---
id: reg-eu-business-wallets
title: European Business Wallets
description: The full text of the proposed EU Regulation on the establishment of European Business Wallets (COM(2025) 838 final), a Commission proposal not yet adopted.
sidebar_label: European Business Wallets (proposed)
keywords: [European Business Wallet, EBW, COM(2025) 838, 2025/0358(COD), eIDAS, digital identity, legislative proposal, ordinary legislative procedure]
slug: /reg-eu-business-wallets/
---

> **Build this with an AI coding agent.** Install the iGrant.io Agent Skills, then ask your agent to build the integration:
>
> ```bash
> npx skills add L3-iGrant/skills
> ```

<head>
   <title>European Business Wallets: proposed EU Regulation | iGrant.io DevDocs</title>
   <meta name="description" content="The full text of the proposed EU Regulation on the establishment of European Business Wallets (COM(2025) 838 final), a Commission proposal not yet adopted."/>
</head>

<span className="status-chip status-chip--proposed">Proposed</span>

:::caution Not yet adopted: this is a proposal
This page reproduces the text of a **Commission legislative proposal**, not an act that is in force. On 19 November 2025 the European Commission tabled the **Proposal for a Regulation of the European Parliament and of the Council on the establishment of European Business Wallets** (**COM(2025) 838 final**), under the ordinary legislative procedure (procedure reference **2025/0358(COD)**).

As a proposal it has **no legal effect**, and its content, article numbering and timelines **may change** during negotiation between the European Parliament and the Council before any adoption. The articles below are reproduced from the Commission's proposed text; treat them as indicative, not as settled law.
:::

The proposed Regulation would establish **European Business Wallets (EBWs)**, a digital solution allowing an EBW owner (an economic operator or a public sector body) to securely store, manage and present owner identification data and electronic attestations of attributes, to sign and seal, to exchange documents and legally valid notifications, and to manage mandates given to authorised representatives. It builds on the European Digital Identity framework (see the <a href="/regulations/reg-eu-digital-id-framework/">European Digital ID Framework</a>) and extends the wallet concept from natural persons to organisations.

### At a glance

| | |
| --- | --- |
| **Document** | COM(2025) 838 final |
| **Type** | Proposal for a Regulation of the European Parliament and of the Council |
| **Procedure** | 2025/0358(COD), ordinary legislative procedure |
| **Proposed on** | 19 November 2025, by the European Commission (Brussels) |
| **Legal basis** | Article 114 of the Treaty on the Functioning of the European Union (TFEU) |
| **Status** | Proposed, not yet adopted |

The full text of the proposal, including its recitals, is available on EUR-Lex [here](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52025PC0838). The enacting terms and the Annex are reproduced below.


## Chapter I - Subject matter, scope and definitions

### Article 1: Subject matter

This Regulation enables secure digital identification and authentication, data sharing and legally valid notifications, reduces administrative burdens and compliance costs, and supports cross-border business and competitiveness. In particular, it:

- (1) establishes a framework for the provision of European Business Wallets;
- (2) establishes the principle of equivalence, giving equivalent legal effect to actions and transactions carried out through a European Business Wallet as to actions and transactions lawfully carried out in person, in paper form, or via any other means or processes that would be deemed compliant with applicable legal, administrative, or procedural requirements;
- (3) establishes rules for the issuance of European Business Wallet owner identification data for the identification of economic operators and public sector bodies;
- (4) establishes the European Digital Directory;
- (5) designates the European unique identifier (EUID), as established and governed by Directive (EU) 2017/1132, as the unique identifier for European Business Wallet owners, and establishes a similar unique identifier for European Business Wallets owners to whom the European Unique Identifier is not available;
- (6) lays down the notification mechanism under which providers of European Business Wallets shall be established;
- (7) lays down obligations for public sector bodies concerning European Business Wallets;
- (8) provides a framework for the supervision of Union entities, where such public sector bodies provide European Business Wallets;
- (9) provides a framework for the recognition of third-country systems similar to the European Business Wallets and the issuance of European Business Wallets to third country economic operators.

### Article 2: Scope

**1.** This Regulation applies to the provision and acceptance of European Business Wallets and the issuance and acceptance of European Business Wallet owner identification data, and to the use of European Business Wallets by economic operators and public sector bodies.

**2.** This Regulation is without prejudice to the existing systems and procedures mandated by Union law governing the exchange of documents and data between competent authorities.

### Article 3: Definitions

For the purposes of this Regulation, the following definitions apply:

  - (1) ‘European Business Wallet’ means a digital solution that allows European Business Wallet owners to securely store, manage, and present European Business Wallet owner identification data and electronic attestations of attributes to Business Wallet-relying parties and other entities using European Business Wallets and European Digital Identity Wallets for the following purposes:
    - (a) to authenticate and provide the verified proofs required by a relying party;
    - (b) to access and use electronic attestations of attributes, electronic signatures, electronic seals, electronic registered delivery services, and electronic time stamps;
    - (c) to enable the creation, management and delegation of mandates to authorised representatives;

and that may support additional functionalities in accordance with this Regulation;

