten to require the Commission, by 21 May 2025, to establish standards, specifications and procedures for the paragraph 2 requirements rather than merely reference numbers of standards for points (e) and (f).

Cited: Art. 24, v1 · Art. 24, v2

text before / after

32014R091002014R0910-20240520

Article 24 Requirements for qualified trust service providers 1. When issuing a qualified certificate for or a trust service, qualified electronic attestation of attributes, a qualified trust service provider shall verify, by appropriate means and in accordance with national law, verify the identity and, if applicable, any specific attributes of the natural or legal person to whom the qualified certificate or the qualified electronic attestation of attributes is to be issued. 1a. The information verification of the identity referred to in the first subparagraph paragraph 1 shall be verified performed, by appropriate means, by the qualified trust service provider provider, either directly or by relying means of a third party, on the basis of one of the following methods or, when needed, on a third party combination thereof in accordance with national law: the implementing acts referred to in paragraph 1c: (a) by means of the European Digital Identity Wallet or a notified electronic identification means which meets the requirements set out in Article 8 with regard to assurance level high; (b) by means of a certificate of a qualified electronic signature or of a qualified electronic seal, issued in compliance with point (a), (c) or (d); (c) by using other identification methods which ensure the identification of the person with a high level of confidence, the conformity of which shall be confirmed by a conformity assessment body; (d) through the physical presence of the natural person or of an authorised representative of the legal person; person, by means of appropriate evidence and procedures, in accordance with national law. 1b. The verification of the attributes referred to in paragraph 1 shall be performed, by appropriate means, by the qualified trust service provider, either directly or (b) remotely, using by means of a third party, on the basis of one of the following methods or, where necessary, on a combination thereof, in accordance with the implementing acts referred to in paragraph 1c: (a) by means of the European Digital Identity Wallet or a notified electronic identification means, for which prior to the issuance of the qualified certificate, a physical presence of the natural person or of an authorised representative of the legal person was ensured and means which meets the requirements set out in Article 8 with regard to the assurance levels substantial or level high; or (c) (b) by means of a certificate of a qualified electronic signature or of a qualified electronic seal seal, issued in compliance accordance with paragraph 1a, point (a) (a), (c) or (b); or (d); (c) by means of a qualified electronic attestation of attributes; (d) by using other identification methods recognised at national methods, which ensure the verification of the attributes with a high level of confidence, the conformity of which provide equivalent assurance in terms of reliability to physical presence. The equivalent assurance shall be confirmed by a conformity assessment body. body; (e) by means of the physical presence of the natural person or of an authorised representative of the legal person, by means of appropriate evidence and procedures, in accordance with national law. 1c. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the verification of identity and attributes in accordance with paragraphs 1, 1a and 1b of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2). 2. A qualified trust service provider providing qualified trust services shall: (a) inform the supervisory body of at least one month before implementing any change in the provision of its qualified trust services and or at least three months in case of an intention to cease those activities; (b) employ staff and, if applicable, subcontractors who possess the necessary expertise, reliability, experience, and qualifications and who have received appropriate training regarding security and personal data protection rules and shall apply administrative and management procedures which correspond to European or international standards; (c) with regard to the risk of liability for damages in accordance with Article 13, maintain sufficient financial resources and/or obtain appropriate liability insurance, in accordance with national law; (d) before entering into a contractual relationship, inform, in a clear clear, comprehensive and comprehensive easily accessible manner, in a publicly accessible space and individually any person seeking to use a qualified trust service of the precise terms and conditions regarding the use of that service, including any limitations on its use; (e) use trustworthy systems and products that are protected against modification and ensure the technical security and reliability of the processes supported by them; them, including using suitable cryptographic techniques; (f) use trustworthy systems to store data provided to it, in a verifiable form so that: (i) they are publicly available for retrieval only where the consent of the person to whom the data relates has been obtained, (ii) only authorised persons can make entries and changes to the stored data, (iii) the data can be checked for authenticity; (fa) notwithstanding Article 21 of Directive (EU) 2022/2555, have appropriate policies and take corresponding measures to manage legal, business, operational and other direct or indirect risks to the provision of the qualified trust service, including at least measures related to the following: (i) registration and onboarding procedures for a service; (ii) procedural or administrative checks; (iii) the management and implementation of services; (fb) notify the supervisory body, the identifiable affected individuals, other relevant competent bodies where applicable and, at the request of the supervisory body, the public if it is of public interest, of any security breaches or disruptions in the provision of the service or the implementation of the measures referred to in point (fa)(i), (ii) or (iii) that have a significant impact on the trust service provided or on the personal data maintained therein, without undue delay and in any event within 24 hours of the incident; (g) take appropriate measures against forgery and forgery, theft or misappropriation of data; data or, without right, deleting, altering or rendering data inaccessible; (h) record and keep accessible for an appropriate period of time, including as long as necessary after the activities of the qualified trust service provider have ceased, all relevant information concerning data issued and received by the qualified trust service provider, in particular, for the purpose of providing evidence in legal proceedings and for the purpose of ensuring continuity of the service. Such recording may be done electronically; (i) have an up-to-date termination plan to ensure the continuity of service in accordance with provisions that are verified by the supervisory body under pursuant to Article 46b(4), point (i) of Article 17(4); (i); (j) ensure lawful processing of personal data in accordance with Directive 95/46/EC; (k) in case of qualified trust service providers issuing qualified certificates, establish and keep updated a certificate database. The supervisory body may request information in addition to the information notified pursuant to point (a) of the first subparagraph or the result of a conformity assessment and may condition the granting of the permission to implement the intended changes to the qualified trust services. If the verification is not concluded within three months of notification, the supervisory body shall inform the trust service provider, specifying the reasons for the delay and the period within which the verification is to be concluded. 3. If a qualified trust service provider issuing qualified certificates decides to revoke a certificate, it shall register such revocation in its certificate database and publish the revocation status of the certificate in a timely manner, and in any event within 24 hours after the receipt of the request. The revocation shall become effective immediately upon its publication. 4. With regard to paragraph 3, qualified trust service providers issuing qualified certificates shall provide to any relying party information on the validity or revocation status of qualified certificates issued by them. This information shall be made available at least on a per certificate basis at any time and beyond the validity period of the certificate in an automated manner that is reliable, free of charge and efficient. 5. 4a. Paragraphs 3 and 4 shall apply accordingly to the revocation of qualified electronic attestations of attributes. 4b. The Commission may, shall be empowered to adopt delegated acts in accordance with Article 47, establishing additional measures referred to in paragraph 2, point (fa), of this Article. 5. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference numbers of standards and, where necessary, establish specifications and procedures for trustworthy systems and products, which comply with the requirements under points (e) and (f) of referred to in paragraph 2 of this Article. Compliance with the requirements laid down in this Article paragraph shall be presumed where trustworthy systems those standards, specifications and products meet those standards. procedures are met. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +3,101 −0 Art. 24a Recognition of qualified trust services

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

A new Article 24a establishes cross-border recognition among Member States for a range of qualified trust services, including qualified electronic signatures, seals, signature and seal creation devices, validation and preservation services, time stamps, website authentication certificates, electronic registered delivery services, electronic attestation of attributes, electronic archiving services, and electronic ledgers.

Each paragraph states that a qualified service or device issued, certified, or provided in one Member State is to be recognised as the corresponding qualified service or device in all other Member States.

Cited: Art. 24a, v2

text before / after

inserted text (02014R0910-20240520)

Article 24a
Recognition of qualified trust services
1. Qualified electronic signatures based on a qualified certificate issued in one Member State and qualified electronic seals based on a qualified certificate issued in one Member State shall be recognised, respectively, as qualified electronic signatures and qualified electronic seals in all other Member States.
2. Qualified electronic signature creation devices and qualified electronic seal creation devices certified in one Member State shall be recognised, respectively, as qualified electronic signature creation devices and qualified electronic seal creation devices in all other Member States.
3. A qualified certificate for electronic signatures, a qualified certificate for electronic seals, a qualified trust service for the management of remote qualified electronic signature creation devices and a qualified trust service for the management of remote qualified electronic seal creation devices provided in one Member State shall be recognised, respectively, as a qualified certificate for electronic signatures, a qualified certificate for electronic seals, a qualified trust service for the management of remote qualified electronic signature creation devices and a qualified trust service for the management of remote qualified electronic seal creation devices in all other Member States.
4. A qualified validation service for qualified electronic signatures and a qualified validation service for qualified electronic seals provided in one Member State shall be recognised, respectively, as a qualified validation service for qualified electronic signatures and a qualified validation service for qualified electronic seals in all other Member States.
5. A qualified preservation service for qualified electronic signatures and a qualified preservation service for qualified electronic seals provided in one Member State shall be recognised, respectively, as a qualified preservation service for qualified electronic signatures and a qualified preservation service for qualified electronic seals in all other Member States.
6. A qualified electronic time stamp provided in one Member State shall be recognised as a qualified electronic time stamp in all other Member States.
7. A qualified certificate for website authentication issued in one Member State shall be recognised as a qualified certificate for website authentication in all other Member States.
8. A qualified electronic registered delivery service provided in one Member State shall be recognised as a qualified electronic registered delivery service in all other Member States.
9. A qualified electronic attestation of attributes issued in one Member State shall be recognised as a qualified electronic attestation of attributes in all other Member States.
10. A qualified electronic archiving service provided in one Member State shall be recognised as a qualified electronic archiving service in all other Member States.
11. A qualified electronic ledger provided in one Member State shall be recognised as a qualified electronic ledger in all other Member States.

MODIFIED ±0 Art. 25

applies from: unknown

Sources disagree — the EU's own amendment metadata and the amending act's instructions found this change; the text comparison finds no difference in the provision's text. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

MODIFIED +623 −0 Art. 26 Requirements for advanced electronic signatures

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2026-05-21

Sources disagree — the text comparison and the EU's own amendment metadata found this change; the amending act's instructions do not mention it. All are shown; none is overruled.

The original list of requirements for advanced electronic signatures is now numbered as paragraph 1, with its four points unchanged.

A new paragraph 2 has been added, providing that the Commission shall by 21 May 2026 assess whether implementing acts establishing reference standards, specifications and procedures for advanced electronic signatures are necessary, may adopt such acts on that basis, and that compliance with those standards, specifications and procedures shall be presumed to meet the Article 26 requirements, with such acts to be adopted under the examination procedure referred to in Article 48(2).

Cited: Art. 26, v2

text before / after

32014R091002014R0910-20240520

Article 26 Requirements for advanced electronic signatures 1. An advanced electronic signature shall meet the following requirements: (a) it is uniquely linked to the signatory; (b) it is capable of identifying the signatory; (c) it is created using electronic signature creation data that the signatory can, with a high level of confidence, use under his sole control; and (d) it is linked to the data signed therewith in such a way that any subsequent change in the data is detectable.2. By 21 May 2026, the Commission shall assess whether it is necessary to adopt implementing acts to establish a list of reference standards and, where necessary, establish specifications and procedures for advanced electronic signatures. On the basis of that assessment, the Commission may adopt such implementing acts. Compliance with the requirements for advanced electronic signatures shall be presumed where an advanced electronic signature complies with the standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED ±0 Art. 27

applies from: unknown

Sources disagree — the EU's own amendment metadata and the amending act's instructions found this change; the text comparison finds no difference in the provision's text. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

MODIFIED +149 −32 Art. 28 Qualified certificates for electronic signatures

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

Paragraph 6 now sets a deadline of 21 May 2025 for the Commission to act by means of implementing acts, whereas the earlier text set no such deadline.

The task itself is reworded from establishing reference numbers of standards to establishing a list of reference standards and, where necessary, specifications and procedures, and compliance is now tied to meeting those standards, specifications and procedures rather than just standards.

Cited: Art. 28, v2 · Art. 28, v1

text before / after

32014R091002014R0910-20240520

Article 28 Qualified certificates for electronic signatures 1. Qualified certificates for electronic signatures shall meet the requirements laid down in Annex I. 2. Qualified certificates for electronic signatures shall not be subject to any mandatory requirement exceeding the requirements laid down in Annex I. 3. Qualified certificates for electronic signatures may include non-mandatory additional specific attributes. Those attributes shall not affect the interoperability and recognition of qualified electronic signatures. 4. If a qualified certificate for electronic signatures has been revoked after initial activation, it shall lose its validity from the moment of its revocation, and its status shall not in any circumstances be reverted. 5. Subject to the following conditions, Member States may lay down national rules on temporary suspension of a qualified certificate for electronic signature: (a) if a qualified certificate for electronic signature has been temporarily suspended that certificate shall lose its validity for the period of suspension; (b) the period of suspension shall be clearly indicated in the certificate database and the suspension status shall be visible, during the period of suspension, from the service providing information on the status of the certificate. 6. The By 21 May 2025, the Commission may, shall, by means of implementing acts, establish a list of reference numbers of standards and, where necessary, establish specifications and procedures for qualified certificates for electronic signature. Compliance with the requirements laid down in Annex I shall be presumed where a qualified certificate for electronic signature meets complies with those standards. standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +370 −0 Art. 29 Requirements for qualified electronic signature creation devices

applies from: unchanged

A new paragraph 1a has been inserted stating that generating or managing electronic signature creation data, or duplicating such data for back-up purposes, is to be carried out only on behalf of and at the request of the signatory, and only by a qualified trust service provider that provides a qualified trust service for managing a remote qualified electronic signature creation device.

Paragraphs 1 and 2 remain as they were, unchanged in wording from the earlier version.

Cited: Art. 29, v2 · Art. 29, v1

text before / after

32014R091002014R0910-20240520

Article 29 Requirements for qualified electronic signature creation devices 1. Qualified electronic signature creation devices shall meet the requirements laid down in Annex II. 1a. Generating or managing electronic signature creation data or duplicating such signature creation data for back-up purposes shall be carried out only on behalf of the signatory, at the request of the signatory, and by a qualified trust service provider providing a qualified trust service for the management of a remote qualified electronic signature creation device. 2. The Commission may, by means of implementing acts, establish reference numbers of standards for qualified electronic signature creation devices. Compliance with the requirements laid down in Annex II shall be presumed where a qualified electronic signature creation device meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +1,270 −0 Art. 29a Requirements for a qualified service for the management of remote qualified electronic signature creation devices

applies from: unknown (an inserted provision states its own application date only in prose)

This article is newly inserted and sets out conditions that a qualified trust service provider must meet to carry out the management of remote qualified electronic signature creation devices as a qualified service, including generating or managing signature creation data on behalf of the signatory, duplicating such data only for back-up purposes under specified security and quantity limits, and complying with requirements identified in the relevant certification report.

It also directs the Commission to establish, by 21 May 2025, a list of reference standards and, where necessary, specifications and procedures for these purposes through implementing acts adopted under the examination procedure.

Cited: Art. 29a, v2

text before / after

inserted text (02014R0910-20240520)

Article 29a
Requirements for a qualified service for the management of remote qualified electronic signature creation devices
1. The management of remote qualified electronic signature creation devices as a qualified service shall be carried out only by a qualified trust service provider that:
(a) generates or manages electronic signature creation data on behalf of the signatory;
(b) notwithstanding point (1)(d) of Annex II, duplicates the electronic signature creation data for back-up purposes only, provided that the following requirements are met:
(i) the security of the duplicated datasets must be at the same level as for the original datasets;
(ii) the number of duplicated datasets must not exceed the minimum needed to ensure continuity of the service;
(c) complies with any requirements identified in the certification report of the specific remote qualified electronic signature creation device issued pursuant to Article 30.
2. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, specifications and procedures for the purposes of paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +258 −0 Art. 30 Certification of qualified electronic signature creation devices

applies from: unchanged

A new paragraph 3a has been added, stating that the validity of a certification referred to in paragraph 1 shall not exceed five years, on condition that vulnerability assessments are carried out every two years.

The same new paragraph adds that where vulnerabilities are identified and not remedied, the certification shall be cancelled.

This paragraph 3a did not appear in the earlier version of Article 30.

Cited: Art. 30, v2 · Art. 30, v1

text before / after

32014R091002014R0910-20240520

Article 30 Certification of qualified electronic signature creation devices 1. Conformity of qualified electronic signature creation devices with the requirements laid down in Annex II shall be certified by appropriate public or private bodies designated by Member States. 2. Member States shall notify to the Commission the names and addresses of the public or private body referred to in paragraph 1. The Commission shall make that information available to Member States. 3. The certification referred to in paragraph 1 shall be based on one of the following: (a) a security evaluation process carried out in accordance with one of the standards for the security assessment of information technology products included in the list established in accordance with the second subparagraph; or (b) a process other than the process referred to in point (a), provided that it uses comparable security levels and provided that the public or private body referred to in paragraph 1 notifies that process to the Commission. That process may be used only in the absence of standards referred to in point (a) or when a security evaluation process referred to in point (a) is ongoing. The Commission shall, by means of implementing acts, establish a list of standards for the security assessment of information technology products referred to in point (a). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2). 3a The validity of a certification referred to in paragraph 1 shall not exceed five years, provided that vulnerabilities assessments are carried out every two years. Where vulnerabilities are identified and not remedied, the certification shall be cancelled. 4. The Commission shall be empowered to adopt delegated acts in accordance with Article 47 concerning the establishment of specific criteria to be met by the designated bodies referred to in paragraph 1 of this Article.

MODIFIED +56 −15 Art. 31 Publication of a list of certified qualified electronic signature creation devices

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

Paragraph 3 changes from an optional power for the Commission to define formats and procedures by implementing acts into a duty for the Commission to establish those formats and procedures by implementing acts, with a deadline of 21 May 2025 added.

The paragraph also adds the words 'of this Article' after the reference to paragraph 1.

Cited: Art. 31, v1 · Art. 31, v2

text before / after

32014R091002014R0910-20240520

Article 31 Publication of a list of certified qualified electronic signature creation devices 1. Member States shall notify to the Commission without undue delay and no later than one month after the certification is concluded, information on qualified electronic signature creation devices that have been certified by the bodies referred to in Article 30(1). They shall also notify to the Commission, without undue delay and no later than one month after the certification is cancelled, information on electronic signature creation devices that are no longer certified. 2. On the basis of the information received, the Commission shall establish, publish and maintain a list of certified qualified electronic signature creation devices. 3. The By 21 May 2025, the Commission may, shall, by means of implementing acts, define establish the formats and procedures applicable for the purpose of paragraph 1. 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +342 −171 Art. 32 Requirements for the validation of qualified electronic signatures

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

A new sentence was added at the end of paragraph 1 stating that compliance with the requirements of that paragraph's first subparagraph is presumed where validation of qualified electronic signatures complies with the standards, specifications and procedures referred to in paragraph 3.

Paragraph 3 was changed from describing the Commission's establishing of reference numbers of standards, with a presumption-of-compliance clause tied to paragraph 1, to describing the Commission's establishing of a list of reference standards and, where necessary, specifications and procedures, with a deadline of 21 May 2025 and without that presumption clause, which was moved to paragraph 1.

Cited: Art. 32, v2 · Art. 32, v1

text before / after

32014R091002014R0910-20240520

Article 32 Requirements for the validation of qualified electronic signatures 1. The process for the validation of a qualified electronic signature shall confirm the validity of a qualified electronic signature provided that: (a) the certificate that supports the signature was, at the time of signing, a qualified certificate for electronic signature complying with Annex I; (b) the qualified certificate was issued by a qualified trust service provider and was valid at the time of signing; (c) the signature validation data corresponds to the data provided to the relying party; (d) the unique set of data representing the signatory in the certificate is correctly provided to the relying party; (e) the use of any pseudonym is clearly indicated to the relying party if a pseudonym was used at the time of signing; (f) the electronic signature was created by a qualified electronic signature creation device; (g) the integrity of the signed data has not been compromised; (h) the requirements provided for in Article 26 were met at the time of signing. Compliance with the requirements laid down in the first subparagraph of this paragraph shall be presumed where the validation of qualified electronic signatures complies with the standards, specifications and procedures referred to in paragraph 3. 2. The system used for validating the qualified electronic signature shall provide to the relying party the correct result of the validation process and shall allow the relying party to detect any security relevant issues. 3. The By 21 May 2025, the Commission may, shall, by means of implementing acts, establish a list of reference numbers of standards and, where necessary, establish specifications and procedures for the validation of qualified electronic signatures. Compliance with the requirements laid down in paragraph 1 shall be presumed where the validation of qualified electronic signatures meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +1,929 −0 Art. 32a Requirements for the validation of advanced electronic signatures based on qualified certificates

applies from: unknown (an inserted provision states its own application date only in prose)

This is an entirely new article setting out conditions that must be confirmed for the validation of an advanced electronic signature based on a qualified certificate, including matters such as the certificate's qualification status at signing time, correspondence of validation data, correct provision of signatory data, indication of pseudonym use, integrity of signed data, and compliance with Article 26 requirements.

It also adds a requirement that the validation system provide the relying party with the correct validation result and allow detection of security relevant issues, and it directs the Commission to establish, by 21 May 2025, a list of reference standards and, where necessary, specifications and procedures via implementing acts, with compliance with those standards giving rise to a presumption of conformity with the listed requirements.

Cited: Art. 32a, v2

text before / after

inserted text (02014R0910-20240520)

Article 32a
Requirements for the validation of advanced electronic signatures based on qualified certificates
1. The process for the validation of an advanced electronic signature based on a qualified certificate shall confirm the validity of an advanced electronic signature based on a qualified certificate, provided that:
(a) the certificate that supports the signature was, at the time of signing, a qualified certificate for electronic signature complying with Annex I;
(b) the qualified certificate was issued by a qualified trust service provider and was valid at the time of signing;
(c) the signature validation data corresponds to the data provided to the relying party;
(d) the unique set of data representing the signatory in the certificate is correctly provided to the relying party;
(e) the use of any pseudonym is clearly indicated to the relying party if a pseudonym was used at the time of signing;
(f) the integrity of the signed data has not been compromised;
(g) the requirements provided for in Article 26 were met at the time of signing.
2. The system used for validating the advanced electronic signature based on qualified certificate shall provide to the relying party the correct result of the validation process and shall allow the relying party to detect any security relevant issues.
3. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the validation of advanced electronic signatures based on qualified certificates. Compliance with the requirements laid down in paragraph 1 of this Article shall be presumed where the validation of advanced electronic signature based on qualified certificates complies with those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +202 −45 Art. 33 Qualified validation service for qualified electronic signatures

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

Paragraph 2 now sets a deadline of 21 May 2025 by which the Commission shall act, replacing the earlier open-ended discretionary phrasing that allowed the Commission to establish reference numbers of standards at any time.

The scope of what the Commission establishes is broadened from merely reference numbers of standards to a list of reference standards plus, where necessary, specifications and procedures, and the compliance presumption is correspondingly tied to meeting those standards, specifications and procedures rather than just standards.

Cited: Art. 33, v1 · Art. 33, v2

text before / after

32014R091002014R0910-20240520

Article 33 Qualified validation service for qualified electronic signatures 1. A qualified validation service for qualified electronic signatures may only be provided by a qualified trust service provider who: (a) provides validation in compliance with Article 32(1); and (b) allows relying parties to receive the result of the validation process in an automated manner, which is reliable, efficient and bears the advanced electronic signature or advanced electronic seal of the provider of the qualified validation service. 2. The By 21 May 2025, the Commission may, shall, by means of implementing acts, establish a list of reference numbers of standards and, where necessary, establish specifications and procedures for qualified validation service referred to in paragraph 1. 1 of this Article. Compliance with the requirements laid down in paragraph 1 of this Article shall be presumed where the qualified validation service for a qualified electronic signature meets signatures complies with those standards. standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +339 −191 Art. 34 Qualified preservation service for qualified electronic signatures

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

The presumption of compliance previously stated in paragraph 2 has been moved into a new paragraph 1a, which now ties that presumption to compliance with standards, specifications and procedures referred to in paragraph 2 rather than only to standards.

Paragraph 2 itself now requires the Commission to establish, by 21 May 2025, a list of reference standards and, where necessary, specifications and procedures, instead of simply allowing it to establish reference numbers of standards for the qualified preservation service.

Cited: Art. 34, v1 · Art. 34, v2

text before / after

32014R091002014R0910-20240520

Article 34 Qualified preservation service for qualified electronic signatures 1. A qualified preservation service for qualified electronic signatures may only be provided by a qualified trust service provider that uses procedures and technologies capable of extending the trustworthiness of the qualified electronic signature beyond the technological validity period. 2. The Commission may, by means of implementing acts, establish reference numbers of standards for the qualified preservation service for qualified electronic signatures. 1a. Compliance with the requirements laid down in paragraph 1 shall be presumed where the arrangements for the qualified preservation service for qualified electronic signatures meet those standards. complies with the standards, specifications and procedures referred to in paragraph 2. 2. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the qualified preservation service for qualified electronic signatures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED ±0 Art. 35

applies from: unknown

Sources disagree — the EU's own amendment metadata and the amending act's instructions found this change; the text comparison finds no difference in the provision's text. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

MODIFIED +610 −0 Art. 36 Requirements for advanced electronic seals

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2026-05-21

The list of requirements for advanced electronic seals is now numbered as paragraph 1, whereas before it stood as unnumbered introductory text.

A new paragraph 2 is added requiring the Commission to assess by 21 May 2026 whether implementing acts are needed to set a list of reference standards and, where necessary, specifications and procedures for advanced electronic seals, with compliance with such standards presumed to satisfy the requirements, and providing that any such implementing acts be adopted under the examination procedure referred to in Article 48(2).

Cited: Art. 36, v1 · Art. 36, v2

text before / after

32014R091002014R0910-20240520

Article 36 Requirements for advanced electronic seals 1. An advanced electronic seal shall meet the following requirements: (a) it is uniquely linked to the creator of the seal; (b) it is capable of identifying the creator of the seal; (c) it is created using electronic seal creation data that the creator of the seal can, with a high level of confidence under its control, use for electronic seal creation; and (d) it is linked to the data to which it relates in such a way that any subsequent change in the data is detectable.2. By 21 May 2026, the Commission shall assess whether it is necessary to adopt implementing acts to establish a list of reference standards and, where necessary, establish specifications and procedures for advanced electronic seals. On the basis of that assessment, the Commission may adopt such implementing acts. Compliance with the requirements for advanced electronic seals shall be presumed where an advanced electronic seal complies with those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED ±0 Art. 37

applies from: unknown

Sources disagree — the EU's own amendment metadata and the amending act's instructions found this change; the text comparison finds no difference in the provision's text. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

MODIFIED +149 −32 Art. 38 Qualified certificates for electronic seals

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

Paragraph 6 now requires the Commission to act by 21 May 2025, whereas the earlier version set no deadline for establishing reference numbers of standards.

The provision also changes the substance of what the Commission is to establish, from reference numbers of standards to a list of reference standards and, where necessary, specifications and procedures.

The compliance-presumption sentence is correspondingly reworded so that meeting standards is replaced by complying with standards, specifications and procedures.

Cited: Art. 38, v1 · Art. 38, v2

text before / after

32014R091002014R0910-20240520

Article 38 Qualified certificates for electronic seals 1. Qualified certificates for electronic seals shall meet the requirements laid down in Annex III. 2. Qualified certificates for electronic seals shall not be subject to any mandatory requirements exceeding the requirements laid down in Annex III. 3. Qualified certificates for electronic seals may include non-mandatory additional specific attributes. Those attributes shall not affect the interoperability and recognition of qualified electronic seals. 4. If a qualified certificate for an electronic seal has been revoked after initial activation, it shall lose its validity from the moment of its revocation, and its status shall not in any circumstances be reverted. 5. Subject to the following conditions, Member States may lay down national rules on temporary suspension of qualified certificates for electronic seals: (a) if a qualified certificate for electronic seal has been temporarily suspended, that certificate shall lose its validity for the period of suspension; (b) the period of suspension shall be clearly indicated in the certificate database and the suspension status shall be visible, during the period of suspension, from the service providing information on the status of the certificate. 6. The By 21 May 2025, the Commission may, shall, by means of implementing acts, establish a list of reference numbers of standards and, where necessary, establish specifications and procedures for qualified certificates for electronic seals. Compliance with the requirements laid down in Annex III shall be presumed where a qualified certificate for electronic seal meets complies with those standards. standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +257 −0 Art. 39a Requirements for a qualified service for the management of remote qualified electronic seal creation devices

applies from: unknown (an inserted provision states its own application date only in prose)

This provision is newly added and states that Article 29a applies mutatis mutandis to a qualified service for the management of remote qualified electronic seal creation devices.

Cited: Art. 39a, v2

text before / after

inserted text (02014R0910-20240520)

Article 39a
Requirements for a qualified service for the management of remote qualified electronic seal creation devices
Article 29a shall apply mutatis mutandis to a qualified service for the management of remote qualified electronic seal creation devices.

INSERTED +225 −0 Art. 40a Requirements for the validation of advanced electronic seals based on qualified certificates

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

A new Article 40a has been added, setting out requirements for validating advanced electronic seals based on qualified certificates.

The new article states that Article 32a applies mutatis mutandis to this validation process.

Cited: Art. 40a, v2

text before / after

inserted text (02014R0910-20240520)

Article 40a
Requirements for the validation of advanced electronic seals based on qualified certificates
Article 32a shall apply mutatis mutandis to the validation of advanced electronic seals based on qualified certificates.

MODIFIED ±0 Art. 41

applies from: unknown

Sources disagree — the EU's own amendment metadata and the amending act's instructions found this change; the text comparison finds no difference in the provision's text. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

MODIFIED +368 −196 Art. 42 Requirements for qualified electronic time stamps

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

A new paragraph 1a now states the presumption of compliance with paragraph 1, tying it to standards, specifications and procedures referred to in paragraph 2, whereas before this presumption was stated directly within paragraph 2 itself.

Paragraph 2 now requires the Commission to act by 21 May 2025 and to establish a list of reference standards and, where necessary, specifications and procedures for binding date and time to data and for establishing the accuracy of time sources, replacing the earlier wording that referred only to establishing reference numbers of standards for binding date and time to data and for accurate time sources without a deadline.

Cited: Art. 42, v2 · Art. 42, v1

text before / after

32014R091002014R0910-20240520

Article 42 Requirements for qualified electronic time stamps 1. A qualified electronic time stamp shall meet the following requirements: (a) it binds the date and time to data in such a manner as to reasonably preclude the possibility of the data being changed undetectably; (b) it is based on an accurate time source linked to Coordinated Universal Time; and (c) it is signed using an advanced electronic signature or sealed with an advanced electronic seal of the qualified trust service provider, or by some equivalent method. 2. The Commission may, by means of implementing acts, establish reference numbers of standards for the binding of date and time to data and for accurate time sources. 1a. Compliance with the requirements laid down in paragraph 1 shall be presumed where the binding of date and time to data and the accurate accuracy of the time source meets those standards. comply with the standards, specifications and procedures referred to in paragraph 2. 2. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the binding of date and time to data and for establishing the accuracy of time sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +1,095 −162 Art. 44 Requirements for qualified electronic registered delivery services

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

A new paragraph 1a has been added stating that compliance with paragraph 1's requirements is presumed where the sending and receiving process complies with the standards, specifications and procedures referred to in paragraph 2, moving this presumption language out of paragraph 2 itself.

Paragraph 2 has been rewritten to set a deadline of 21 May 2025 for the Commission to establish, by implementing acts, a list of reference standards and, where necessary, specifications and procedures for sending and receiving data, replacing the earlier open-ended reference to establishing reference numbers of standards.

Two new paragraphs, 2a and 2b, have been added covering interoperability agreements between providers of qualified electronic registered delivery services, conformity assessment of such interoperability frameworks against paragraph 1's requirements, and the Commission's power to adopt implementing acts establishing reference standards, specifications and procedures for that interoperability framework, with a requirement that technical specifications be cost-effective and proportionate.

Cited: Art. 44, v2

text before / after

32014R091002014R0910-20240520

Article 44 Requirements for qualified electronic registered delivery services 1. Qualified electronic registered delivery services shall meet the following requirements: (a) they are provided by one or more qualified trust service provider(s); (b) they ensure with a high level of confidence the identification of the sender; (c) they ensure the identification of the addressee before the delivery of the data; (d) the sending and receiving of data is secured by an advanced electronic signature or an advanced electronic seal of a qualified trust service provider in such a manner as to preclude the possibility of the data being changed undetectably; (e) any change of the data needed for the purpose of sending or receiving the data is clearly indicated to the sender and addressee of the data; (f) the date and time of sending, receiving and any change of data are indicated by a qualified electronic time stamp. In the event of the data being transferred between two or more qualified trust service providers, the requirements in points (a) to (f) shall apply to all the qualified trust service providers. 2. The Commission may, by means of implementing acts, establish reference numbers of standards for processes for sending and receiving data. 1a. Compliance with the requirements laid down in paragraph 1 shall be presumed where the process for sending and receiving data meets those standards. complies with the standards, specifications and procedures referred to in paragraph 2. 2. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for processes for sending and receiving data. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).2a. Providers of qualified electronic registered delivery services may agree on interoperability between qualified electronic registered delivery services which they provide. Such interoperability framework shall comply with the requirements laid down in paragraph 1 and such compliance shall be confirmed by a conformity assessment body. 2b. The Commission may, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the interoperability framework referred to in paragraph 2a of this Article. The technical specifications and content of standards shall be cost-effective and proportionate. The implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +1,188 −181 Art. 45 Requirements for qualified certificates for website authentication

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

The text now specifies that compliance with the Annex IV requirements for qualified certificates for website authentication is evaluated according to standards, specifications and procedures referred to in paragraph 2, rather than relying solely on Annex IV.

Two new paragraphs, 1a and 1b, were added: one requiring providers of web-browsers to recognise such qualified certificates, display identity data and additional attested attributes in a user-friendly manner, and ensure support and interoperability (with an exception for microenterprises and small enterprises during their first five years of operation), and the other stating that such certificates shall not be subject to mandatory requirements other than those in paragraph 1.

Paragraph 2 was changed from allowing the Commission to establish reference numbers of standards, to requiring the Commission, by 21 May 2025, to establish a list of reference standards and, where necessary, specifications and procedures.

Cited: Art. 45, v2 · Art. 45, v1

text before / after

texts differ too much for an inline diff; shown separately

before (32014R0910)

Article 45
Requirements for qualified certificates for website authentication
1. Qualified certificates for website authentication shall meet the requirements laid down in Annex IV.
2. The Commission may, by means of implementing acts, establish reference numbers of standards for qualified certificates for website authentication. Compliance with the requirements laid down in Annex IV shall be presumed where a qualified certificate for website authentication meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

after (02014R0910-20240520)

Article 45
Requirements for qualified certificates for website authentication
1. Qualified certificates for website authentication shall meet the requirements laid down in Annex IV. The evaluation of compliance with those requirements shall be carried out in accordance with the standards, specifications and procedures referred to in paragraph 2 of this Article.
1a. Qualified certificates for website authentication issued in accordance with paragraph 1 of this Article shall be recognised by providers of web-browsers. Providers of web-browsers shall ensure that the identity data attested in the certificate and additional attested attributes are displayed in a user-friendly manner. Providers of web-browsers shall ensure support and interoperability with qualified certificates for website authentication referred to in paragraph 1 of this Article, with the exception of microenterprises or small enterprises as defined in Article 2 of the Annex to Recommendation 2003/361/EC during the first five years of operating as providers of web-browsing services.
1b. Qualified certificates for website authentication shall not be subject to any mandatory requirements other than the requirements laid down in paragraph 1.
2. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for qualified certificates for website authentication, referred to in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +1,695 −0 Art. 45a Cybersecurity precautionary measures

applies from: unknown (an inserted provision states its own application date only in prose)

A new Article 45a is added setting out cybersecurity precautionary measures for providers of web-browsers in relation to Article 45 obligations, including the circumstances under which such providers may take precautionary measures regarding a certificate, the notification duties owed to the Commission, the competent supervisory body, the certificate holder and the issuing qualified trust service provider, and the supervisory body's role in investigating and responding to such notifications.

Cited: Art. 45a, v2

text before / after

inserted text (02014R0910-20240520)

Article 45a
Cybersecurity precautionary measures
1. Providers of web-browsers shall not take any measures contrary to their obligations set out in Article 45, in particular the requirements to recognise qualified certificates for website authentication and to display the identity data provided in a user-friendly manner.
2. By way of derogation from paragraph 1 and only in the event of substantiated concerns related to security breaches or the loss of integrity of an identified certificate or set of certificates, providers of web-browsers may take precautionary measures in relation to that certificate or set of certificates.
3. Where a provider of a web-browser takes precautionary measures pursuant to paragraph 2, the provider of the web-browser shall notify its concerns in writing, without undue delay, together with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory body, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory body shall issue an acknowledgement of receipt to the provider of the web-browser in question.
4. The competent supervisory body shall investigate the issues raised in the notification in accordance with Article 46b(4), point (k). Where the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate, the supervisory body shall inform the provider of the web-browser accordingly and shall request that provider to put an end to the precautionary measures referred to in paragraph 2 of this Article.

INSERTED +875 −0 Art. 45b Legal effects of electronic attestation of attributes

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

A new Article 45b is added that addresses electronic attestation of attributes, stating that such attestations shall not be denied legal effect or admissibility as evidence solely because they are electronic or do not meet the requirements for qualified electronic attestations of attributes.

The new article further states that a qualified electronic attestation of attributes, and attestations issued by or on behalf of a public sector body responsible for an authentic source, shall have the same legal effect as lawfully issued paper attestations, and that an attestation issued by or on behalf of such a body in one Member State shall be recognised as such an attestation in all Member States.

Cited: Art. 45b, v2

text before / after

inserted text (02014R0910-20240520)

Article 45b
Legal effects of electronic attestation of attributes
1. An electronic attestation of attributes shall not be denied legal effect or admissibility as evidence in legal proceedings on the sole ground that it is in electronic form or that it does not meet the requirements for qualified electronic attestations of attributes.
2. A qualified electronic attestation of attributes and attestations of attributes issued by, or on behalf of, a public sector body responsible for an authentic source shall have the same legal effect as lawfully issued attestations in paper form.
3. An attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source in one Member State shall be recognised as an attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source in all Member States.

INSERTED +624 −0 Art. 45c Electronic attestation of attributes in public services

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

A new Article 45c is added, stating that where national law requires electronic identification using an electronic identification means and authentication to access a public sector body's online service, person identification data in an electronic attestation of attributes cannot substitute for that electronic identification and authentication unless a Member State specifically allows it.

The new provision further states that when a Member State does allow such use, qualified electronic attestations of attributes issued by other Member States must also be accepted.

Cited: Art. 45c, v2

text before / after

inserted text (02014R0910-20240520)

Article 45c
Electronic attestation of attributes in public services
Where an electronic identification using an electronic identification means and authentication is required under national law to access an online service provided by a public sector body, person identification data in the electronic attestation of attributes shall not substitute electronic identification using an electronic identification means and authentication for electronic identification unless specifically allowed by the Member State. In such a case, qualified electronic attestation of attributes from other Member States shall also be accepted.

INSERTED +1,246 −0 Art. 45d Requirements for qualified electronic attestation of attributes

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is a newly inserted provision setting requirements for qualified electronic attestation of attributes, covering compliance with Annex V, the evaluation of that compliance, a bar on additional mandatory requirements, the effect of revocation on validity, and a Commission mandate to adopt implementing acts establishing reference standards, specifications and procedures.

The text itself states that the Commission is to adopt those implementing acts by 21 November 2024.

By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for qualified electronic attestations of attributes.

Cited: Art. 45d, v2

text before / after

inserted text (02014R0910-20240520)

Article 45d
Requirements for qualified electronic attestation of attributes
1. Qualified electronic attestation of attributes shall meet the requirements laid down in Annex V.
2. The evaluation of compliance with the requirements laid down in Annex V shall be carried out in accordance with the standards, specifications and procedures referred to in paragraph 5 of this Article.
3. Qualified electronic attestations of attributes shall not be subject to any mandatory requirement in addition to the requirements laid down in Annex V.
4. Where a qualified electronic attestation of attributes has been revoked after initial issuance, it shall lose its validity from the moment of its revocation and its status shall not in any circumstances be reverted.
5. By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for qualified electronic attestations of attributes. Those implementing acts shall be consistent with the implementing acts referred to in Article 5a(23) on the implementation of the European Digital Identity Wallet. They shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +1,272 −0 Art. 45e Verification of attributes against authentic sources

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is a new article requiring Member States to ensure that, within 24 months of the entry into force of the implementing acts referred to in Articles 5a(23) and 5c(6), measures are taken so that qualified trust service providers of electronic attestations of attributes can verify at least the attributes listed in Annex VI against authentic sources in the public sector, at the request of the user, in accordance with Union or national law.

It also requires the Commission, by 21 November 2024, to adopt implementing acts establishing a list of reference standards and, where necessary, specifications and procedures for the attribute catalogue, attestation schemes, and verification procedures, consistent with the implementing acts on the European Digital Identity Wallet under Article 5a(23) and adopted under the examination procedure of Article 48(2).

Cited: Art. 45e, v2

text before / after

inserted text (02014R0910-20240520)

Article 45e
Verification of attributes against authentic sources
1. Member States shall ensure, within 24 months of the date of entry into force of the implementing acts referred to in Articles 5a(23) and 5c(6), that, at least for the attributes listed in Annex VI, wherever those attributes rely on authentic sources within the public sector, measures are taken to allow qualified trust service providers of electronic attestations of attributes to verify those attributes by electronic means at the request of the user, in accordance with Union or national law.
2. By 21 November 2024, the Commission shall, taking into account relevant international standards, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the catalogue of attributes, as well as schemes for the attestation of attributes and verification procedures for qualified electronic attestations of attributes for the purposes of paragraph 1 of this Article. Those implementing acts shall be consistent with the implementing acts referred to in Article 5a(23) on the implementation of the European Digital Identity Wallet. They shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +3,807 −0 Art. 45f Requirements for electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

A new Article 45f sets out requirements that an electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source must meet, including compliance with Annex VII and specific content in the supporting qualified certificate.

The new article also addresses the reliability of issuing public sector bodies, their notification to the Commission with a conformity assessment report, publication of the list of such bodies, effects of revocation, deemed compliance through reference standards, Commission implementing acts with deadlines, and an interface requirement with European Digital Identity Wallets.

Cited: Art. 45f, v2

text before / after

inserted text (02014R0910-20240520)

Article 45f
Requirements for electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source
1. An electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source shall meet the following requirements:
(a) those set out in Annex VII;
(b) the qualified certificate supporting the qualified electronic signature or qualified electronic seal of the public sector body referred to in Article 3, point (46), identified as the issuer referred to in point (b), of Annex VII, containing a specific set of certified attributes in a form suitable for automated processing and:
(i) indicating that the issuing body is established in accordance with Union or national law as the responsible for the authentic source on the basis of which the electronic attestation of attributes is issued or as the body designated to act on its behalf;
(ii) providing a set of data unambiguously representing the authentic source referred to in point (i); and
(iii) identifying the Union or national law referred to in point (i).
2. The Member State where public sector bodies referred to in Article 3, point (46), are established shall ensure that the public sector bodies that issue electronic attestations of attributes meet a level of reliability and trustworthiness equivalent to qualified trust service providers in accordance with Article 24.
3. Member States shall notify public sector bodies referred to in Article 3, point (46), to the Commission. That notification shall include a conformity assessment report issued by a conformity assessment body confirming that the requirements set out in paragraphs 1, 2 and 6 of this Article are met. The Commission shall make available to the public, through a secure channel, the list of public sector bodies referred to in Article 3, point (46), in electronically signed or sealed form suitable for automated processing.
4. Where an electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source has been revoked after initial issuance, it shall lose its validity from the moment of its revocation and its status shall not be reverted.
5. An electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source shall be deemed to be compliant with the requirements laid down in paragraph 1, where it complies with the standards, specifications and procedures referred to in paragraph 6.
6. By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source. Those implementing acts shall be consistent with the implementing acts referred to in Article 5a(23) on the implementation of the European Digital Identity Wallet. They shall be adopted in accordance with the examination procedure referred to in Article 48(2).
7. By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the purposes of paragraph 3 of this Article. Those implementing acts shall be consistent with the implementing acts referred to in Article 5a(23) on the implementation of the European Digital Identity Wallet. They shall be adopted in accordance with the examination procedure referred to in Article 48(2).
8. Public sector bodies referred to in Article 3, point (46), issuing electronic attestation of attributes shall provide an interface with European Digital Identity Wallets that are provided in accordance with Article 5a.

INSERTED +568 −0 Art. 45g Issuing of electronic attestation of attributes to European Digital Identity Wallets

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

Article 45g is a new provision requiring providers of electronic attestations of attributes to let European Digital Identity Wallet users request, obtain, store and manage such attestations regardless of the Member State providing the wallet.

It further states that providers of qualified electronic attestations of attributes are to provide an interface with European Digital Identity Wallets provided in accordance with Article 5a.

Cited: Art. 45g, v2

text before / after

inserted text (02014R0910-20240520)

Article 45g
Issuing of electronic attestation of attributes to European Digital Identity Wallets
1. Providers of electronic attestations of attributes shall provide European Digital Identity Wallet users with the possibility to request, obtain, store and manage the electronic attestation of attributes irrespective of the Member State where the European Digital Identity Wallet is provided.
2. Providers of qualified electronic attestations of attributes shall provide an interface with European Digital Identity Wallets that are provided in accordance in Article 5a.

INSERTED +769 −0 Art. 45h Additional rules for the provision of electronic attestation of attributes services

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is a newly inserted article setting out rules for providers of qualified and non-qualified electronic attestation of attributes services, requiring that personal data tied to those services not be combined with personal data from other services offered by the provider or its commercial partners.

It further states that such personal data must be kept logically separate from other data held by the provider, and that providers of qualified electronic attestation of attributes services must provide those trust services in a manner that is functionally separate from their other services.

Cited: Art. 45h, v2

text before / after

inserted text (02014R0910-20240520)

Article 45h
Additional rules for the provision of electronic attestation of attributes services
1. Providers of qualified and non-qualified electronic attestation of attributes services shall not combine personal data relating to the provision of those services with personal data from any other services offered by them or their commercial partners.
2. Personal data relating to the provision of electronic attestation of attributes services shall be kept logically separate from other data held by the provider of electronic attestation of attributes.
3. Providers of qualified electronic attestation of attributes’ services shall implement the provision of such qualified trust services in a manner that is functionally separate from other services provided by them.

INSERTED +616 −0 Art. 45i Legal effect of electronic archiving services

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

A new Article 45i has been added establishing that electronic data and documents preserved using an electronic archiving service cannot be denied legal effect or admissibility as evidence merely because they are electronic or because the service used is not a qualified one.

The new provision also states that data and documents preserved using a qualified electronic archiving service benefit from a presumption of integrity and of origin for the duration of the preservation period by the qualified trust service provider.

Cited: Art. 45i, v2

text before / after

inserted text (02014R0910-20240520)

Article 45i
Legal effect of electronic archiving services
1. Electronic data and electronic documents preserved using an electronic archiving service shall not be denied legal effect or admissibility as evidence in legal proceedings on the sole ground that they are in electronic form or that they are not preserved using a qualified electronic archiving service.
2. Electronic data and electronic documents preserved using a qualified electronic archiving service shall enjoy the presumption of their integrity and of their origin for the duration of the preservation period by the qualified trust service provider.

INSERTED +1,851 −0 Art. 45j Requirements for qualified electronic archiving services

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

Article 45j is a new provision setting out requirements that qualified electronic archiving services must meet, covering who provides them, how durability, legibility, integrity and origin accuracy are maintained, safeguards against loss or alteration, and an automated report confirming the presumption of integrity of retrieved data.

It also requires that report to be delivered reliably and efficiently and to bear the qualified electronic signature or seal of the archiving service provider, and it directs the Commission to adopt implementing acts by 21 May 2025 establishing reference standards, specifications and procedures, compliance with which creates a presumption of conformity.

Cited: Art. 45j, v2

text before / after

inserted text (02014R0910-20240520)

Article 45j
Requirements for qualified electronic archiving services
1. Qualified electronic archive services shall meet the following requirements:
(a) they are provided by qualified trust service providers;
(b) they use procedures and technologies capable of ensuring the durability and legibility of electronic data and electronic documents beyond the technological validity period and at least throughout the legal or contractual preservation period, while maintaining their integrity and the accuracy of their origin;
(c) they ensure that those electronic data and those electronic documents are preserved in such a way that they are safeguarded against loss and alteration, except for changes concerning their medium or electronic format;
(d) they shall allow authorised relying parties to receive a report in an automated manner that confirms that electronic data and electronic documents retrieved from a qualified electronic archive enjoy the presumption of integrity of the data from the beginning of the preservation period to the moment of retrieval.
The report referred to in point (d) of the first subparagraph shall be provided in a reliable and efficient way and shall bear the qualified electronic signature or qualified electronic seal of the provider of the qualified electronic archiving service.
2. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for qualified electronic archiving services. Compliance with the requirements for qualified electronic archive services shall be presumed where a qualified electronic archive service complies with those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +459 −0 Art. 45k Legal effects of electronic ledgers

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is a newly inserted article stating that an electronic ledger cannot be denied legal effect or use as evidence in legal proceedings merely because it is electronic or fails to meet qualified electronic ledger requirements.

It also states that data records held in a qualified electronic ledger benefit from a presumption of unique, accurate, sequential chronological ordering and of integrity.

Cited: Art. 45k, v2

text before / after

inserted text (02014R0910-20240520)

Article 45k
Legal effects of electronic ledgers
1. An electronic ledger shall not be denied legal effect or admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements for qualified electronic ledgers.
2. Data records contained in a qualified electronic ledger shall enjoy the presumption of their unique and accurate sequential chronological ordering and of their integrity.

INSERTED +1,047 −0 Art. 45l Requirements for qualified electronic ledgers

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is a new article setting out requirements that qualified electronic ledgers must meet, including that they be created and managed by one or more qualified trust service providers, establish the origin of data records, ensure unique sequential chronological ordering of records, and make any subsequent change to recorded data immediately detectable.

It also provides that compliance with those requirements is presumed where a ledger complies with standards, specifications and procedures to be established by the Commission through implementing acts adopted under the examination procedure referred to in Article 48(2).

Cited: Art. 45l, v2

text before / after

inserted text (02014R0910-20240520)

Article 45l
Requirements for qualified electronic ledgers
1. Qualified electronic ledgers shall meet the following requirements:
(a) they are created and managed by one or more qualified trust service providers;
(b) they establish the origin of data records in the ledger;
(c) they ensure the unique sequential chronological ordering of data records in the ledger;
(d) they record data in such a way that any subsequent change to the data is immediately detectable, ensuring their integrity over time.
2. Compliance with the requirements laid down in paragraph 1 shall be presumed where an electronic ledger complies with the standards, specifications and procedures referred to in paragraph 3.
3. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the requirements laid down in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +4,715 −0 Art. 46a Supervision of the European Digital Identity Wallet Framework

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is a newly inserted article establishing supervision of the European Digital Identity Wallet Framework, requiring Member States to designate one or more supervisory bodies with powers and resources to oversee wallet providers, and setting out those bodies' notification duties, tasks, cooperation obligations, powers to require remedies or suspension of wallet provision, and annual reporting to the Commission.

The text also directs the Commission to adopt implementing acts establishing formats and procedures for the annual reports by a stated date.

Cited: Art. 46a, v2

text before / after

inserted text (02014R0910-20240520)

Article 46a
Supervision of the European Digital Identity Wallet Framework
1. Member States shall designate one or more supervisory bodies established in their territory.
The supervisory bodies designated pursuant to the first subparagraph shall be given the necessary powers and adequate resources for the exercise of their tasks in an effective, efficient and independent manner.
2. Member States shall notify to the Commission the names and the addresses of their supervisory bodies designated pursuant to paragraph 1 and any subsequent changes thereto. The Commission shall publish a list of the notified supervisory bodies.
3. The role of the supervisory bodies designated pursuant to paragraph 1 shall be:
(a) to supervise providers of European Digital Identity Wallets established in the designating Member State and to ensure, by means of ex ante and ex post supervisory activities, that those providers and European Digital Identity Wallets they provide meet the requirements laid down in this Regulation;
(b) to take action, if necessary, in relation to providers of European Digital Identity Wallets established in the territory of the designating Member State, by means of ex post supervisory activities, when informed that providers or European Digital Identity Wallets that they provide infringe this Regulation.
4. The tasks of the supervisory bodies designated pursuant to paragraph 1 shall include, in particular, the following:
(a) to cooperate with other supervisory bodies and to provide them with assistance in accordance with Articles 46c and 46e;
(b) to request information necessary to monitor compliance with this Regulation;
(c) to inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant security breaches or loss of integrity of which they become aware in the performance of their tasks and, in the case of a significant security breach or loss of integrity which concerns other Member States, to inform the single point of contact designated or established pursuant to Article 8(3) of Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of this Regulation in the other Member States concerned, and to inform the public or require providers of European Digital Identity Wallet to do so where the supervisory body determines that disclosure of the security breach or of the loss of integrity would be in the public interest;
(d) to carry out on-site inspections and off-site supervision;
(e) to require that providers of European Digital Identity Wallets remedy any failure to fulfil the requirements laid down in this Regulation;
(f) to suspend or cancel the registration and inclusion of relying parties in the mechanism referred to in Article 5b(7) in the case of illegal or fraudulent use of the European Digital Identity Wallet;
(g) to cooperate with competent supervisory authorities established pursuant to Article 51 of Regulation (EU) 2016/679, in particular, by informing them without undue delay, where personal data protection rules appear to have been infringed and about security breaches which appear to constitute personal data breaches.
5. Where the supervisory body designated pursuant to paragraph 1 requires the provider of a European Digital Identity Wallet to remedy any failure to fulfil requirements under this Regulation pursuant to paragraph 4, point (e), and that provider does not act accordingly and, if applicable, within a time limit set by that supervisory body, the supervisory body designated pursuant to paragraph 1 may, taking into account, in particular, the extent, duration and consequences of that failure, order the provider to suspend or to cease the provision of the European Digital Identity Wallet. The supervisory body shall inform the supervisory bodies of other Member States, the Commission, relying parties and users of the European Digital Identity Wallet without undue delay of the decision to require the suspension or cessation of the provision of the European Digital Identity Wallet.
6. By 31 March each year, each supervisory body designated pursuant to paragraph 1 shall submit to the Commission a report on its main activities in the previous calendar year. The Commission shall make those annual reports available to the European Parliament and the Council.
7. By 21 May 2025, the Commission shall, by means of implementing acts, establish the formats and procedures for the report referred to in paragraph 6 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +5,136 −0 Art. 46b Supervision of trust services

