Chapter I: Subject matter, scope and definitions
Article 1: Subject matter
Sets out what the Regulation would do: create a framework for providing European Business Wallets, give actions taken through a Wallet the same legal effect as their paper or in-person equivalent, set rules for identifying Wallet owners, establish a European Digital Directory and a unique identifier for every owner, lay down how Wallet providers are notified, place obligations on public sector bodies, and open the framework to third countries.[1]
Article 2: Scope
The Regulation would cover providing and accepting European Business Wallets, issuing and accepting the data that identifies their owners, and the use of Wallets by economic operators and public sector bodies. It would leave untouched the systems Union law already mandates for exchanging documents and data between competent authorities.[1]
Article 3: Definitions
Defines 43 terms. A European Business Wallet would be a digital solution that lets its owner store, manage and present identification data and electronic attestations of attributes, use signatures, seals, registered delivery and time stamps, and create and delegate mandates to authorised representatives. An "economic operator" would be any natural or legal person acting in a commercial or professional capacity, which brings sole traders and the self-employed within scope. Many of the remaining terms are taken over directly from the eIDAS Regulation.[1][7][8]
Chapter II: European Business Wallets
Article 4: Principle of equivalence
An action taken with one of the core functionalities in Article 5(1) would have the same legal effect as the same action lawfully carried out in person, on paper, or by any other compliant means. The same would apply when a self-employed person or sole trader uses the qualified electronic registered delivery service as a standalone service, without a Business Wallet.[1]
Article 5: Core functionalities of European Business Wallets
Lists 14 functionalities every Wallet would have to offer. They include issuing, storing and presenting electronic attestations of attributes with selective disclosure; qualified electronic signatures, seals and time stamps; sending and receiving documents through a qualified electronic registered delivery service; letting several users operate one Wallet under authorisations the owner can manage and revoke; exporting all data in a machine-readable format; and a log of all transactions. Providers could add further functionalities as long as they do not compromise these, and would have to offer the registered delivery service on its own to users of European Digital Identity Wallets.[1]
Article 6: Technical features for European Business Wallets
Wallets would need common protocols and interfaces for issuing and presenting identification data and attestations, for interaction with other Wallets and with European Digital Identity Wallets, for automated use without manual intervention, and for remote onboarding through an authorised representative whose electronic identification meets assurance level "substantial" or "high". Each owner would get at least one unique digital address. Role-to-attribute mappings would have to be auditable and revocable, and conflicting roles, over-delegation and expired authorisations detected and prevented in real time.[1][10]
Article 7: Requirements and obligations for providers of European Business Wallets
Only providers on the Commission's list could provide Wallets. They would have to be established in the Union, have their principal place of business and main operations there, and not be subject to control by a third country or a third-country entity. They would also have to meet the cybersecurity requirements of Directive (EU) 2022/2555 (NIS2), inform owners clearly about terms and data portability, and, if they stop providing Wallets or are removed from the list, notify owners and transfer or delete their data as the owners instruct.[1]
Article 8: European Business Wallet owner identification data
The data that identifies a Wallet owner would be issued as a qualified electronic attestation of attributes by a qualified trust service provider, as an attestation issued by or on behalf of the public sector body responsible for an authentic source, or, for Union entities, by the Commission. It would contain at least the owner's official name as recorded in the relevant register and its unique identifier under Article 9. Member States would notify the authentic sources used to verify it.[1][8]
Article 9: Unique identifiers
Where an economic operator already has a European Unique Identifier (EUID), the identifier used in company law, that would be its identifier. Owners without one would receive a unique identifier created under an implementing act, which would also prevent any owner from being given more than one.[1][9]
Article 10: European Digital Directory
The Commission would run a European Digital Directory, with an API for system-to-system use and a secure web portal, acting as the trusted source of information about Wallet owners. Only Wallet owners, their authorised representatives and Wallet providers could access it. Providers would have to pass on any change to the information within one working day.[1]
Article 11: Notification of providers of European Business Wallets
An entity that wants to provide Wallets would notify its national supervisory body, describing how its Wallets deliver the core functionalities and declaring conformity. The supervisory body would have 30 days to review the notification; if it gives no substantive response in that time, the notification would be treated as complete. Qualified trust service providers would skip the review and could offer Wallets immediately. A refusal could be challenged in court.[1]
Article 12: List of notified providers of European Business Wallets
Supervisory bodies would pass provider registrations, changes and removals to the Commission, reporting changes within 24 hours. The Commission would publish the resulting list of Wallet providers on its website in a machine-readable format.[1]
Article 13: Governance and supervision
The supervisory bodies Member States already designate under eIDAS would also supervise Wallet providers established in their territory, through what the proposal calls ex post supervision. Their tasks would include investigating complaints, checking termination plans and removing non-compliant providers from the list. Member States would set penalties, including administrative fines of up to 2% of a provider's total worldwide annual turnover. Where a national authority fails to act and the internal market is at risk, the Commission could step in and, among other measures, temporarily suspend a provider from the list.[1][8]
Article 14: European Digital Identity Cooperation Group
The cooperation group of Member States and the Commission already set up under eIDAS would also handle European Business Wallets, sharing best practice and coordinating implementation.[1][8]
Article 15: Governance and supervision of Union entities that are providers of European Business Wallets
Where an EU institution, body, office or agency provides Wallets, the Commission rather than a national authority would supervise it, carrying out the relevant supervisory tasks from Article 13 and reporting on its activities.[1]
Chapter V: Final provisions
Article 19: Committee procedure
The implementing acts the Regulation calls for would be adopted with the assistance of the committee already set up under the eIDAS Regulation.[1][7]
Article 20: Amendment to Regulation (EU) No 910/2014
Would amend Article 5a of the eIDAS Regulation, the provision on European Digital Identity Wallets, so that it refers to natural persons, including a natural person representing a legal person. It would also restate that using a European Digital Identity Wallet is voluntary for natural persons, and that not using one must not restrict their access to services, the labour market or the freedom to conduct business.[1][7][8]
European Business Wallet vs EU Digital Identity Wallet →
Article 21: Evaluation and review
Three years after entry into force, the Commission would report to Parliament and the Council on how well the Regulation works. The report would cover the core functionalities, provider compliance, penalties and the registered delivery service, and would assess whether the scope should change, including whether to make use of the Wallets an obligation.[1]
Article 22: Entry into force and application
The Regulation would enter into force on the twentieth day after its publication in the Official Journal, and would apply one year after that. It has not been adopted, so neither date is known.[1]