in force 2024-05-20 INSERTED+2,383 −0§
Amended by Regulation (EU) 2024/1183 32024R1183
applies from: unknown (an inserted provision states its own application date only in prose)
Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.
Article 5e is a newly inserted provision setting out obligations for Member States when European Digital Identity Wallets, their validation mechanisms, or the underlying electronic identification scheme are breached or partly compromised, including suspension, withdrawal, notification, re-establishment and revocation of validity.
It also directs the Commission to publish corresponding amendments to the list referred to in Article 5d and to adopt implementing acts establishing reference standards and, where necessary, specifications and procedures for the measures described.
Cited: Art. 5e, v2
text before / after
inserted text (02014R0910-20240520)
Article 5e Security breach of European Digital Identity Wallets 1. Where European Digital Identity Wallets provided pursuant to Article 5a, the validation mechanisms referred to in Article 5a(8) or the electronic identification scheme under which the European Digital Identity Wallets are provided are breached or partly compromised in a manner that affects their reliability or the reliability of other European Digital Identity Wallets, the Member State that provided the European Digital Identity Wallets shall, without undue delay, suspend the provision and the use of European Digital Identity Wallets. Where justified by the severity of the security breach or compromise referred to in the first subparagraph, the Member State shall withdraw European Digital Identity Wallets without undue delay. The Member State shall inform the users affected, the single points of contact designated pursuant to Article 46c(1), the relying parties and the Commission accordingly. 2. If the security breach or compromise referred to in paragraph 1, first subparagraph, of this Article is not remedied within three months of the suspension, the Member State that provided the European Digital Identity Wallets shall withdraw European Digital Identity Wallets and revoke their validity. The Member State shall inform the users affected, the single points of contact designated pursuant to Article 46c(1), the relying parties and the Commission of the withdrawal accordingly. 3. Where the security breach or compromise referred to in paragraph 1, first subparagraph, of this Article is remedied, the providing Member State shall re-establish the provision and the use of European Digital Identity Wallets and inform the affected users and relying parties, the single points of contact designated pursuant to Article 46c(1) and the Commission without undue delay. 4. The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list referred to in Article 5d without undue delay. 5. By 21 November 2024, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the measures referred to in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).