  - (2) ‘European Business Wallet owner identification data’ means a set of data that enables the establishment of the identity of a European Business Wallet owner and that is issued by a provider of European Business Wallet owner identification data;
  - (3) ‘provider of European Business Wallet owner identification data’ means a qualified trust service provider or public sector body or the Commission issuing European Business Wallet owner identification data;
  - (4) ‘economic operator’ means any natural or legal person, or a group of such persons, including temporary associations of undertakings, acting in a commercial or professional capacity for purposes related to their trade, business, craft or profession;
  - (5) ‘public sector body’ means a Union entity, a national, state, regional or local authority, a body governed by public law or an association formed by one or several such entities or bodies, or a private entity mandated by at least one such entities, authorities, bodies or associations to provide public services, when acting under such a mandate;
  - (6) ‘Union entity’ means a Union institution, body, office and agency set up by or pursuant to the Treaty on European Union, the Treaty on the Functioning of European Union or the Treaty establishing the European Atomic Energy Community;
  - (7) ‘European Business Wallet owner’ means an economic operator or public sector body that owns or has a right of use of a European Business Wallet;
  - (8) ‘trust service’ means trust service as defined in Article 3, point (16) of Regulation (EU) 910/2014;
  - (9) ‘attribute’ means attribute as defined in Article 3, point (43) of Regulation (EU) 910/2014;
  - (10) ‘electronic attestations of attributes’ means electronic attestations of attributes as defined in Article 3, point (44) of Regulation (EU) No 910/2014;
  - (11) ‘qualified attestation of attributes’ means qualified attestation of attributes as defined in Article 3, point (45) of Regulation (EU) No 910/2014;
  - (12) ‘European Digital Identity Wallet’ means European Digital Identity Wallet as defined in Article 3, point (42) of Regulation (EU) No 910/2014;
  - (13) ‘electronic signature’ means an electronic signature as defined in Article 3, point (10) of Regulation (EU) No 910/2014;
  - (14) ‘qualified electronic signature’ means a qualified electronic signature as defined in Article 3, point (12) of Regulation (EU) No 910/2014;
  - (15) ‘electronic seal’ means an electronic seal as defined in Article 3, point (25) of Regulation (EU) No 910/2014;
  - (16) ‘qualified electronic seal’ means qualified electronic seal as defined in Article 3, point (27) of Regulation (EU) No 910/2014;
  - (17) ‘qualified electronic stamp’ means a qualified electronic stamp as defined in Article 3, point (34) of Regulation (EU) No 910/2014;
  - (18) ‘authorised representative’ means a natural or legal person acting on behalf of the European Business Wallet owner in executing and operating functions of a designated European Business Wallet on the basis of an authorisation granted by a European Business Wallet owner;
  - (19) ‘mandate’ means the authorisation granted by a European Business Wallet owner to an authorised representative, enabling that representative to act on behalf of the owner in executing and operating functions of a designated European Business Wallet;
  - (20) ‘electronic document’ means an electronic document as defined in Article 3, point (35) of Regulation (EU) No 910/2014;
  - (21) ‘qualified electronic registered delivery service’ means a qualified electronic registered delivery service as defined in Article 3, point (37) of Regulation (EU) No 910/2014;
  - (22) ‘user’ means a natural or legal person, or a natural person representing another natural person or a legal person, that uses European Business Wallets or European Business Wallet electronic identification means provided in accordance with this Regulation;
  - (23) ‘European Business Wallet-relying party’ means a natural person, an economic operator or public sector body that relies upon European Business Wallets;
  - (24) ‘wallet unit attestation’ means a data object that describes the components of the European Business Wallet unit or allows authentication and validation of those components;
  - (25) ‘European Business Wallet unit’ means a unique configuration of a European Business Wallet solution that includes European Business Wallet front-end and European Business Wallet back-end, wallet secure cryptographic applications and wallet secure cryptographic devices provided by a provider to a European Business Wallet to a specific European Business Wallet owner;
  - (26) ‘European Business Wallet solution’ means a combination of software, hardware, services, settings, and configurations, including European Business Wallet front-end and back-end, one or more wallet secure cryptographic applications and one or more wallet secure cryptographic devices;
  - (27) ‘critical assets’ means assets within or in relation to a European Business Wallet unit of such extraordinary importance that where their availability, confidentiality or integrity are compromised, that would have a very serious, debilitating effect on the ability to rely on the European Business Wallet unit;
  - (28) ‘wallet secure cryptographic application’ means an application that manages critical assets by being linked to and using the cryptographic and non-cryptographic functions provided by the wallet secure cryptographic device;
  - (29) ‘wallet secure cryptographic device’ means a tamper-resistant device that provides an environment that is linked to and used by the wallet secure cryptographic application to protect critical assets and provide cryptographic functions for the secure execution of critical operations;
  - (30) ‘trust service provider’ means a trust service provider as defined in Article 3, point (19) of Regulation (EU) No 910/2014;
  - (31) ‘qualified trust service provider’ means qualified trust service provider as defined in Article 3, point (20) of Regulation (EU) No 910/2014;
  - (32) ‘electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source’; means a electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source as defined in Article 3, point (46) of Regulation (EU) No 910/2014;
  - (33) ‘authentic source’ means authentic source as defined in Article 3, point (47) of Regulation (EU) No 910/2014;
  - (34) ‘attestation scheme’ means a set of rules applicable to one or more types of electronic attestation of attributes;
  - (35) ‘catalogue of schemes means a digital repository listing schemes for the attestation of attributes registered in accordance with this Regulation and that is maintained and published online by the Commission;
  - (36) ‘European unique identifier’ means the European Unique Identifier referred to in Directive (EU) 2017/1132;
  - (37) ‘national register’ means an official database or system established and maintained by or on behalf of a national government or its designated authority, which records, stores, and manages information pertaining to legal entities, including but not limited to companies, partnerships, foundations, associations as well as businesses as natural persons such as sole-traders and self-employed persons or other registrable persons or organisations;
  - (38) ‘API’ or ‘Application Programming Interface’ means a set of definitions and protocols for building and integrating application software to share data;
  - (39) ‘submission’ or ‘submit 'means any transmission of structured or unstructured data, files, forms, or records by between a public sector body and an economic operator or between economic operators or between public sector bodies, where such transmission is required, requested, or permitted under Union or national law, and is intended to support a legal, administrative, or procedural purpose;
  - (40) ‘notification’ means any transmission of information, decisions, requests, or acknowledgements between a public sector body and an economic operator or between economic operators or between public sector bodies, which is required, requested, or permitted under Union or national law, and which is intended to produce legal effects or inform the recipient of rights, obligations, or procedural developments;
  - (41) ‘administrative procedure’ means a sequence of actions, defined by Union or national law, that must be taken by economic operators or public sector bodies to comply with obligations, provide information, or obtain a decision, authorisation, or benefit from a public sector body in the exercise of administrative functions;
  - (42) 'European Business Wallet front-end' means the user interface component, regardless of platform or form factor, that interacts with users acting on behalf of the owner, and is part of the European Business Wallet unit;
  - (43) 'European Business Wallet back-end' means the server-side components, including software, services, and infrastructure, that provide the necessary functionality and support for the European Business Wallet Frontend, and form part of the European Business Wallet unit.

## Chapter II – European Business Wallets

### Article 4: Principle of equivalence

Where a European Business Wallet owner makes use of any of the core functionalities of a European Business Wallet referred to in Article 5(1), the resulting action shall have the same legal effect as if the action had been lawfully carried out in person, in paper form, or via any other means or processes that would be deemed compliant with applicable legal, administrative, or procedural requirements.

Where a self-employed person or a sole trader makes use of the qualified electronic registered delivery service in the circumstances set out in Article 5(3), the resulting action shall have the same legal effect as if the action had been lawfully carried out in person, in paper form, or via any other means or processes that would be deemed compliant with applicable legal, administrative, or procedural requirements.

### Article 5: Core functionalities of European Business Wallets

**1.** Providers of European Business Wallets shall ensure that the European Business Wallets they provide enable European Business Wallet owners to make use of the following core functionalities:

  - (a) securely issue, request, obtain, select, combine, store, delete, share and present electronic attestations of attributes;
  - (b) selectively disclose European Business Wallet owner identification data and attributes contained in electronic attestations of attributes, in the context of the functionalities listed in point a;
  - (c) request and share European Business Wallet owner identification data and electronic attestations of attributes in a secured way between European Business Wallets and European Digital Identity Wallets and with European Business Wallet-relying parties;
  - (d) sign by means of qualified electronic signatures and seal by means of qualified electronic seals, as applicable;
  - (e) bind data in electronic form to a particular time by means of qualified electronic time stamps;
  - (f) issue electronic attestations of attributes to European Business Wallets and European Digital Identity Wallets;
  - (g) issue electronic attestations of attributes through the European Business Wallet of the owner, allowing the issued attestation to be linked to other relevant attestations forming part of a chain;
  - (h) enable the use of qualified and non-qualified electronic attestations of attributes to allow European Business Wallet owners and their authorised representatives to authenticate themselves;
  - (i) transmit and receive electronic documents and data by means of a qualified electronic registered delivery service capable of supporting confidentiality and integrity;
  - (j) authorise multiple users to access and operate the European Business Wallet of the owner, and for the European Business Wallet owner to manage and revoke such authorisations;
  - (k) authorise European Business Wallet-relying parties to request electronic attestations of attributes issued to the European Business Wallet owner, and for the European Business Wallet owner to manage and revoke such authorisations;
  - (l) export their data, including issued European Business Wallet owner identification data, electronic attestations of attributes, communication logs, and interaction records, in a structured, commonly used and machine-readable format, at the request of the owner or in the event of termination of service or revocation of the notification of the provider of the European Business Wallet;
  - (m) access a log of all transactions;
  - (n) access a common dashboard for accessing, storing and verifying communications exchanged through the qualified electronic registered delivery service referred to in point (i).

**2.** Providers of European Business Wallets may offer additional functionalities beyond those listed in paragraph 1 provided that such functionalities do not interfere with or compromise the confidentiality, availability, or integrity of the minimum core functionalities, and the reliability and interoperability of the European Business Wallets they provide.

**3.** Providers of European Business Wallets shall enable the provision of the qualified electronic registered delivery service referred to in paragraph 1, point (i) as a standalone service to users of European Digital Identity Wallets.

**4.** Providers of European Business Wallets shall implement the functionalities referred to in paragraph 1 in accordance with requirements set out in the Annex.

**5.** The Commission shall, by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the core functionalities of European Business Wallets referred to in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.

### Article 6: Technical features for European Business Wallets

**1.** Providers of European Business Wallets shall ensure that the European Business Wallets they provide support common protocols and interfaces:

  - (a) for the issuance of European Business Wallet owner identification data, qualified and non-qualified electronic attestations of attributes and qualified and non-qualified certificates to European Business Wallets;
  - (b) for European Business Wallet-relying parties to request and validate European Business Wallet owner identification data and electronic attestations of attributes;
  - (c) for the sharing and presenting to European Business Wallet-relying parties of European Business Wallet owner identification data, electronic attestation of attributes and of selectively disclosed data;
  - (d) to allow interaction with the European Business Wallets automatically without manual intervention or through direct user action;
  - (e) to securely onboard the European Business Wallet owner remotely via an authorised representative with an electronic identification means of that authorised representative which meets the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels ‘substantial’ or ‘high’;
  - (f) for interaction between European Business Wallets, and between European Business Wallets and European Digital Identity Wallets for the purpose of receiving, validating and sharing European Business Wallet owner identification data and electronic attestations of attributes in a secure manner;
  - (g) for authenticating European Business Wallet-relying parties by implementing authentication mechanisms, where authentication is required;
  - (h) for European Business Wallet-relying parties to verify the authenticity and validity of European Business Wallets, where the verification of the authenticity and validity is required;
  - (i) for the provision of the qualified electronic registered delivery service referred to in Article 5(1), point (i), including an interface to the European Digital Directory established pursuant to Article 10;
  - (j) for the assigning to each European Business Wallet owner, for the purposes of the qualified electronic registered delivery service referred to in Article 5(1), point (i) and the European Digital Directory referred to in Article 10, at least one unique digital address;
  - (k) for the provision of wallet unit attestations to all European Business Wallet units, containing public keys and corresponding private keys protected by a wallet secure cryptographic device;
  - (l) for the management of critical assets, for the use of at least one wallet secure cryptographic application and wallet secure cryptographic device and, where critical assets relate to performing electronic identification at assurance level substantial, for ensuring that such cryptographic operators or other operations processing critical assets are performed in accordance with the requirements for the characteristics and design of electronic identification means at assurance level substantial as set out in Commission Implementing Regulation (EU) 2015/1502.

**2.** Providers of European Business Wallets shall also:

  - (a) ensure that the European Business Wallet owner identification data is digitally associated with the European Business Wallet of the owner;
  - (b) ensure that, for the purposes of the functionality referred to in Article 5(1), point (j):
    - mappings between roles and attributes are verifiable, auditable, revocable and traceable to their legitimate issuers;
    - conflicts of roles, over-delegation, or expired authorisations are automatically detected and prevented in real time;
    - all authorisation logic is interoperable across Member States.
  - (c) ensure security-by-design;
  - (d) provide validation mechanisms, in order to ensure that the authenticity and validity of European Business Wallets can be verified;
  - (e) provide a mechanism enabling European Business Wallet owners to easily request technical support and report technical problems or any other incidents having a negative impact on the use of European Business Wallets;
  - (f) ensure that the validity of the European Business Wallets can be revoked in the following circumstances:
    - upon the explicit request of the European Business Wallet owner;
    - where the security of the European Business Wallet has been compromised;
    - upon the permanent or temporary cessation of activity of the European Business Wallet owner;
    - where the provider of the European Business Wallet is not included in the list referred to in Article 12(5).
  - (g) without undue delay, notify to the Commission:
    - the mechanism allowing for the validation of the European Business Wallet owner identification data;
    - the mechanism by which to validate the authenticity and validity of European Business Wallets.

**3.** The Commission shall make available the information notified pursuant to paragraph 2, point (g) of this Article to the public through a secure channel, in electronically signed or sealed form suitable for automated processing.

**4.** Providers of European Business Wallets shall implement the technical features provided for in paragraphs 1 and 2 in accordance with the requirements set out in the Annex.

**5.** The Commission shall, by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the technical features of European Business Wallets provided for in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.

### Article 7: Requirements and obligations for providers of European Business Wallets

**1.** European Business Wallets shall be provided by providers of European Business Wallets that are included in the list established pursuant to Article 12(5).

**2.** Given the role of European Business Wallets in the Unions digital infrastructure, providers of European Business Wallets shall be established in the Union, have their principal place of business and main operations in the Union and not present a risk to the security of the Union. In particular they shall not be subject to control by a third country or by a third-country entity.

**3.** Providers of European Business Wallets shall comply with the requirements set out in Article 19a of Regulation (EU) 910/2014. That obligation shall not apply to providers of European Business Wallets that are qualified trust service providers.

**4.** Providers of European Business Wallets shall comply with the requirements set out in Directive (EU) 2022/2555 of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union.

**5.** Providers of European Business Wallets shall comply with applicable cybersecurity requirements laid down in Union and national law, including those relating to the identification of high-risk suppliers. Providers shall also ensure that their suppliers of software and security solutions comply with these requirements and conform to the relevant security standards and requirements.

**6.** Providers of European Business Wallets shall:

  - (a) implement appropriate technical and organisational measures to ensure the confidentiality, integrity, authenticity, interoperability, and availability of the European Business Wallets they provide with other European Business Wallets and European Digital Identity Wallets;
  - (b) ensure that European Business Wallet owners are clearly informed, in a user-friendly, concise and accessible manner, about the terms and conditions of use of the European Business Wallet, including the scope and limitations of core and additional functionalities, cybersecurity standards, and the European Business Wallet owner’s rights with regard to data portability, redress, and termination of service;
  - (c) ensure that authorised representatives of European Business Wallet owners are clearly informed, in a user-friendly, concise and accessible manner, about their rights and obligations in relation to their European Business Wallet unit, in particular, the right to request revocation of their wallet unit attestation, using the authentication mechanism provided in point 1 of the Annex;
  - (d) cooperate with the competent supervisory bodies referred to in Article 13(1), or with the Commission in the cases referred to in Article 13(10) and 14(1) and respond without undue delay to any request for information or documentation necessary to verify compliance with this Regulation;
  - (e) notify the relevant national supervisory bodies, or the Commission in the cases referred to in Article 14(1), of any substantive changes to their services or overall structure which may impact the compliance of the provider with this Regulation;
  - (f) notify European Business Wallet owners in the event of suspension, revocation or voluntary termination of the providers of European Business Wallet`s services and of the removal of the provider of European Business Wallet from the list established pursuant to Article 12(5) and ensure the transfer or deletion of the European Business Wallet owner data in accordance with the European Business Wallet owners instructions, including European Business Wallet owner identification data;
  - (g) ensure that the information on European Business Wallet owners, pursuant to Article 10(2), is notified to the Commission and that the information initially submitted to the Commission is kept up to date and corroborated using the providers of the European Business Wallet owner identification data issuing the unique identifiers referred to in Article 8(5), point (b).

### Article 8: European Business Wallet owner identification data

**1.** Providers of European Business Wallet owner identification data shall issue European Business Wallet owner identification data to European Business Wallets of European Business Wallet owners. Where European Business Wallet owners are Union entities, the Commission shall issue European Business Wallet owner identification data to the European Business Wallets of those Union entities.

**2.** Member States shall notify to the Commission the relevant authentic sources for the verification of the required attributes for the issuance of the European Business Wallet owner identification data. On the basis of the information received pursuant to this paragraph, the Commission shall make available on the Commission’s website, in a machine-readable format, a list of the notified relevant authentic sources.

**3.** European Business Wallet owner identification data shall be issued in a format compliant with one of the standards listed in Annex II of Commission Implementing Regulation (EU) 2024/2979 and as:

  - (a) qualified electronic attestations of attributes, when provided by qualified trust service providers;
  - (b) electronic attestations of attributes issued by or on behalf of a public sector body responsible for an authentic source, when provided by a public sector body so responsible;
  - (c) electronic attestations of attributes, when provided by the Commission.

**4.** European Business Wallet owner identification data issued by the Commission shall have the same legal effect as qualified electronic attestations of attributes and attestations of attributes issued by, or on behalf of, a public sector body responsible for an authentic source.

**5.** European Business Wallet owner identification data shall contain at least the following attributes:

  - (a) the official name of the economic operator or public sector body, as recorded in the relevant register or official record;
  - (b) the relevant unique identifier attributed in accordance with Article 9.

**6.** The Commission shall establish and maintain an attestation scheme for European Business Wallet owner identification data. That scheme shall be listed in the catalogue of schemes for the attestation of attributes referred to in Article 8 of Implementing Regulation (EU) 2025/1569.

**7.** The Commission may, by means of implementing acts, set out requirements for European Business Wallet owner identification data issued pursuant to this Article, including procedures for Member States to notify to the Commission the relevant authentic sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.

### Article 9: Unique identifiers

**1.** Where an economic operator has been attributed a European Unique Identifier, that identifier shall be used as the unique identifier referred to in Article 8(4), point (b) of this Regulation.

**2.** Where an economic operator or public sector body has not been attributed a European Unique Identifier, a unique identifier shall be created in accordance with the implementing act referred to in paragraph 4.

**3.** Where a public sector body is a Union entity, the Commission shall create and attribute a unique identifier to that Union entity in accordance with paragraph 4 of this Article.

**4.** The Commission shall, by means of implementing acts, establish specifications, requirements and procedures relating to the unique identifier referred to in paragraph 2 of this Article, including measures to ensure that European Business Wallet owners are not attributed more than one unique identifier. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.

### Article 10: European Digital Directory

**1.** The Commission shall establish, operate and maintain a European Digital Directory which shall act as the trusted source of information for European Business Wallet owners and shall take the form of a web application comprising of two interfaces:

    - (a) a machine-readable interface exposed through an API for automated system-to-system communication;
    - (b) a secure, web-based platform that provides access to authenticated and authorised users and system online portal for European Business Wallet users.

**2.** For the purpose of maintaining the European Digital Directory, providers of European Business Wallets shall, upon the provision of a European Business Wallet, provide to the Commission the categories of information set out in the implementing act referred to in paragraph 6

**3.** The Commission shall ensure that the relevant information shall be included in the European Digital Directory.

**4.** The Commission shall make the European Digital Directory only accessible to European Business Wallet owners and their authorised representatives and providers of European Business Wallets.

**5.** Any modification or revocation concerning the information referred to in paragraph 2 shall, without undue delay and in any event within one working day, be communicated by the providers of European Business Wallet directly to the Commission for the purpose of maintaining the European Digital Directory.

**6.** The Commission shall, by means of implementing acts, establish standards and technical specifications for the unique digital addresses and the categories of information to be communicated to the Commission for the purpose of the European Digital Directory. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.

### Article 11: Notification of providers of European Business Wallets

**1.** Entities that intend to provide European Business Wallets shall notify that intention together with the information listed in paragraph 2 to the competent supervisory body.

**2.** The notification referred to in paragraph 1 shall include the following information:

    - (a) the entity’s legal name, any commercial names used, website URL, contact email, telephone number, and physical address;
    - (b) the entity’s register number issued by a national register, where available
    - (c) a description of how the core functionalities, set out in Article 5(1) shall be offered by the European Business Wallets the entity intends to provide;
    - (d) a description of any additional functionalities supported by the European Business Wallets the entity intends to provide;
    - (e) a declaration of conformity with the requirements of this Regulation.

**3.** Qualified trust service providers shall not be subject to the review and verification procedure set out in paragraphs 4 to 6. Upon submitting the information listed in paragraph 2, the competent supervisory body shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(5) and it may immediately offer European Business Wallets.

**4.** Upon receipt of a notification, the supervisory body shall have 30 days to review the information submitted.

When that review leads the supervisory body to conclude that the information is complete and the description referred to in paragraph 2 point (c) appears to correspond to the requirements laid down in Article 5(1), it shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(5).

**5.** When that review leads the supervisory body to conclude that the information is not complete or the description referred to in paragraph 2 point (c) appears not to correspond to the requirements laid down in Article 5(1), it shall request additional information or explanations from the notifying entity and set a reasonable deadline, not exceeding 15 calendar days, for response. If that information or those explanations allow the supervisory body to conclude that the information is complete and the description referred to in paragraph 2 point (c) appears to correspond to the requirements laid down in Article 5(1), it shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(5). If not, or no response is received, the supervisory body shall inform the notifying entity that it will not be added to the list referred to in Article 12(5).

**6.** Where the supervisory body has not provided the notifying entity with a substantive response on the outcome of the review referred to in paragraph 4 within 30 calendar days of receiving the notification, the information shall be considered as complete and the description referred to in paragraph 2 point (c) shall be considered as appearing to correspond to the requirements laid down in Article 5(1), and the supervisory body shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(5)

**7.** Member States shall ensure that notifying entities have the right to an effective judicial remedy against a decision of the supervisory authority, without prejudice to any other administrative or non-judicial remedy, in cases where the supervisory authority refuses to list them as a provider of European Business Wallets or takes no decision within a reasonable timeframe.

### Article 12: List of notified providers of European Business Wallets

**1.** Supervisory bodies shall inform the Commission of any changes to the information provided pursuant to Article 11, within 24 hours of having become aware of any changes.

**2.** The information provided by the supervisory bodies referred to in Article 11 and Article 12(1) shall include the following:

    - (a) the purpose of the submission, which may be one of the following:
    - the registration of a notified provider of European Business Wallets not previously present on the list referred to in paragraph 5;
    - a change to previously submitted information regarding providers of European Business Wallets currently present on the list referred to in paragraph 5;
    - a request to remove a provider of European Business Wallets from the list referred to in paragraph 5;
    - (b) name and, where applicable, the commercial name of the provider of European Business Wallets;
    - (c) the Member State in which the provider of European Business Wallets has its principal place of establishment;
    - (d) the name of the competent supervisory body;
    - (e) an indication whether the provider of European Business Wallets is a qualified trust service provider.

**3.** On the basis of the information received pursuant to this Article, the Commission shall establish and maintain on the Commission’s website, in a machine-readable format, a list of providers of European Business Wallets.

### Article 13: Governance and supervision

**1.** In each Member State, the supervisory bodies designated pursuant to Article 46a of Regulation (EU) No 910/2014 shall also be the supervisory bodies for the purposes of this Regulation.

**2.** Those supervisory bodies shall be responsible for supervisory tasks as regards providers of European Business Wallets having their principal place of establishment in that Member State.

**3.** Member States shall ensure that the supervisory bodies referred to in paragraph 1 have the necessary powers and adequate resources for the exercise of their tasks in an effective, efficient and independent manner.

**4.** The role of national supervisory bodies referred to in paragraph 1 shall be to:

  - (a) monitor compliance with the requirements laid down in this Regulation and take action, if necessary, in relation to providers of European Business Wallets, by means of ex post supervisory activities;
  - (b) act as the main liaison office for providers of European Business Wallet owner identification data, facilitating access to information from relevant national authorities and registries, where necessary, for the issuance of European Business Wallet owner identification data and unique identifiers.

**5.** The tasks of the supervisory bodies referred to in paragraph 1 shall include the following:

  - (a) review and assess the notifications submitted in accordance with Article 11;
  - (b) investigate substantiated claims, particularly those made by European Business Wallets owners, that a provider of European Business Wallets fails to comply with any of its obligations under this Regulation and to take action if necessary;
  - (c) verify the existence and correct application of termination plans where a provider of European Business Wallets ceases its activities, including how information is kept accessible;
  - (d) ensure that providers of European Business Wallets remedy any failure to fulfil the requirements laid down in this Regulation;
  - (e) impose penalties in accordance with paragraphs 6 to 9;
  - (f) inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant security breach or loss of integrity of which it becomes aware in the performance of its tasks and, in the case of a significant security breach or loss of integrity which concerns other Member States, to inform the single point of contact designated or established pursuant to Article 8(3) Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of Regulation (EU) No 910/2014 in the other Member States concerned, and to inform the public or require the provider of European Business Wallets to do so where the supervisory body determines that disclosure of the breach of security or loss of integrity would be in the public interest;
  - (g) cooperate with supervisory authorities established pursuant to Article 51 of Regulation (EU) 2016/679, in particular, by informing them, without undue delay, where personal data protection rules appear to have been breached and about security breaches which appear to constitute personal data breaches;
  - (h) cooperate, as appropriate, with other national supervisory bodies;
  - (i) set up and ensure clear publicity of a complaint mechanism whereby complaints can be filed by providers of European Business Wallets in accordance with Article 11(7);
  - (j) report to the Commission on its main activities;
  - (k) revoke the inclusion in the list established pursuant to Article 12(5) of a provider of European Business Wallets if the supervisory body determines that the provider no longer meets the requirements laid down in this Regulation or that the provider has failed to comply with the obligations imposed by this Regulation;
  - (l) cooperate with the supervisory authorities designated pursuant to Article 46b of Regulation (EU) No 910/2014 by the Member States, in particular, to ensure that economic operators established outside the Union are issued only one set of European Business Wallet owner identification data and European business Wallet unique identifier.

**6.** Member States shall lay down the rules allowing the supervisory body referred to in paragraph 1 of this Article to impose penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented. Those penalties shall be effective, proportionate and dissuasive. Those rules shall not affect Article 31 of Directive (EU) 2022/2555 and Article 83 of Regulation (EU) 2016/679.

**7.** By [Publications Office, insert the date 12 months after the entry into force of this Regulation] Member States shall notify the Commission of the rules laid down by Member States in accordance with paragraph 6 and shall notify the Commission without delay of any subsequent amendments to the rules. The Commission shall regularly update and maintain an easily accessible public register of those rules.

**8.** Member States shall take into account the following non-exhaustive and indicative criteria for the imposition of penalties in accordance with paragraph 6:

  - (a) the nature, gravity, scale and duration of the infringement;
  - (b) any action taken by the infringing party to mitigate or remedy the damage caused by the infringement;
  - (c) any previous infringements by the infringing party;
  - (d) the financial benefits gained or losses avoided by the infringing party due to the infringement, insofar as such benefits or losses can be reliably established;
  - (e) any other aggravating or mitigating factor applicable to the circumstances of the case;
  - (f) the infringing party’s total annual turnover in the preceding financial year in the Union.

Member States shall ensure that infringements of this Regulation committed by providers of European Business Wallets be subject to administrative fines of a maximum of 2% of the total worldwide annual turnover in the preceding financial year.

**9.** Where the legal system of a Member State does not provide for administrative fines being imposed by administrative authorities, fines initiated by the supervisory body and imposed by competent national courts, which have an equivalent effect to the administrative fines imposed by supervisory bodies, shall be considered to comply with the requirements laid down in paragraph 6. In any event, the fines imposed shall be effective, proportionate and dissuasive. That Member State shall notify to the Commission the provisions of the laws which it adopts pursuant to this paragraph by [Publications Office, insert the date 12 months after the entry into force of this Regulation] and, without delay, any subsequent amendment law or amendment affecting them.

**10.** In circumstances which justify an immediate intervention to preserve the proper functioning of the internal market and where the Commission has sufficient reason to consider that the European Business Wallets provided by a provider are non-compliant with the requirements laid down in this Regulation and no effective measures have been taken by the competent supervisory authority, the Commission shall carry out an evaluation of compliance. The Commission shall inform the relevant authorities accordingly and the provider shall cooperate as necessary.

**11.** Based on the evaluation, the Commission may decide that a corrective or restrictive measure is necessary, and after consulting the Member States concerned and the provider, the Commission may determine the appropriate course of action. The Commission shall take into account the nature and severity of the non-compliance, as well as the potential impact on the internal market and the rights of economic operators.

**12.** On the basis of the consultation, the Commission may adopt implementing acts to provide for corrective or restrictive measures, including temporarily suspending the provider from the list of notified providers or requiring the provider to take specific actions to bring the European Business Wallets into compliance with the Regulation. Those implementing acts shall be adopted in accordance with the examination procedure.

**13.** The Commission shall immediately communicate the implementing acts to the provider and Member States shall implement those implementing acts without delay and inform the Commission accordingly. These measures shall be applicable for the duration of the exceptional situation that justified the Commission’s intervention, provided that the European Business Wallets concerned are not brought into compliance with this Regulation.

