regulating

EUDI Wallet, GDPR and selective disclosure: how the wallet protects data

6

Min

•

05.10.2026

In short: the European digital identity wallet (EUDI Wallet) is designed "privacy by design" and aligned with the GDPR. Thanks to selective disclosure, the citizen shares only the strictly necessary attribute, with their explicit consent, and keeps control of their data. For businesses, this means asking only for what is useful and declaring their purpose. The good news: this minimisation work serves well beyond the wallet, provided it is articulated with your KYC and AML obligations.

‍

Why the wallet is designed for privacy

‍

The European digital identity wallet is governed by Regulation (EU) 2024/1183, better known as eIDAS 2.0. This text does not merely create an identification tool: it places data protection at the heart of its design.

‍

The wallet is indeed built on the principle of "privacy by design", that is, protecting privacy from the very design stage. In concrete terms, the tool is built to share as little data as possible, not to collect as much as possible. This logic is directly aligned with the GDPR, whose core principles it applies: minimisation, consent, control by the data subject.

‍

In other words, the wallet is not limited to digitising an identity card. It changes the way data flows between a citizen and a business. Where a scan of an ID document hands over the entire document at once, the wallet makes it possible to transmit only a targeted piece of information.

‍

Selective disclosure, explained

‍

Selective disclosure is the wallet's central privacy feature. Its principle is simple: the citizen shares only the attribute strictly necessary for the situation, without revealing the rest of their data.

A few concrete examples make the idea immediate:

‍

  • Prove that you are of age without revealing your date of birth. The merchant or online service receives a response along the lines of "yes, this person is over 18", without ever knowing the day, month or year of birth.
  • Prove your residence without giving your full address. A service can verify that the person does reside in a given municipality or country, without obtaining the street number and name.
  • Justify a status (student, licence holder, etc.) without sharing your entire civil status.

‍

In each case, the business obtains the proof it needs, and nothing else. This is a reversal of usual practices, where a full document is often requested to verify only a single point.

Two safeguards complete this mechanism:

  • Sharing relies on the citizen's explicit consent, for each request. Nothing leaves the wallet without the person's validation.
  • The citizen keeps control and traceability of their shares: they can know to whom they sent what, and when.

‍

What minimisation requires of businesses

‍

For businesses, the wallet introduces a clear and structuring constraint: data minimisation. The business that receives the attributes, called the "relying party", can ask only for the attributes necessary for its purpose.

‍

This requirement comes with an obligation of transparency. The relying party must declare its purpose at the time of registration. It therefore cannot request data "just in case" or for an unforeseen use: the scope of what it can ask for is framed upstream.

‍

For many organisations, this means reviewing journeys designed in another era, where data was collected broadly out of convenience or habit. With the wallet, the question is no longer "what data can I collect?" but "what data is truly indispensable to me for this specific purpose?".

‍

This is not a purely technical constraint: it is also a substantive alignment with the GDPR, which already set out the minimisation principle. The wallet simply makes it concrete and verifiable.

‍

Reconciling minimisation with KYC/AML obligations

‍

One point of vigilance deserves to be stated without ambiguity: minimisation does not exempt from any regulatory verification obligation. A business subject to anti-money laundering and counter-terrorist financing (AML) or to know-your-customer (KYC) obligations must still verify enough about the identity and profile of its customers.

‍

Two logics that may seem opposed therefore need to be articulated:

  • Ask less, under minimisation and the GDPR.
  • Verify enough, under KYC and AML.

‍

In practice, these two requirements are not really at odds. Minimisation requires not collecting beyond what is necessary, but AML obligations define precisely what is necessary in a regulated context. The right approach is to map, for each journey, the attributes actually required by law and by your risk analysis, then to ask only for those.

‍

To go deeper into this articulation between identity verification and compliance obligations, our complete KYC guide details the expected steps and control points.

‍

How to turn it into an asset

‍

Rather than enduring these requirements, a business has every interest in treating them as an opportunity to clean up its data practices. The work required by the wallet indeed has a value that goes well beyond the wallet itself.

‍

Three concrete projects stand out:

  • Collect only what is useful. Review each form and each journey to remove data requested without a real purpose. Less data collected also means less risk in the event of an incident.
  • Document the legal basis. For each piece of data, be able to say why you process it and on what grounds. This is a GDPR expectation, and a valuable reflex when facing an inspection.
  • Align journeys with the GDPR. Make consent clear, the purpose legible, and processing traceable.

‍

This work serves beyond the wallet: it strengthens your overall GDPR compliance, simplifies your audits, and improves your customers' trust. Businesses that tackle it now turn a regulatory constraint into a long-term advantage.

‍

To place this topic within the general framework of the European wallet, our reference article on eIDAS 2.0 covers what you need to know.

‍

In conclusion

‍

The European wallet is not only an identification tool: it is a data-flow model designed for privacy. Selective disclosure, explicit consent, minimisation, traceability: each building block protects the citizen and holds the business accountable.

‍

For organisations, the challenge is twofold. On one side, ask only for what is useful and honestly declare your purpose. On the other, keep verifying enough to comply with KYC and AML. Done well, this alignment is not a hindrance: it is a healthy overhaul of your data practices, one that will serve you well beyond the wallet's deadline.

‍

Sources: Regulation (EU) 2024/1183 (eIDAS 2.0); General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).

‍

Get your journeys ready for eIDAS 2.0

Meelo helps you integrate the European wallet into your journeys, and complements it: dynamic fraud detection (400+ signals, behaviour, device), KYB and beneficial owners, creditworthiness analysis. A decision in 2 to 5 seconds, documented and auditable.

Cassandre Nolf
Strategy Marketing Manager