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

Article 46b is a wholly new provision setting out requirements for Member States to designate a supervisory body for trust services, defining its resourcing, notification to the Commission, role, tasks, optional trust infrastructure function, annual reporting duty, and a deadline for the Commission to adopt related guidelines and implementing acts.

It did not exist in the earlier version of the text.

Cited: Art. 46b, v2

text before / after

inserted text (02014R0910-20240520)

Article 46b
Supervision of trust services
1. Member States shall designate a supervisory body established in their territory or designate, upon mutual agreement with another Member State, a supervisory body established in that other Member State. That supervisory body shall be responsible for supervisory tasks in the designating Member State as regards trust services.
The supervisory bodies designated pursuant to the first subparagraph shall be given the necessary powers and adequate resources for the exercise of their tasks.
2. Member States shall notify to the Commission the names and addresses of their supervisory bodies designated pursuant to paragraph 1 and any subsequent changes thereto. The Commission shall publish a list of the notified supervisory bodies.
3. The role of the supervisory bodies designated pursuant to paragraph 1 shall be:
(a) to supervise qualified trust service providers established in the territory of the designating Member State and to ensure, by means of ex ante and ex post supervisory activities, that those qualified trust service providers and the qualified trust services that they provide meet the requirements laid down in this Regulation;
(b) to take action, if necessary, in relation to non-qualified trust service providers established in the territory of the designating Member State, by means of ex post supervisory activities, when informed that those non-qualified trust service providers or the trust services they provide allegedly do not meet the requirements laid down in this Regulation.
4. The tasks of the supervisory body designated pursuant to paragraph 1 shall include in particular the following:
(a) to inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant security breach or loss of integrity of which it becomes aware in the performance of its tasks and, in the case of a significant security breach or loss of integrity which concerns other Member States, to inform the single point of contact designated or established pursuant to Article 8(3) Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of this Regulation in the other Member States concerned, and to inform the public or require the trust service provider to do so where the supervisory body determines that disclosure of the breach of security or loss of integrity would be in the public interest;
(b) to cooperate with other supervisory bodies and to provide them with assistance in accordance with Articles 46c and 46e;
(c) to analyse the conformity assessment reports referred to in Article 20(1) and Article 21(1);
(d) to report to the Commission about its main activities in accordance with paragraph 6 of this Article;
(e) to carry out audits or request a conformity assessment body to perform a conformity assessment of the qualified trust service providers in accordance with Article 20(2);
(f) to cooperate with competent supervisory authorities established pursuant to Article 51 of Regulation (EU) 2016/679, in particular, by informing them, without undue delay, where personal data protection rules appear to have been breached and about security breaches which appear to constitute personal data breaches;
(g) to grant qualified status to trust service providers and to the services they provide, and to withdraw that status in accordance with Articles 20 and 21;
(h) to inform the body responsible for the national trusted list referred to in Article 22(3) of its decisions to grant or withdraw qualified status, unless that body is also the supervisory body designated pursuant to paragraph 1 of this Article;
(i) to verify the existence and correct application of provisions on termination plans where the qualified trust service provider ceases its activities, including how information is kept accessible in accordance with Article 24(2), point (h);
(j) to require that trust service providers remedy any failure to fulfil the requirements laid down in this Regulation;
(k) to investigate claims made by providers of web-browsers pursuant to Article 45a and to take action if necessary.
5. Member States may require the supervisory body designated pursuant to paragraph 1 to establish, maintain and update a trust infrastructure in accordance with national law.
6. By 31 March each year, each supervisory body designated pursuant to paragraph 1 shall submit to the Commission a report on its main activities in the previous calendar year. The Commission shall make those annual reports available to the European Parliament and the Council.
7. By 21 May 2025, the Commission shall adopt guidelines on the exercise by the supervisory bodies designated pursuant to paragraph 1 of this Article of the tasks referred to in paragraph 4 of this Article, and, by means of implementing acts, establish the formats and procedures for the report referred to in paragraph 6 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

INSERTED +937 −0 Art. 46c Single points of contact

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This provision is newly added and requires each Member State to designate a single point of contact for trust services, European Digital Identity Wallets and notified electronic identification schemes.

It sets out that this contact point liaises to facilitate cross-border cooperation among supervisory bodies and, where appropriate, with the Commission, ENISA and other national competent authorities, and requires publication and notification to the Commission of its name and address, with the Commission then publishing a list of all such contact points.

Cited: Art. 46c, v2

text before / after

inserted text (02014R0910-20240520)

Article 46c
Single points of contact
1. Each Member State shall designate a single point of contact for trust services, European Digital Identity Wallets and notified electronic identification schemes.
2. Each single point of contact shall exercise a liaison function to facilitate cross-border cooperation between the supervisory bodies for trust service providers and between the supervisory bodies for the providers of European Digital Identity Wallets and, where appropriate, with the Commission and European Union Agency for Cybersecurity (ENISA) and with other competent authorities within its Member State.
3. Each Member State shall make public and, without undue delay, notify to the Commission the names and the addresses of the single point of contact designated pursuant to paragraph 1 and any subsequent change thereto.
4. The Commission shall publish a list of the single points of contact notified pursuant to paragraph 3.

INSERTED +2,119 −0 Art. 46d Mutual assistance

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

Article 46d is a newly added provision setting out mutual assistance arrangements among supervisory bodies designated under Articles 46a and 46b, including seeking assistance through the Cooperation Group, informing and consulting one another, requesting supervisory or enforcement measures, and carrying out joint investigations.

The provision also lists grounds on which a supervisory body may refuse a request for assistance and requires the Cooperation Group to issue guidance on organisational aspects and procedures for mutual assistance by a specified date and every two years thereafter.

Cited: Art. 46d, v2

text before / after

inserted text (02014R0910-20240520)

Article 46d
Mutual assistance
1. In order to facilitate the supervision and enforcement of obligations under this Regulation, the supervisory bodies designated pursuant to Article 46a(1) and Article 46b(1) may seek, including through the Cooperation Group established pursuant to Article 46e(1), mutual assistance from the supervisory bodies of another Member State where the provider of the European Digital Identity Wallet or the trust service provider is established, or where its network and information systems are located or its services are provided.
2. The mutual assistance shall at least entail that:
(a) the supervisory body applying supervisory and enforcement measures in one Member State shall inform and consult the supervisory body from the other Member State concerned;
(b) a supervisory body may request the supervisory body of another Member State concerned to take supervisory or enforcement measures, including, for instance, requests to carry out inspections related to the conformity assessment reports as referred to in Articles 20 and 21 regarding the provision of trust services;
(c) where appropriate, supervisory bodies may carry out joint investigations with the supervisory bodies of other Member States.
The arrangements and procedures for joint actions under the first subparagraph shall be agreed upon and established by the Member States concerned in accordance with their national law.
3. A supervisory body to which a request for assistance is addressed may refuse that request on any of the following grounds:
(a) the assistance requested is not proportionate to the supervisory activities of the supervisory body carried out in accordance with Articles 46a and 46b;
(b) the supervisory body is not competent to provide the requested assistance;
(c) providing the requested assistance would be incompatible with this Regulation.
4. By 21 May 2025 and every two years thereafter, the Cooperation Group established pursuant to Article 46e(1) shall issue guidance on the organisational aspects and procedures for the mutual assistance referred to in paragraphs 1 and 2 of this Article.

INSERTED +3,755 −0 Art. 46e The European Digital Identity Cooperation Group

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

This is a newly inserted provision establishing the European Digital Identity Cooperation Group, setting out its composition, chairing arrangement, observer participation, and a list of tasks covering cooperation on digital identity wallets, electronic identification and trust services.

It also directs Member States to ensure effective cooperation of their appointed representatives and requires the Commission to adopt implementing acts establishing procedural arrangements for peer reviews of notified electronic identification schemes.

Cited: Art. 46e, v2

text before / after

inserted text (02014R0910-20240520)

Article 46e
The European Digital Identity Cooperation Group
1. In order to support and facilitate Member States’ cross-border cooperation and exchange of information on trust services, European Digital Identity Wallets and notified electronic identification schemes, the Commission shall establish a European Digital Identity Cooperation Group (the Cooperation Group).
2. The Cooperation Group shall be composed of representatives appointed by the Member States and of the Commission. The Cooperation Group shall be chaired by the Commission. The Commission shall provide the Cooperation Group’s Secretariat.
3. Representatives of relevant stakeholders may, on an ad hoc basis, be invited to attend meetings of the Cooperation Group and to participate in its work as observers.
4. ENISA shall be invited to participate as observer in the workings of the Cooperation Group when it exchanges views, best practices and information on relevant cybersecurity aspects such as notification of security breaches, and when the use of cybersecurity certificates or standards are addressed.
5. The Cooperation Group shall have the following tasks:
(a) exchange advice and cooperate with the Commission on emerging policy initiatives in the field of digital identity wallets, electronic identification means and trust services;
(b) advise the Commission, as appropriate, in the early preparation of draft implementing and delegated acts to be adopted pursuant to this Regulation;
(c) in order to support the supervisory bodies in the implementation of the provisions of this Regulation:
(i) exchange best practices and information regarding the implementation of the provisions of this Regulation;
(ii) assess the relevant developments in the digital identity wallet, electronic identification and trust services sectors;
(iii) organise joint meetings with relevant interested parties from across the Union to discuss activities carried out by the cooperation group and gather input on emerging policy challenges;
(iv) with the support of ENISA, exchange views, best practices and information on relevant cybersecurity aspects concerning European Digital Identity Wallets, electronic identification schemes and trust services;
(v) exchange best practices in relation to the development and implementation of policies on the notification of security breaches, and common measures as referred to in Articles 5e and 10;
(vi) organise joint meetings with the NIS Cooperation Group established pursuant to Article 14(1) of Directive (EU) 2022/2555 to exchange relevant information in relation to trust services and electronic identification related cyber threats, incidents, vulnerabilities, awareness raising initiatives, trainings, exercises and skills, capacity building, standards and technical specifications capacity as well as standards and technical specifications;
(vii) discuss, upon a request of a supervisory body, specific requests for mutual assistance as referred to in Article 46d;
(viii) facilitate the exchange of information between the supervisory bodies by providing guidance on the organisational aspects and procedures for the mutual assistance referred to in Article 46d;
(d) organise peer reviews of electronic identification schemes to be notified under this Regulation.
6. Member States shall ensure effective and efficient cooperation of their designated representatives in the Cooperation Group.
7. By 21 May 2025, the Commission shall, by means of implementing acts, establish the necessary procedural arrangements to facilitate the cooperation between the Member States referred to in paragraph 5, point (d), of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

MODIFIED +98 −0 Art. 47 Exercise of the delegation

applies from: unchanged

Paragraphs 2, 3 and 5 now also refer to Article 5c(7) and Article 24(4b), alongside the existing reference to Article 30(4), as sources of the delegated power being described.

