Skip to content
TrustList
News

German MPs hear experts fault the d-you wallet before 2027 launch

Editorial

By TrustList Editorial

The Digital Identities Act, which sets the national rules for the EU identity wallet, had its first reading on 23 September and has to pass within weeks to meet the January 2027 start.

About German MPs hear experts fault the d-you wallet before 2027 launch

German MPs hear experts fault the d-you wallet before 2027 launch

6 October 2026: Experts called to the Bundestag's digital committee on Tuesday were largely unhappy with Germany's plan for the EU digital identity wallet, known as d-you, with several criticising the lack of pseudonymous use at launch. The hearing covered the Digital Identities Act, the national law that has to be in place for the wallet to be available from January 2027.

Not yet independently verified. We read the Bundestag page for dates and the bill's purpose, and heise for what the experts said. We have not read the bill text or the written statements. We will update this when it can be confirmed, and remove this note.

The Bundestag held the bill's first reading on 23 September, and the digital committee held its hearing on 6 October. The bill supplements the revised EU eIDAS regulation, which applies directly, and settles points the regulation leaves to national law, such as how the German identity card can feed the wallet, links to national registers and which bodies supervise wallets. The Bundestag says use of the wallet stays voluntary. A ministry official told the hearing the law has to pass within the coming weeks to clear the formal steps in time.

Andreas Hartl, speaking for the Federal Data Protection Commissioner, welcomed a trustworthy public system but asked that the first version's capabilities and the timetable be stated clearly. Missing pseudonymous use, he said, is a data protection problem. Jiska Classen, a smartphone security researcher, said much of the security architecture is not public and that a compromised phone would let someone identify themselves as another person. She asked for a clear liability rule and a block that is not only forward-looking. Thomas Lohninger of epicenter.works said service providers should have to register their intended uses with an authority, as in other EU states.

Torsten Lodderstedt, a managing director of the operator Common Codes, defended the design. He said it chose the best balance of privacy, security and usability, and that a cloud security anchor is currently the only workable route because user devices are not secure enough. According to heise, the Federal Office for Information Security (BSI) shares that view.

One caveat for planners: a ministry official said it is not yet possible to say when d-you will be notified to the European Commission as an eIDAS-compliant wallet. That step needs the status "feature completed wallet", and the national law enables only a national connection.

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy