What the Council changed in the European Business Wallet proposal
The Council text
The Council's press release links its general approach to Council document ST 7659/26, a note from the Cyprus Presidency to the Permanent Representatives Committee dated 22 May 2026. Its annex sets out the whole Regulation, with additions to the Commission proposal in bold and deletions struck through.[6][13]
The table below covers the substantive changes. It leaves out the editorial ones the Presidency also made, such as tidied wording and renumbered cross-references, and it does not cover the recitals or the Annex.[13]
The Council's own summary
In its press release, the Council highlighted five changes:
- Interoperability: Wallets should complement, not replace, existing national business-to-business and business-to-government systems.[6]
- Equivalence: actions through a Wallet keep their legal equivalence to paper, but national administrative and procedural requirements remain applicable.[6]
- Mandates: the authorisation system is not intended to affect powers of attorney or legal mandates under national or Union law.[6]
- Providers: a higher threshold for becoming a Wallet provider, implementing acts on the paperwork applicants must submit, and a stronger role for national supervisory bodies when a provider is systemically non-compliant.[6]
- Timing: up to 60 days instead of 30 for supervisory bodies to review a provider application, and the deadlines grouped and streamlined.[6]
Scope and legal effect
| Article | Commission proposal | Council general approach |
|---|---|---|
| Article 2 Scope | The Regulation would leave untouched the systems that Union law mandates for exchanging documents and data between competent authorities.[1] | It would also leave untouched systems mandated by national law, and would be without prejudice to action taken by Member States for public order, public security and defence.[13] |
| Article 3 Definitions | Wallet owners would grant "mandates" to "authorised representatives". An economic operator would be any natural or legal person, or group of them, acting in a commercial or professional capacity.[1] | Mandates and authorised representatives are replaced by "authorisations" that an owner grants to Wallet users to perform specified actions in a designated Wallet. The definition of economic operator would name companies, partnerships, foundations, associations, sole traders and self-employed persons.[13] |
| Article 4 Principle of equivalence | An action taken with any of the core functionalities in Article 5(1) would have the same legal effect as the same action carried out in person, on paper, or by other compliant means.[1] | Equivalence would attach to the qualified trust services that form part of those functionalities, and would also cover authorised Wallet users. A new paragraph keeps existing EU or national requirements on electronic formats in administrative procedures applicable.[13] |
What a Wallet would do
| Article | Commission proposal | Council general approach |
|---|---|---|
| Article 5 Core functionalities | Owners could authorise several users to operate their Wallet and manage and revoke those authorisations, and could export their data.[1] | Authorisations, including those tied to roles, would be without prejudice to any power of attorney or legal mandate. Owners could also import their data, so that they can move between Wallet providers.[13] |
| Article 6 Technical features | An owner would be onboarded remotely through an authorised representative using electronic identification at assurance level "substantial" or "high".[1] | Onboarding would go through a legal representative or another person lawfully empowered to carry it out, with electronic identification at assurance level "high". Providers would also have to give public sector bodies that do not own a Wallet a unique digital address as a standalone service, and make Wallets accessible to persons with disabilities.[13] |
Who could provide a Wallet
| Article | Commission proposal | Council general approach |
|---|---|---|
| Article 7 Requirements for providers | Providers would have to meet the requirements of Article 19a of the eIDAS Regulation, except qualified trust service providers, which would be exempt.[1] | The exemption for qualified trust service providers is deleted. Within eight months of entry into force, the Commission would adopt an implementing act on how to assess whether a provider presents a risk to the security of the Union, including control by a third country. Providers would keep an up-to-date risk assessment and update their self-assessment every 24 months, or sooner after a significant incident or a substantial change.[13] |
| Article 11 Becoming a provider | A would-be provider would notify its supervisory body, with a declaration of conformity. The body would have 30 days to review; without a substantive response in that time, the notification would count as complete. Qualified trust service providers would skip the review.[1] | Notification becomes an application for authorisation, backed by a self-assessment report and a risk assessment; existing eIDAS conformity assessment reports could be reused. The review period would be 60 days, and silence would no longer count as approval: the body would have to explain the delay and conclude within at most 20 more days. The fast track for qualified trust service providers is deleted.[13] |
| Article 12 List of providers | Supervisory bodies would report changes to the Commission within 24 hours.[1] | Within 3 working days. The Commission would add an authorised provider to its list, or remove a non-compliant one, within two working days.[13] |