### Article 14: European Digital Identity Cooperation Group

The European Digital Identity Cooperation Group established pursuant to Article 46e of Regulation (EU) No 910/2014 shall be responsible for facilitating cooperation and information sharing among Member States and the Commission on matters related to the European Business Wallets. This shall include sharing best practices, discussing technical and operational issues, and coordinating efforts to ensure the proper implementation and functioning of the European Business Wallets.

### Article 15: Governance and supervision of Union entities that are providers of European Business Wallets

**1.** Where a Union entity is a provider of European Business Wallets the Commission shall be its supervisory body.

**2.** The role of the Commission acting as a supervisory body in accordance with paragraph 1 shall be to monitor compliance with the requirements laid down in this Regulation and take action, if necessary, in relation to providers of European Business Wallets, by means of ex post supervisory activities.

**3.** When acting as a supervisory body in accordance with paragraph 1, the Commission shall perform the tasks referred to in Article 13(5) points a, b, c, d, h and k.

The Commission shall prepare a report on its main activities in this respect.

## Chapter III – Acceptance of the European Business Wallets

### Article 16: Obligations on public sector bodies

**4.** By [Publications Office, please insert the date 24 months after the entry into force of this Regulation] public sector bodies shall enable economic operators to take the following actions by using the core functionalities of European Business Wallets as set out in Article 5(1):

  - (a) identify and authenticate;
  - (b) sign or seal;
  - (c) submit documents;
  - (d) send or receive notifications.

The actions listed in points (a) to (d) of the first subparagraph shall take place for the purpose of meeting a reporting obligation or fulfilling an administrative procedure.

**5.** For the purposes of paragraph 1, points (c) and (d), public sector bodies shall have European Business Wallets, including the qualified electronic registered delivery service referred to in Article 5(1), point (i).

**6.** By way of derogation from paragraph 2 and until [Publications Office, insert the date 36 months after entry into force of this Regulation], public sector bodies may choose not to offer the qualified electronic registered delivery service referred to in Article 5(1), point (i), and support instead other existing alternative solutions which enable economic operators to take the actions listed in paragraph 1, points (c) and (d), provided those solutions:

    - (a) comply with the requirements applicable to qualified electronic registered delivery services set out in Regulation (EU) No 910/2014;
    - (b) offer a gateway that enables European Business Wallet owners to submit documents and send and receive notifications using the qualified electronic registered delivery service referred to in Article 5(1), point (i).

After the expiry of the derogation period laid down in this paragraph, public sector bodies may continue to support the alternative solutions referred to in that subparagraph but shall, in accordance with paragraph 2, have European Business Wallets, including the qualified electronic registered delivery service referred to in paragraph 1 of Article 5(1), point (i).

## Chapter IV - International aspects

### Article 17: Business wallets and other similar instruments and frameworks offered in third countries

**1.** The Commission may adopt implementing acts establishing that business wallets or systems offering similar functions that are issued by providers established in third countries are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that such business wallets or systems are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.

**2.** The Commission may adopt implementing acts establishing that third country frameworks for systems offering similar functions as the European Business Wallets are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that the systems provided under that framework are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.

**3.** Prior to the adoption of the implementing acts referred to in paragraphs 1 and 2, the Commission shall assess whether the assurances can be considered as equivalent to the requirements under this Regulation.

**4.** The Commission shall, where available information reveals that those assurances can no longer be considered as equivalent to the requirements under this Regulation, to the extent necessary, repeal, amend or suspend the act referred to in paragraphs 1 and 2 by means of an implementing act.

**5.** The Commission shall publish on its website a list of frameworks, business wallets or systems offering similar functions that are issued by providers established in third countries in relation to which the Commission has adopted an implementing act pursuant to this Article.

### Article 18: Issuing of European Business Wallets to economic operators established outside the Union

**1.** Providers of European Business Wallets may provide European Business Wallets to economic operators established in a third country under the condition that such economic operators have been issued European Business Wallet owner identification data and a unique identifier in accordance with this Article.

**2.** For the purposes of this Article, economic operators shall request only one set of European Business Wallet owner identification data from one provider of European Business Wallet owner identification data.

**3.** Where an economic operator established outside the Union requests a European Business Wallet, the provider of European Business Wallets shall notify this request to the supervisory body of the Member State in which the provider is notified.

**4.** Providers of European Business Wallets shall request European Business Wallet owner identification data from a provider of European Business Wallet owner identification data on behalf of the economic operator established in a third country.

**5.** Providers of European Business Wallet owner identification data may issue European Business Wallet owner identification data and unique identifiers pursuant to Articles 8 and 9 to economic operators established outside the Union, provided that:

  - (a) the identity proofing and verification of those economic operators fulfils one or, when needed, a combination, of the methods for verification of identity set out in Article 24 (1a) of Regulation (EU) No 910/2014;
  - (b) the economic operator has not been issued another set of European Business Wallet owner identification data.

**6.** Member States shall cooperate to ensure that providers of European Business Wallet owner identification data can verify that an economic operator established outside the Union has not yet been issued European Business Wallet owner identification data.

## Chapter V – Final provisions

### Article 19: Committee procedure

The Commission shall be assisted by the committee established by Article 48 of Regulation (EU) No 910/2014. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.

### Article 20: Amendment to Regulation (EU) No 910/2014

In Regulation (EU) No 910/2014, Article 5a is amended as follows:

(1) paragraph 1 is replaced by the following:

‘1. For the purpose of ensuring that all natural persons in the Union have secure, trusted and seamless cross-border access to public and private services, while having full control over their data, each Member State shall provide at least one European Digital Identity Wallet within 24 months of the date of entry into force of the implementing acts referred to in paragraph 23 of this Article and in Article 5c(6).’

(2) in paragraph 5 point (f) is replaced by the following:

‘(f) ensure that the person identification data, which is available from the electronic identification scheme under which the European Digital Identity Wallet is provided, uniquely represents the natural person or the natural person representing the natural or legal person, and is associated with that European Digital Identity Wallet;’;

(3) in paragraph 9 point c) is replaced by the following:

‘(c) upon the death of the user.’;

(4) Paragraph 15 is replaced by the following:

’15. The use of European Digital Identity Wallets shall be voluntary. Access to public and private services, access to the labour market and freedom to conduct business shall not in any way be restricted or made disadvantageous to natural persons that do not use European Digital Identity Wallets. It shall remain possible to access public and private services by other existing identification and authentication means.’.

### Article 21: Evaluation and review

**7.** The Commission shall review the application of this Regulation and shall, by [Publications Office, insert the date – 3 years after entry into force], submit a report to the European Parliament and to the Council. The report shall evaluate the effectiveness of the provisions of this Regulation with regard to facilitating the submission of electronic documents and electronic attestations to public sector bodies, by the usage of the European Business Wallets, as well as technological, market, and legal developments. The report shall also assess whether it is necessary to modify the scope of this Regulation or its specific provisions to set out an obligation for the use of the European Business Wallets to address the risks of legal fragmentation.

**8.** The report referred to in paragraph 1 shall include the following aspects:

    - (a) the minimum core functionalities of European Business Wallets;
    - (b) the level of compliance of providers of European Business Wallets and the notification procedure and criteria established in Article 11;
    - (c) the application and functioning of the rules on penalties laid down by the Member States pursuant to Article 13;
    - (d) the detailed requirements and technical specifications for the qualified electronic registered delivery service referred to in Article 5(1) point I;

No later than one year before the report referred to in paragraph 1 is due, Member States shall provide the Commission with the information necessary for the preparation of the reports.

