Identity data is personal data
Wallet attributes, national identifiers, certificate metadata and biometrics fall under GDPR. eIDAS sets technical frames; GDPR requires legal basis, minimisation, DPIA and data subject rights.
Processing register
Add trust services and wallet integrations to your processing record: purpose, basis, retention, subprocessors (QTSP), transfers outside EEA. ISO 27701 helps link privacy and security.
Consent and selective disclosure
EUDI wallet design targets minimal data sharing. Document how your service requests attributes, not ‘fetch everything’ because the API allows it.
Checklist
- Inventory eID, QES and QTSP use
- Map vendors and trust list status
- Link to ISMS, GDPR and risk register
- Plan DPIA where wallet or identity data
- Test fallback and incident scenarios
Practical next step
For eIDAS 2.0 GDPR, ISO Ready links identity, trust and security measures in one ISMS, with actions, evidence and vendors toward audit. Run the readiness scan on iso-ready.nl.
More on eIDAS 2.0
- Eidas2 Compliance
- Gdpr Privacy
- Iso 27701 Certification
- European Digital Identity Wallet
- Iso 27701 Privacy Management
- Dora Compliance