Identification and the European Digital Directory
| Article | Commission proposal | Council general approach |
|---|---|---|
| Article 8 Owner identification data | The Commission could adopt implementing acts setting requirements for owner identification data, but would not have to.[1] | The Commission would have to adopt them, within one year of entry into force. Member States could also notify an intermediary platform acting on behalf of their authentic sources.[13] |
| Article 9 Unique identifiers | An owner without a European Unique Identifier would get a unique identifier created under an implementing act.[1] | That identifier would be created on request, or when the owner is provided with a Wallet.[13] |
| Article 10 European Digital Directory | Only Wallet owners, their authorised representatives and Wallet providers could access the Directory. Providers would pass on changes within one working day.[1] | Sets minimum entries (official name, unique identifier, digital address, country of establishment), adds public sector bodies that do not own a Wallet, opens access to Member State authorities, and requires providers to check owner information at least every 72 hours.[13] |
Supervision and penalties
| Article | Commission proposal | Council general approach |
|---|---|---|
| Article 13 Supervision | The supervisory bodies already designated under eIDAS would supervise Wallet providers and could remove non-compliant ones from the list. Where a national authority failed to act, the Commission could adopt implementing acts with corrective measures, including temporary suspension.[1] | Each Member State would designate a competent authority, new or existing, or by agreement one in another Member State. Supervisory bodies would notify the Commission of non-compliance instead of removing providers themselves. The Commission could step in only for systematic non-compliance, together with the supervisory body, and suspend a provider temporarily by decision after giving it a chance to remedy. Member States could decide whether fines apply to national public authorities; the ceiling of 2% of worldwide annual turnover is unchanged.[13] |
| Article 15 Supervision of Union entities | The Commission would supervise any Union entity that provides Wallets.[1] | The Commission would supervise Union entities other than the Union institutions, acting with complete independence.[13] |
Public sector bodies
| Article | Commission proposal | Council general approach |
|---|---|---|
| Article 16 Obligations on public sector bodies | 24 months after entry into force, public sector bodies would have to let businesses identify, sign or seal, submit documents and send or receive notifications with a Wallet. For documents and notifications they would need a Wallet of their own, with qualified electronic registered delivery. Existing alternatives could stand in until 36 months after entry into force.[1] | The fixed deadline, the requirement to hold a Wallet and the derogation are deleted. Member States would take appropriate organisational and technical measures, and the obligation would apply two years after the last implementing acts apply (see Article 22).[13] |
Third countries
| Article | Commission proposal | Council general approach |
|---|---|---|
| Article 17 Third-country wallets | The Commission could recognise third-country wallets or frameworks as equivalent, after an assessment, if they interoperate with the eIDAS trust framework.[1] | They would also need an equivalent level of security, and the assessment would have to consider at least data protection, cybersecurity and independence from control by high-risk governments.[13] |
| Article 18 Businesses outside the Union | Member States would cooperate so that no business established outside the Union receives more than one set of identification data.[1] | National supervisory bodies would do so, and could use the European Digital Directory for it. The representative carrying out onboarding would also have their identity verified.[13] |
Review and timing
| Article | Commission proposal | Council general approach |
|---|---|---|
| Article 21 Evaluation and review | The Commission would report on the Regulation three years after entry into force.[1] | Five years after entry into force, and the report would cover time and cost savings where available, uptake, and a specific assessment of the impact on micro, small and medium-sized enterprises.[13] |
| Article 22 Entry into force and application | The Regulation would apply one year after entry into force.[1] | Some provisions, including those on implementing acts and on supervision, would apply from entry into force, most of the Regulation one year after the last of the listed implementing acts applies, and Article 16 two years after that. Most implementing acts would be due within one year of entry into force. None of these dates is known, because the Regulation has not been adopted.[13] |
What about the European Parliament?
Parliament has not yet adopted its position. Its lead committee, ITRE, voted on 10 September 2026 to adopt its report and to open interinstitutional negotiations, and the report (A10-0240/2026) was tabled for plenary on 23 September 2026. Parliament's procedure file lists the file as awaiting Parliament's first-reading position.[4]
This page compares the Council's text only. Parliament's changes would be added alongside once Parliament has adopted its position. See where the file stands
