On Wednesday 28 June, the Council of the EU and the European Parliament will hold a third round of interinstitutional negotiations (‘trilogues’) on the future European Digital Identity Wallet (see EUROPE 13181/10). Negotiations are progressing, but a number of important issues still need to be debated by the co-legislators.
The certification of the wallet will be at the heart of the discussions.
The European Parliament would like to see the certification schemes of the European Cybersecurity Act (CSA) (see EUROPE 12212/13) further integrated and applied, as and when they become available.
The European Parliament would also like the scope of certification pertaining to the General Data Protection Regulation (GDPR) to be mandatory.
For its part, the Swedish Presidency of the Council of the EU has proposed to Member States that ‘CSA’ certification systems for the certification of wallets should be mandatory as soon as they are available and with regard to the scope they are able to cover. “Once these schemes are available, they will be referenced in implementing acts and therefore become mandatory to use for the Wallet certification”, says the document.
Until such systems are available, certification would be carried out by conformity assessment bodies in line with national certification systems based on common reference standards and procedures for the wallet.
Furthermore, noting that ‘GDPR’ certification is normally voluntary, the Council of the EU could ease back on this issue and agree to make it compulsory.
Discussions will also be held to discuss unique identifiers and the business model for the electronic wallet. On this last point, the European Parliament would like its use to be entirely free of charge. The Council of the EU, for its part, would like signatures to be free of charge for natural persons, but would like Member States to be able to introduce paid-for signature services once a minimum number of free transactions has been made.
The issue of penalties will also be discussed. The European Parliament would like to see maximum fines of at least €7 million – or 1.4% of annual worldwide turnover – imposed on non-qualified trust service providers. Qualified trust service providers could face maximum fines of at least €10 million, or 2% of annual worldwide turnover.
The Council of the EU, for its part, is mooting the idea of maximum fines of at least €500,000 or 1% of turnover, without distinction. “Such a regime would still offer Member States a wide flexibility as they would be able to set at national level the level of the minimum fines and also maximum fines which could go beyond the harmonized minimum of maximum thresholds in the Regulation”, says the Swedish Presidency of the Council of the EU.
The European Parliament and the Council of the EU will also have to agree on the timetable for issuing the wallets. The European Commission proposed a period of 12 months from entry into force. The European Parliament would like an 18-month deadline, while the Council of the EU would like 24 months. On this point, the EU Council does not seem inclined to be flexible.
See the document: https://aeur.eu/f/7rx (Original version in French by Thomas Mangin)