In the earlier version these same paragraphs referred only to Article 30(4).

Cited: Art. 47, v2 · Art. 47, v1

text before / after

32014R091002014R0910-20240520

Article 47 Exercise of the delegation 1. The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article. 2. The power to adopt delegated acts referred to in Article 5c(7), Article 24(4b) and Article 30(4) shall be conferred on the Commission for an indeterminate period of time from 17 September 2014. 3. The delegation of power referred to in Article 5c(7), Article 24(4b) and Article 30(4) may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force. 4. As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council. 5. A delegated act adopted pursuant to Article 5c(7), Article 24(4b) or Article 30(4) shall enter into force only if no objection has been expressed either by the European Parliament or the Council within a period of two months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by two months at the initiative of the European Parliament or of the Council.

INSERTED +1,182 −0 Art. 48a Reporting requirements

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.

Article 48a is a new provision requiring Member States to collect statistics on the functioning of European Digital Identity Wallets and qualified trust services provided in their territory, covering items such as wallet holder numbers, accepting services, complaints and incidents, and security breaches.

It also requires the collected statistics to be made publicly available in an open, machine-readable format and to be submitted by Member States to the Commission in an annual report due by 31 March each year.

Cited: Art. 48a, v2

text before / after

inserted text (02014R0910-20240520)

Article 48a
Reporting requirements
1. Member States shall ensure the collection of statistics in relation to the functioning of European Digital Identity Wallets and the qualified trust services provided on their territory.
2. The statistics collected in accordance with paragraph 1 shall include the following:
(a) the number of natural and legal persons having a valid European Digital Identity Wallet;
(b) the type and number of services accepting the use of the European Digital Identity Wallet;
(c) the number of user complaints and consumer protection or data protection incidents relating to relying parties and qualified trust services;
(d) a summary report including data on incidents preventing the use of the European Digital Identity Wallet;
(e) a summary of significant security incidents, data breaches and affected users of European Digital Identity Wallets or of qualified trust services.
3. The statistics referred to in paragraph 2 shall be made available to the public in an open and commonly used, machine-readable format.
4. By 31 March each year, Member States shall submit to the Commission a report on the statistics collected in accordance with paragraph 2.

MODIFIED +756 −295 Art. 49 Review

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2026-05-21, 2030-05-21 · dates removed: 2020-07-01

The provision is now split into three numbered paragraphs, replacing the earlier unnumbered structure of three paragraphs.

The review deadline of 1 July 2020 is replaced by a reporting deadline of 21 May 2026, the list of provisions to be evaluated now refers to Article 5c(5) instead of Article 6, point (f) of Article 7 and Articles 34, 43, 44 and 45, and a new paragraph requires the report to assess availability, security and usability of notified electronic identification means and European Digital Identity Wallets, including whether online private service providers relying on third-party electronic identification services must accept them.

The recurring four-year progress report to the European Parliament and the Council is now tied to a starting date of 21 May 2030 rather than being measured from the earlier report date.

Cited: Art. 49, v1 · Art. 49, v2

text before / after

32014R091002014R0910-20240520

Article 49 Review 1. The Commission shall review the application of this Regulation and shall shall, by 21 May 2026, submit a report to the European Parliament and to the Council no later than 1 July 2020. The Council. In that report, the Commission shall shall, in particular, evaluate in particular whether it is appropriate to modify the scope of this Regulation or its specific provisions, including provisions including, in particular, the provisions included in Article 6, point (f) of Article 7 and Articles 34, 43, 44 and 45, 5c(5), taking into account the experience gained in the application of this Regulation, as well as technological, market and legal developments. Where necessary, that report shall be accompanied by a proposal to amend this Regulation. 2. The report referred to in paragraph 1 shall include an assessment of the first paragraph availability, security and usability of the notified electronic identification means and European Digital Identity Wallets that fall within the scope of this Regulation and assess whether all online private service providers relying on third-party electronic identification services for users authentication, shall be accompanied, where appropriate, by legislative proposals. In addition, required to accept the use of notified electronic identification means and European Digital Identity Wallet. 3. By 21 May 2030 and every four years thereafter, the Commission shall submit a report to the European Parliament and the Council every four years after the report referred to in the first paragraph on the progress made towards achieving the objectives of this Regulation.

MODIFIED +707 −710 Art. 51 Transitional measures

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2024-05-20, 2026-05-21, 2027-05-21 · dates removed: 2017-07-01, 2017-07-02

Paragraph 1 now states that secure signature creation devices assessed under the earlier Directive continue to be considered qualified electronic signature creation devices only until 21 May 2027, rather than being considered so without an end date.

Paragraph 2 now sets 21 May 2026 as the date until which qualified certificates issued to natural persons under the earlier Directive continue to be considered qualified certificates, replacing the earlier text's rule that they remained qualified until their own expiry.

Paragraph 3 no longer concerns a certification-service-provider's submission of a conformity assessment report by 1 July 2017, and instead addresses the management of remote qualified electronic signature and seal creation devices by qualified trust service providers other than those covered by Articles 29a and 39a, permitting that management without qualified status until 21 May 2026; paragraph 4 likewise no longer addresses the consequence of missing the 1 July 2017 deadline, and instead requires qualified trust service providers granted qualified status before 20 May 2024 to submit a conformity assessment report on compliance with Article 24(1), (1a) and (1b) by 21 May 2026.

Cited: Art. 51, v2 · Art. 51, v1

text before / after

texts differ too much for an inline diff; shown separately

before (32014R0910)

Article 51
Transitional measures
1. Secure signature creation devices of which the conformity has been determined in accordance with Article 3(4) of Directive 1999/93/EC shall be considered as qualified electronic signature creation devices under this Regulation.
2. Qualified certificates issued to natural persons under Directive 1999/93/EC shall be considered as qualified certificates for electronic signatures under this Regulation until they expire.
3. A certification-service-provider issuing qualified certificates under Directive 1999/93/EC shall submit a conformity assessment report to the supervisory body as soon as possible but not later than 1 July 2017. Until the submission of such a conformity assessment report and the completion of its assessment by the supervisory body, that certification-service-provider shall be considered as qualified trust service provider under this Regulation.
4. If a certification-service-provider issuing qualified certificates under Directive 1999/93/EC does not submit a conformity assessment report to the supervisory body within the time limit referred to in paragraph 3, that certification-service-provider shall not be considered as qualified trust service provider under this Regulation from 2 July 2017.

after (02014R0910-20240520)

Article 51
Transitional measures
1. Secure signature creation devices of which the conformity has been determined in accordance with Article 3(4) of Directive 1999/93/EC shall continue to be considered to be qualified electronic signature creation devices under this Regulation until 21 May 2027.
2. Qualified certificates issued to natural persons under Directive 1999/93/EC shall continue to be considered as qualified certificates for electronic signatures under this Regulation until 21 May 2026.
3. The management of remote qualified electronic signature and seal creation devices by qualified trust service providers other than qualified trust service providers providing qualified trust services for the management of remote qualified electronic signature and seal creation devices in accordance with Articles 29a and 39a may be carried out without the need to obtain the qualified status for the provision of these management services until 21 May 2026.
4. Qualified trust service providers that have been granted their qualified status under this Regulation before 20 May 2024 shall submit a conformity assessment report to the supervisory body proving compliance with Article 24(1), (1a) and (1b) as soon as possible and in any event by 21 May 2026.

INSERTED ±0 Title

applies from: unknown

Sources disagree — the EU's own amendment metadata found this change; the text comparison finds no difference in the provision's text and the amending act's instructions do not mention it. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

MODIFIED ±0 Section 2

applies from: unknown

Sources disagree — the amending act's instructions found this change; the text comparison finds no difference in the provision's text and the EU's own amendment metadata does not list it. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

MODIFIED +18 −0 Annex I ANNEX I

applies from: unchanged

Sources disagree — the text comparison and the EU's own amendment metadata found this change; the amending act's instructions do not mention it. All are shown; none is overruled.

Point (i) now refers to the information or the location of the services that can be used to enquire about the validity status of the qualified certificate, whereas the earlier version referred only to the location of such services.

Cited: Annex I, v1 · Annex I, v2

text before / after

32014R091002014R0910-20240520

ANNEX I REQUIREMENTS FOR QUALIFIED CERTIFICATES FOR ELECTRONIC SIGNATURES Qualified certificates for electronic signatures shall contain: (a) an indication, at least in a form suitable for automated processing, that the certificate has been issued as a qualified certificate for electronic signature; (b) a set of data unambiguously representing the qualified trust service provider issuing the qualified certificates including at least, the Member State in which that provider is established and: for a legal person: the name and, where applicable, registration number as stated in the official records, for a natural person: the person’s name; (c) at least the name of the signatory, or a pseudonym; if a pseudonym is used, it shall be clearly indicated; (d) electronic signature validation data that corresponds to the electronic signature creation data; (e) details of the beginning and end of the certificate’s period of validity; (f) the certificate identity code, which must be unique for the qualified trust service provider; (g) the advanced electronic signature or advanced electronic seal of the issuing qualified trust service provider; (h) the location where the certificate supporting the advanced electronic signature or advanced electronic seal referred to in point (g) is available free of charge; (i) the information or the location of the services that can be used to enquire about the validity status of the qualified certificate; (j) where the electronic signature creation data related to the electronic signature validation data is located in a qualified electronic signature creation device, an appropriate indication of this, at least in a form suitable for automated processing.