### Article 22: Entry into force and application

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.

It shall apply from [Publications Office, insert the date – 1 year after entry into force].

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels,

For the European Parliament For the Council

The President The President

## Annex: Requirements for minimum functionalities and technical requirements of European Business Wallets

### 1.  European Business Wallets Unit Authentication

Access to the European Business Wallets Unit shall be granted only after the European Business Wallets user has been successfully authenticated by means of either:

- (1) a notified electronic identification (eID) means in accordance with Article 6 of Regulation (EU) No 910/2014, fulfilling at least the requirements for a substantial level of assurance as defined in Article 8 of that Regulation and further specified in Commission Implementing Regulation (EU) 2015/1502; or
- (2) an alternative authentication mechanism recognised as equivalent and fulfilling at least the requirements for a substantial level of assurance as defined in Article 8 of Regulation (EU) No 910/2014 and further specified in Commission Implementing Regulation (EU) 2015/1502.

Until such authentication has been completed, no functionality of the European Business Wallets Unit or of any other functionalities shall be made accessible to the Wallets user.

### 2.  European Business Wallets Unit integrity

Providers of European Business Wallets shall, for each European Business Wallet unit, generate and sign a European Business Wallet unit attestation in accordance with the requirements laid down in point 5. The certificate used to sign or seal the Business Wallet unit attestation shall be issued under a certificate listed in the trusted list referred to in Commission Implementing Regulation (EU) 2024/2980.

### 3.  European Business Wallets secure communication and critical asset management

- (1) European Business Wallet back-end shall use at least one Wallet secure cryptographic application and Wallets secure cryptographic device to manage critical assets.
- (2) Providers of the European Business Wallets shall ensure integrity, authenticity and confidentiality of the communication between the Business Wallet’s back-end, front-end and secure cryptographic applications and device.
- (3) Where critical assets relate to performing electronic identification at assurance level substantial, the European Business Wallets cryptographic operations or other operations processing critical assets shall be performed in accordance with the requirements for the characteristics and design of electronic identification means at assurance level substantial, as set out in Commission Implementing Regulation (EU) 2015/1502.

### 4.  Wallets secure cryptographic applications

- (1) Providers of European Business Wallets shall ensure that European Business Wallets secure cryptographic applications and devices:
  - (a) perform the wallet’s cryptographic operations involving critical assets other than those needed for the Wallets unit to authenticate the Wallets owner only in cases where those applications have successfully authenticated Wallets users;
  - (b) where they authenticate the European Business Wallet owner in the context of performing electronic identification at assurance level substantial as set out in Implementing Regulation (EU) 2015/1502;
  - (c) are able to securely generate new cryptographic keys;
  - (d) are able to perform secure erasure of critical assets;
  - (e) are able to generate a proof of possession of private keys;
  - (f) protect the private keys generated by these Wallets secure cryptographic applications and devices during the existence of the keys;
  - (g) comply with the requirements for the characteristics and design of electronic identification means at assurance level substantial, as set out in Implementing Regulation (EU) 2015/1502.

### 5.  Wallets unit authenticity and validity

- (1) Providers of European Business Wallets shall ensure that the European Business Wallets unit attestations referred to in point 1 contain public keys and that the corresponding private keys are protected by a Wallets secure cryptographic device.
- (2) Providers of European Business Wallets shall provide mechanisms, independent of Wallets units, for the secure identification and authentication of Wallets users.

### 6.  Revocation of Wallets unit attestations

- (1) Providers of European Business Wallets shall establish a publicly available policy specifying the conditions and the timeframe for the revocation of Wallets unit attestations.
- (2) In line with Article 6, where the providers of European Business Wallets revoke European Business Wallets unit attestations, they shall inform the affected European Business Wallets users without undue delay and no later than 24 hours from the revocation of their European Business Wallets units, including the reason for the revocation and the consequences for the European Business Wallets user. This information shall be provided in a manner that is concise, easily accessible and using clear and plain language.
- (3) Where European Business Wallets providers have revoked a European Business Wallet’s unit attestation, they shall make publicly available the validity status of the European Business Wallet unit attestation and describe the location of that information in the Business Wallet’s unit attestation.

### 7.  Transaction logs

- (1) The providers of European Business Wallets shall provide an appropriate logging policy that shall include, at a minimum, electronic signing, electronic sealing, and notifications of all transactions with Business-Wallet-relying parties, other European Business Wallets units, and European Digital Identity Wallets units, irrespective of whether the transaction is successfully completed.
- (2) The logged information shall at least contain:
  - (a) the time and date of the transaction;
  - (b) the name, contact details, and unique identifier of the corresponding Business-Wallet-relying party and the Member State in which that Business-Wallet-relying party is established, or in case of other Wallets units, relevant information from the Wallets unit attestation;
  - (c) the type or types of data requested and presented in the transaction;
  - (d) in the case of non-completed transactions, the reason for such non-completion.
- (3) Providers of European Business Wallets shall ensure integrity, authenticity and confidentiality of the logged information.
- (4) European Business Wallets back-end shall log reports sent by the Wallets user to the competent authorities via the Wallets unit, including interactions related to notifications, regulatory compliance, data sharing, or audit requests.
- (5) The logs referred to in subpoints 1 and 2 shall be accessible to the European Business Wallets provider, where it is necessary for the provision of Wallets services.
- (6) The logs referred to in subpoints 1 and 2 shall remain accessible for as long as required to be accessible by Union law or national law.

### 8.  Qualified electronic signatures and seals

- (1) In line with Article 6, providers of European Business Wallets shall ensure that Wallets users are able to receive qualified certificates for qualified electronic signatures or seals which are linked to qualified signature or seal creation devices that are either local, external, or remote in relation to the Wallet’s unit.
- (2) Providers of European Business Wallets shall ensure that European Business Wallets solutions can securely interface with one of the following types of qualified signature or seal creation devices: local, external, or remotely managed qualified signature or seal creation devices for the purposes of using the qualified certificates referred to in subpoint 1.

### 9.  Signature creation applications

- (1) The signature creation applications used by European Business Wallets units may be provided either by European Business Wallets providers, by providers of trust services or by Business-Wallet-relying parties.
- (2) Signature creation applications shall have the following functions:
  - (a) signing or sealing data provided by European Business Wallets users;
  - (b) signing or sealing data provided by relying parties;
  - (c) creating signatures or seals in accordance with at least the mandatory format;
    - creating signatures or seals in accordance with the optional format;
    - informing Wallets users about the result of the signature or seal creation process.

To ensure uniform conditions for the implementation of this Regulation, the Commission is empowered to adopt implementing acts in accordance with Article 6 that specify the technical standards referred to in subpoint 2, letters (c) and (c)(ii).

- (3) The signature creation applications may either be integrated into or be external to European Business Wallets back-end. Where signature creation applications rely on remote qualified signature creation devices and where they are integrated into European Business Wallets back-end, they shall support the application programming interface set out in the implementing acts, which the Commission is empowered to adopt in accordance with Article 5 in order to ensure uniform conditions for the implementation of this Regulation.

