October 2, 2026:

Finland’s national legislation enabling the European Digital Identity (EUDI) Wallet takes effect today, October 1, 2026 — putting Helsinki among a small group of EU capitals that have secured both a legal foundation and a named government agency building the actual software, with fewer than 84 days before the bloc’s hard implementation deadline. The timing underscores a deepening divide across the European Union: while a handful of countries are clearing legislative milestones, privacy researchers at European Digital Rights (EDRi) have documented that the technical implementing rules governing what the wallet can and cannot do with your data are being quietly rewritten in a way that could deliver a materially weaker privacy instrument than the one the European Parliament approved.
On the same day Finland’s legislation entered the books, Bulgaria’s Council of Ministers approved the governance steps needed to begin developing its own EUDI Wallet, naming a supervisory authority for wallet providers. The contrast between Helsinki and Sofia illuminates the challenge that now faces Brussels: a regulation that requires 27 sovereign states to simultaneously produce a technically sophisticated, privacy-preserving digital identity infrastructure — all before December 24, 2026 — is producing 27 different timelines, 27 different readiness levels, and one growing argument about whether the privacy architecture will survive the implementation process.
According to Euronews, some 24 of the EU’s 27 member states have yet to make a digital identity wallet available to their citizens and are expected to miss the bloc’s December 24, 2026 legal deadline.
Finland’s new statute supplements Regulation (EU) 2024/1183 — the eIDAS 2.0 reform adopted by the European Parliament and Council in spring 2024 — and creates the domestic legal machinery through which EUDI Wallets can be issued, supervised, and accepted across Finnish public and private services.
Under the framework, the Digital and Population Data Services Agency (DVV, or Digi- ja väestötietovirasto) is mandated to offer a government-provided wallet at minimum, with private-sector providers also permitted to issue compliant wallets if they meet the requirements set for wallet providers. Oversight falls to Finland’s Transport and Communications Agency, Traficom, which will supervise wallet providers and establish a register of services that accept digital wallets.
Alongside the wallet framework, Finnish citizens will gain the country’s first digital identity document — an electronic ID credential co-produced by the National Police Board and the DVV. This credential will be granted to anyone holding a valid passport or identification card.
“Digital wallets will make using services in the EU even easier,” said Anna-Kaisa Ikonen, Finland’s Minister of Local and Regional Government, who has shepherded the country’s EUDI project since the Finnish Ministry of Finance launched it in April 2024. “Wallets will also be more secure, as they will give people better control of their personal information.”
Despite the legislative milestone, Finns will not be able to download a working wallet app today. Both Finland’s wallet and its new digital ID are expected to become available in 2027. DVV is still completing the software build, with earlier agency communications pointing to a late-2026 or early-2027 launch window.
Privacy-enhancing technology is built into the wallet’s design from the outset. The system enables selective disclosure of personal information, allowing users to verify specific attributes — such as whether they are over 18 — without revealing additional personal details such as their full birthdate, name, or address. The DVV has already tested this capability in a live pilot: in partnership with travel technology company Amadeus, the agency demonstrated an online airline check-in flow using the EUDI Wallet, presenting only the identification attributes the airline’s service actually required.
Understanding why the EDRi critique matters requires a brief look at the technical architecture the eIDAS 2.0 regulation mandated and what “selective disclosure” actually means in engineering terms.
Under eIDAS 1.0 (Regulation EU 910/2014) — the 2014 framework it supersedes — cross-border digital identity worked through federated identity: a national identity provider would transmit a signed token to a relying party (a government portal, a bank) containing the user’s verified attributes. That token typically included everything: name, date of birth, national identifier, address. The relying party learned more about you than it strictly needed, and the identity provider could log where you used the credential.
eIDAS 2.0 mandated a fundamentally different model, built on attribute-based credential presentation using a protocol called OpenID4VC (OpenID for Verifiable Credentials), specified in the Architecture Reference Framework the European Commission publishes and maintains. In this model, the wallet holds cryptographically signed attestations of your attributes, issued by the DVV or another trust service provider. When a relying party asks for proof that you are over 18, the wallet can present a cryptographic proof of that specific Boolean claim without transmitting your birthdate, name, or any other attribute. The relying party learns only “age ≥ 18.”
To protect against cross-service tracking, the regulation mandated three specific properties in addition to selective disclosure:
Unlinkability: Different services cannot correlate your wallet presentations across interactions to infer that the same person used both services. This requires that the wallet generate unlinkable presentations — technically implemented by deriving per-presentation key pairs from the underlying credential, so each transaction cannot be tied to others.