MODIFIED ±0 Annex II

applies from: unknown

Sources disagree — the EU's own amendment metadata found this change; the text comparison finds no difference in the provision's text and the amending act's instructions do not mention it. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

MODIFIED +23 −5 Annex III ANNEX III

applies from: unchanged

Sources disagree — the text comparison and the EU's own amendment metadata found this change; the amending act's instructions do not mention it. All are shown; none is overruled.

Point (i) now refers to the information or the location of the services usable to enquire about the validity status of the qualified certificate, whereas the earlier text referred only to the location of the services that can be used to enquire as to that validity status.

Cited: Annex III, v1 · Annex III, v2

text before / after

32014R091002014R0910-20240520

ANNEX III REQUIREMENTS FOR QUALIFIED CERTIFICATES FOR ELECTRONIC SEALS Qualified certificates for electronic seals shall contain: (a) an indication, at least in a form suitable for automated processing, that the certificate has been issued as a qualified certificate for electronic seal; (b) a set of data unambiguously representing the qualified trust service provider issuing the qualified certificates including at least the Member State in which that provider is established and: for a legal person: the name and, where applicable, registration number as stated in the official records, for a natural person: the person’s name; (c) at least the name of the creator of the seal and, where applicable, registration number as stated in the official records; (d) electronic seal validation data, which corresponds to the electronic seal creation data; (e) details of the beginning and end of the certificate’s period of validity; (f) the certificate identity code, which must be unique for the qualified trust service provider; (g) the advanced electronic signature or advanced electronic seal of the issuing qualified trust service provider; (h) the location where the certificate supporting the advanced electronic signature or advanced electronic seal referred to in point (g) is available free of charge; (i) the information or the location of the services that can be used to enquire as to about the validity status of the qualified certificate; (j) where the electronic seal creation data related to the electronic seal validation data is located in a qualified electronic seal creation device, an appropriate indication of this, at least in a form suitable for automated processing.

MODIFIED +147 −18 Annex IV ANNEX IV

applies from: unchanged

Sources disagree — the text comparison and the EU's own amendment metadata found this change; the amending act's instructions do not mention it. All are shown; none is overruled.

Point (c) now ends the natural-person description with a semicolon and moves the legal-person description, previously combined in point (c), into a new separate point (ca), which adds the phrase describing a unique set of data unambiguously representing the legal person before restating the name and, where applicable, registration number requirement.

Point (j) changes from referring only to the location of the certificate validity status services to referring to the information or the location of those services, and changes the phrase about enquiring as to the validity status to enquiring about the validity status.

Cited: Annex IV, v1 · Annex IV, v2

text before / after

32014R091002014R0910-20240520

ANNEX IV REQUIREMENTS FOR QUALIFIED CERTIFICATES FOR WEBSITE AUTHENTICATION Qualified certificates for website authentication shall contain: (a) an indication, at least in a form suitable for automated processing, that the certificate has been issued as a qualified certificate for website authentication; (b) a set of data unambiguously representing the qualified trust service provider issuing the qualified certificates including at least the Member State in which that provider is established and: for a legal person: the name and, where applicable, registration number as stated in the official records, for a natural person: the person’s name; (c) for natural persons: at least the name of the person to whom the certificate has been issued, or a pseudonym. If pseudonym; if a pseudonym is used, it shall be clearly indicated; (ca) for legal persons: a unique set of data unambiguously representing the legal person to whom the certificate is issued, with at least the name of the legal person to whom the certificate is issued and, where applicable, the registration number as stated in the official records; (d) elements of the address, including at least city and State, of the natural or legal person to whom the certificate is issued and, where applicable, as stated in the official records; (e) the domain name(s) operated by the natural or legal person to whom the certificate is issued; (f) details of the beginning and end of the certificate’s period of validity; (g) the certificate identity code, which must be unique for the qualified trust service provider; (h) the advanced electronic signature or advanced electronic seal of the issuing qualified trust service provider; (i) the location where the certificate supporting the advanced electronic signature or advanced electronic seal referred to in point (h) is available free of charge; (j) the information or the location of the certificate validity status services that can be used to enquire as to about the validity status of the qualified certificate.

INSERTED +1,670 −0 Annex V REQUIREMENTS FOR QUALIFIED ELECTRONIC ATTESTATION OF ATTRIBUTES

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree about the kind of change — they agree this provision changed and disagree about how: the text comparison called it INSERTED, the EU's own amendment metadata called it INSERTED and the amending act's instructions called it MODIFIED. All are shown; none is overruled.

Annex V is newly added and sets out a list of items that a qualified electronic attestation of attributes must contain, covering an indication of its qualified status, identifying data for both the issuing qualified trust service provider and the entity to which the attributes refer, the attested attributes, the validity period, an attestation identity code, the qualified electronic signature or seal, the location of the supporting certificate, and information on how to check the attestation's validity status.

Cited: Annex V, v2

text before / after

inserted text (02014R0910-20240520)

ANNEX V
REQUIREMENTS FOR QUALIFIED ELECTRONIC ATTESTATION OF ATTRIBUTES
Qualified electronic attestation of attributes shall contain:
(a) an indication, at least in a form suitable for automated processing, that the attestation has been issued as a qualified electronic attestation of attributes;
(b) a set of data unambiguously representing the qualified trust service provider issuing the qualified electronic attestation of attributes including at least, the Member State in which that provider is established and:
(i) for a legal person: the name and, where applicable, registration number as stated in the official records;
(ii) for a natural person: the person’s name;
(c) a set of data unambiguously representing the entity to which the attested attributes refer; if a pseudonym is used, it shall be clearly indicated;
(d) the attested attribute or attributes, including, where applicable, the information necessary to identify the scope of those attributes;
(e) details of the beginning and end of the attestation’s period of validity;
(f) the attestation identity code, which must be unique for the qualified trust service provider and, if applicable, the indication of the scheme of attestations that the attestation of attributes is part of;
(g) the qualified electronic signature or qualified electronic seal of the issuing qualified trust service provider;
(h) the location where the certificate supporting the qualified electronic signature or qualified electronic seal referred to in point (g) is available free of charge;
(i) the information or location of the services that can be used to enquire about the validity status of the qualified attestation..

INSERTED +890 −0 Annex VI MINIMUM LIST OF ATTRIBUTES

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the EU's own amendment metadata found this change; the amending act's instructions do not mention it. All are shown; none is overruled.

Annex VI is new text setting out a minimum list of attributes, including address, age, gender, civil status, family composition, nationality or citizenship, educational and professional qualifications, powers and mandates to represent persons, public permits and licences, and financial and company data for legal persons.

It states that, pursuant to Article 45e, Member States shall ensure that measures allow qualified trust service providers of electronic attestations of attributes to verify these attributes electronically at the user's request against the relevant authentic source at national level or via designated intermediaries recognised at national level, in accordance with Union or national law, where the attributes rely on authentic sources within the public sector.

Cited: Annex VI, v2

text before / after

inserted text (02014R0910-20240520)

ANNEX VI
MINIMUM LIST OF ATTRIBUTES
Pursuant to Article 45e, Member States shall ensure that measures are taken to allow qualified trust service providers of electronic attestations of attributes to verify by electronic means at the request of the user, the authenticity of the following attributes against the relevant authentic source at national level or via designated intermediaries recognised at national level, in accordance with Union or national law and where these attributes rely on authentic sources within the public sector:
1. Address;
2. Age;
3. Gender;
4. Civil status;
5. Family composition;
6. Nationality or citizenship;
7. Educational qualifications, titles and licences;
8. Professional qualifications, titles and licences;
9. Powers and mandates to represent natural or legal persons;
10. Public permits and licences;
11. For legal persons, financial and company data.

INSERTED +1,727 −0 Annex VII REQUIREMENTS FOR ELECTRONIC ATTESTATION OF ATTRIBUTES ISSUED BY OR ON BEHALF OF A PUBLIC BODY RESPONSIBLE FOR AN AUTHENTIC SOURCE

applies from: unknown (an inserted provision states its own application date only in prose)

Sources disagree — the text comparison and the EU's own amendment metadata found this change; the amending act's instructions do not mention it. All are shown; none is overruled.

Annex VII is a newly added annex setting out the content that an electronic attestation of attributes issued by or on behalf of a public body responsible for an authentic source must contain, listing items from an indication of the attestation's issuance basis through issuer identification, subject identification, attested attributes, validity period, attestation identity code, qualified electronic signature or seal, certificate location, and validity-status enquiry information.

Cited: Annex VII, v2

text before / after

inserted text (02014R0910-20240520)

ANNEX VII
REQUIREMENTS FOR ELECTRONIC ATTESTATION OF ATTRIBUTES ISSUED BY OR ON BEHALF OF A PUBLIC BODY RESPONSIBLE FOR AN AUTHENTIC SOURCE
An electronic attestation of attributes issued by or on behalf of a public body responsible for an authentic source shall contain:
(a) an indication, at least in a form suitable for automated processing, that the attestation has been issued as an electronic attestation of attributes issued by or on behalf of a public body responsible for an authentic source;
(b) a set of data unambiguously representing the public body issuing the electronic attestation of attributes, including at least, the Member State in which that public body is established and its name and, where applicable, its registration number as stated in the official records;
(c) a set of data unambiguously representing the entity to which the attested attributes refer; if a pseudonym is used, it shall be clearly indicated;
(d) the attested attribute or attributes, including, where applicable, the information necessary to identify the scope of those attributes;
(e) details of the beginning and end of the attestation’s period of validity;
(f) the attestation identity code, which must be unique for the issuing public body and, if applicable, an indication of the scheme of attestations that the attestation of attributes is part of;
(g) the qualified electronic signature or qualified electronic seal of the issuing body;
(h) the location where the certificate supporting the qualified electronic signature or qualified electronic seal referred to in point (g) is available free of charge;
(i) the information or location of the services that can be used to enquire about the validity status of the attestation.

MODIFIED ±0 CHA II

applies from: unknown

Sources disagree — the EU's own amendment metadata found this change; the text comparison finds no difference in the provision's text and the amending act's instructions do not mention it. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

MODIFIED ±0 CHA III

applies from: unknown

Sources disagree — the EU's own amendment metadata found this change; the text comparison finds no difference in the provision's text and the amending act's instructions do not mention it. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

MODIFIED ±0 CHA VI

applies from: unknown

Sources disagree — the EU's own amendment metadata found this change; the text comparison finds no difference in the provision's text and the amending act's instructions do not mention it. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

INSERTED ±0 CHA IVa

applies from: unknown

Sources disagree — the EU's own amendment metadata found this change; the text comparison finds no difference in the provision's text and the amending act's instructions do not mention it. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

Back to top ↑

The full entry, with the citation mapping v1 = 32014R0910, v2 = 02014R0910-20240520, is committed at eu/32014R0910/CHANGELOG.md.