### 10.  Data export and portability

Business Wallets shall support the secure export and portability of an owner’s European Business Wallet data in at least an open format. This shall enable the owner to migrate their data to another Business Wallets solution while ensuring a level of assurance of at least "substantial", as defined in Implementing Regulation (EU) 2015/1502.

### 11.  Secure Legal Communication Channel for the Business Wallet

- (1) In line with Article 5 of this Regulation, Business Wallets shall integrate and support the use of a specific qualified electronic registered delivery service in accordance with Articles 43 and 44 of Regulation (EU) No 910/2014.
- (2) The Commission shall, by means of implementing acts:
  - (a) designate one qualified electronic registered delivery service that shall serve as the mandatory secure legal communication channel for European Business Wallets;
  - (b) define the minimum technical and interoperability requirements that such qualified electronic registered delivery service must fulfil, including alignment with the reference standards, specifications and procedures established under Articles 43 and 44 of Regulation (EU) No 910/2014;
  - (c) ensure that the chosen qualified electronic registered delivery service is based on open, publicly available and royalty-free standards to guarantee interoperability and prevent vendor lock-in;
  - (d) ensure that the chosen qualified electronic registered delivery service provides end-to-end encryption to guarantee confidentiality;
  - (e) establish procedures for ensuring continuous availability, redundancy and fallback mechanisms in case of service failure.
- (3) Interoperability between Business Wallets and the designated qualified electronic registered delivery service shall be mandatory. Providers of Business Wallets shall ensure technical integration in accordance with the implementing acts referred to in subpoint 2.

### 12.  European Business Wallets Access Control Mechanism

- (1) Providers of European Business Wallets shall ensure that authorisation decisions under the access control mechanism are based on one or more of the following criteria, as appropriate to the specific access request:
  - (a) the electronic attestation of attributes of the acting subject;
  - (b) the formal role of the acting subjects within a recognised organisational structure or economic operator;
  - (c) the scope, validity and constraints of any mandate, delegation, or power of attorney;
  - (d) contextual information or policies and rules adopted at Union or national level for sector-specific compliance.
- (2) Providers of European Business Wallets shall ensure the access control mechanism nables fine-grained and auditable authorisation outcomes, ensuring that:
  - (a) visibility of credentials and attestations is selective and conditioned on access rights;
  - (b) access to business processes, digital procedures or submission interfaces is controlled by real-time validation of roles and mandates;
  - (c) all access and execution events are logged, timestamped, and bound to cryptographically verifiable proofs of authorisation, suitable for audit and legal proceedings.
- (3) Providers of the European Business Wallets shall ensure that:
  - (a) mappings between roles and attributes are verifiable, auditable, revocable and traceable to their legitimate issuers;
  - (b) conflicts of roles, over-delegation, or expired authorisations are automatically detected and prevented in real time;
  - (c) all authorisation logic is interoperable across Member States.
- (4) The list of reference standards, technical specifications and procedures to be applied for the implementation of the access control mechanism shall be defined in the implementing acts, which the Commission is empowered to adopt in accordance with Article 5 in order to ensure uniform conditions for the implementation of this Regulation. These shall cover in particular:
  - (a) the formats for the representation of roles and attributes;
  - (b) interoperability mechanisms for mandates and delegations across wallets;
  - (c) protocols, policy language and constraint enforcement;
  - (d) requirements for secure logging, timestamping and auditability of authorisation events.
- (5) Compliance with the requirements laid down in this Article shall be presumed where the standards, specifications and procedures referred to in subpoint 1 are met.

### 13.  General provisions for protocols and interfaces

In line with Article 6 of this Regulation, providers of European Business Wallets shall ensure that European Business Wallets units:

- (1) authorise requests and, where applicable, authenticate those made through relying-party access certificates or Wallet unit attestations. Authentication of the relying party shall be required where attestations are intended for a restricted audience; in all other cases, attestations may be presented by any requesting party;
- (2) display to Wallet users’ information contained in the Business-Wallet-relying party access certificates or in the Wallets unit attestations where applicable;
- (3) display to Wallets users, where applicable, the attributes that Wallets users are requested to present;
- (4) present Wallet unit attestations of the Wallet unit to Business-Wallet-relying parties or Wallets units that request it.

### 14.  Issuance of electronic attestations of attributes to Wallets units

- (1) In line with Article 5 of this Regulation, providers of European Business Wallets shall ensure that Business Wallet units requesting issuance of, electronic attestations of attributes are able to authenticate relying parties.
- (2) In relation to the issuance of electronic attestations of attributes to a Wallet unit, Wallet providers shall ensure that the following requirements are complied with:
  - (a) where European Business Wallets owners, through their Business Wallet unit, request from the provider of the European Business Wallet the issuance of Business Wallets owner identification data or of electronic attestations of attributes from providers of Business Wallets owner identification data or providers of electronic attestations of attributes that enable issuance of Business Wallets owner identification data or electronic attestations in more than one format, the Wallets unit shall request it in all formats referred to in Article 8 to this Regulation laying down rules for the application of the Business Wallets Regulation as regards the integrity and core functionalities of Business Wallets;
  - (b) where Business Wallet owners use their Business Wallets unit to interact with competent national authorities and providers of electronic attestations of attributes, Wallet units shall enable authentication and validation of the Wallet unit components by presenting the Wallet unit attestations to those competent national authorities and providers upon their request;
  - (c) Wallet solutions shall support mechanisms that enable providers of Business Wallets Owner Identification Data to verify issuance, delivery and activation in compliance with assurance level substantial requirements set out in Commission Implementing Regulation (EU) 2015/1502 (11);
  - (d) Wallet units shall verify the authenticity and validity of Business Wallets owner identification data and electronic attestations of attributes.

### 15.  Presentation of attributes to European Business Wallet relying parties

In line with point (d) and (k) of paragraph 1 of Article 5, European Business Wallet providers shall ensure that:

- (1) European Business Wallet solutions support protocols and interfaces for the presentation of attributes to Business-Wallet-relying parties in accordance with the standards defined in the implementing acts;
- (2) At the request of users, European Business Wallet units respond to successfully authenticated and validated requests from Business-Wallet-relying parties in accordance with the standards defined in the implementing acts;
- (3) European Business Wallet units support proving the possession of private keys corresponding to public keys used in cryptographic bindings.

### 16.  Issuance of European Business Wallet Owner Identification Data to Wallets units

- (1) Competent authorities shall ensure that Business Wallets owner identification data issued to Business Wallets units comply with the technical specifications set out in the implementing acts, in line with Article 8 of this Regulation.
- (2) Competent national authorities shall ensure that Business Wallets owner identification data that they issue is cryptographically bound to the Wallets unit to which it is issued.

### 17.  Issuance of electronic attestations of attributes to Wallets units

- (1) Electronic attestations of attributes issued to European Business Wallets units shall comply with at least one of the standards in the list set out in the implementing acts, in line with Article 5 of this Regulation.
- (2) Providers of electronic attestations of attributes shall identify themselves to European Business Wallets units using their wallet-relying party access certificate.
- (3) Providers of electronic attestations of attributes shall ensure that electronic attestations of attributes issued to European Business Wallets units contain the information necessary for authentication and validation of those electronic attestations of attributes.