Issuer blindness: The DVV or other credential issuer cannot see where and when you use your credentials. The issuer’s role ends at issuance; no callback or logging mechanism can report back on usage.
No tracking by design: The regulation explicitly prohibits the issuer from monitoring use, and prohibits services from combining data across sessions to build profiles.
These three properties are what separate a EUDI Wallet from a national ID card system with an app. A credential that satisfies all three is a genuine privacy-preserving tool; one that satisfies only the first resembles a more convenient version of the federated identity architecture eIDAS 2.0 was supposed to replace.
The gap between the regulation’s mandates and what citizens may actually receive is what has occupied EDRi and its partner organizations since early 2026.
In March of that year, EDRi — the European digital rights network — together with epicenter.works and eight other civil society organizations submitted analysis of the draft implementing acts to the European Commission, identifying four specific problems. Among the most significant: the implementing acts were weakening the wallet’s untraceability and unlinkability safeguards — changing the requirement from “prevent” linkability to “hinder” it — and were adding mandatory facial biometric data to the minimum dataset every wallet must carry.
“Hinder” and “prevent” are not interchangeable in data-protection law. A system designed to prevent linkability must make cross-session correlation technically impossible; a system designed to hinder it need only make correlation more difficult. The second standard leaves room for de-anonymization attacks that the first forecloses.
The facial portrait requirement compounds the concern. A dataset that includes a biometric portrait is inherently more identifiable than one without; once a facial image travels from a relying party’s server to any system capable of running facial-recognition queries, it creates a linkability surface that text-based attributes do not.
Member states reached a partial resolution at an eIDAS committee meeting in June 2026, agreeing that national authorities may make the portrait optional rather than mandatory. Privacy advocates counter that nothing obliges them to do so, and that resolving a fundamental privacy question through a technical committee — two years after the European Parliament thought it had already resolved it in the regulation’s text — sets a troubling precedent for what may happen as implementing acts continue to be finalized.
“The question of what a European identity wallet must contain is being resolved in a technical committee,” Brussels Signal observed in its September 16, 2026 analysis, adding that “a specification can be argued over while it exists on paper. Once it has been implemented across 27 national systems and the databases behind them, changing it stops being a drafting question and becomes a procurement one.”
For any European uncertain about what this means for them: participation in the EUDI Wallet system is voluntary and free. No EU citizen is required to obtain or use a wallet. Physical identity documents — passports, national ID cards, driver’s licenses — remain valid and will not be phased out.
What the eIDAS 2.0 regulation does require is that:
(a) Each member state makes at least one certified EUDI Wallet available to citizens by December 24, 2026 — a deadline almost all of them are expected to miss;
(b) From roughly late 2027, regulated private-sector businesses — banks, insurers, telecoms, energy providers, and very large online platforms subject to the Digital Services Act — must accept the wallet as a valid form of identification for identity checks and KYC (Know Your Customer) processes;
(c) From approximately July 2027, banks face an earlier adoption deadline tied to updated anti-money-laundering requirements;
(d) From December 2027, the wallet must also let citizens create qualified electronic signatures free of charge for non-professional use — turning the wallet into a distribution channel for a function currently provided by commercial trust service providers at cost.
For businesses, the interplay of these timelines creates a compliance planning horizon spanning from now through late 2027. For banks in particular, the July 2027 deadline is closer than the headline “end of 2027” framing suggests.
Not all 27 member states are in the same position, and the variation is striking.
Italy is the standout outlier. Its IT Wallet — built on top of the IO app, Italy’s existing citizen-government services platform — draws roughly eight million monthly users, making it the only EUDI-adjacent wallet that has demonstrated consumer adoption at scale. Germany has set January 2, 2027 as its planned launch date, nine days after the legal deadline expires. France is conducting public testing in the second half of 2026. Poland is integrating the wallet into its existing mObywatel platform. Denmark’s AltID initiative has entered its production phase.
Finland now joins this group, having cleared the legislative prerequisite that Bulgaria is still drafting. Earlier analyst assessments rated only three member states as “almost certain” to meet the December 2026 deadline, with five classified as “very likely” and eight as “likely” — leaving the majority of the bloc facing meaningful risk.
The Netherlands provides the starkest adoption data: its pilot wallet attracted just 57 users before the program moved into a delayed timeline, with the full rollout pushed to late 2027, according to Brussels Signal. Consumer awareness remains a challenge across the bloc; research by identity verification company IDnow found that 51 percent of surveyed consumers in France and Germany had never heard of the EUDI Wallet.
The European Commission has invested approximately €46 million (approximately $52 million) from the Digital Europe Programme into four large-scale pilot projects — POTENTIAL, EWC, NOBID, and DC4EU — that collectively issued more than 1,500 digital credentials and completed more than 8,000 cross-border transactions ahead of the deadline. Finland’s DVV participated in the EWC (EU Digital Identity Wallet Consortium), focusing on travel, payments, and organizational identity use cases alongside Germany, Sweden, and several other member states.
With legislation now in force, attention inside Finland shifts to DVV completing its software build and achieving the wallet certification required under EU technical standards. Traficom will stand up the registry of services that accept wallet credentials. Private providers eyeing the Finnish market will need to demonstrate compliance before they can operate.
For the broader European Union, the next 84 days will be the most revealing. The December 24, 2026 deadline will pass with most of the bloc still under construction. Germany’s January 2027 launch will be the next significant data point on whether a major economy can deliver a functional, widely usable wallet in the months that follow. Italy’s monthly-user figures will continue to be the most closely watched adoption signal.
The Commission’s own target — 80 percent of EU citizens using a digital identity solution by 2030 — requires not just that wallets exist, but that citizens choose to reach for them. Italy’s trajectory suggests that goal is achievable; the Netherlands pilot suggests it is not automatic. The difference, as implementation proceeds, may lie less in the technical specifications than in the privacy guarantees those specifications actually deliver — and whether the implementing acts that are still being finalized leave those guarantees intact.
The December 24, 2026 legal deadline requires all 27 EU member states to make at least one certified EUDI Wallet available — but independent analysts assessed earlier this year that only a small minority of countries were on track to meet that date with a fully featured wallet. Germany, for example, has set January 2, 2027 as its planned launch. For Finnish citizens specifically, the DVV’s wallet app is expected in 2027. The regulation’s business-acceptance requirements for banks, insurers, and large platforms do not kick in until approximately July 2027 (banks) and late 2027 (other regulated sectors) — so even in countries with working wallets, the ecosystem in which those wallets are genuinely useful is still being built.
The eIDAS 2.0 regulation mandated three core privacy properties: selective disclosure (you share only the specific attributes a service needs), unlinkability (different services cannot correlate your interactions), and issuer blindness (the government agency that issued your credential cannot see where you use it). In theory these properties, implemented using cryptographic protocols like OpenID4VC, would make the EUDI Wallet more privacy-protective than current national ID systems. In practice, civil society groups including EDRi and epicenter.works documented in March 2026 that the implementing acts being finalized outside parliamentary review were weakening the unlinkability requirement from “prevent” to “hinder” it, and were adding mandatory facial biometrics to the minimum data set. A partial concession was reached at a June 2026 committee meeting — member states may make the portrait optional — but advocates argue nothing requires them to do so. Whether the wallet citizens receive will match the one the European Parliament approved is the defining question of the implementation period now underway.
The original eIDAS regulation (EU) 910/2014 from 2014 created a framework for cross-border electronic identification, but participation was voluntary and adoption was limited — most national eID systems worked well domestically but poorly across borders. eIDAS 2.0 (Regulation EU 2024/1183), which entered into force on May 20, 2024, mandates that each member state make a wallet available to citizens, introduces the device-local self-sovereign identity model (your credentials live on your phone, not on a government server), requires the three privacy properties described above, and imposes mandatory acceptance obligations on regulated private-sector businesses. Of Finland’s pre-existing digital identity tools, only the Citizen Certificate (Kansalaisvarmenne) had been formally notified under eIDAS 1.0. The new wallet represents a substantially more ambitious and interoperable standard.
Yes, and this connection matters. The European Commission urged member states in April 2026 to adopt its age-verification application, and has built the tool so it can be folded into national EUDI Wallets rather than run as a separate system. This means the wallet’s selective disclosure architecture — in principle, showing only “over 18” without revealing identity — is being positioned as the technical mechanism for EU-wide online age gating. Whether that mechanism genuinely preserves anonymity depends on the implementing acts currently being contested by EDRi. If unlinkability requirements are weakened and facial portraits become part of the minimum data set, an age-verification interaction that appears anonymous may not, in practice, be.