Digital Identity
Digital identity is a verified representation of a real person’s identity that exists in electronic form and can be presented to prove who they are, distinct from a username and password, which prove access to an account, not identity itself. The concept has moved from theory to binding law in the past two years: the EU’s eIDAS 2.0 regulation requires every member state to offer a digital identity wallet to citizens by the end of 2026.
Key takeaways
- Digital identity is a verified, reusable identity credential, not a login, which only proves account access.
- The EU’s eIDAS 2.0 regulation (Regulation (EU) 2024/1183, in force since 20 May 2024) requires every member state to offer a digital identity wallet by the end of 2026.
- Private-sector acceptance of the EUDI Wallet in regulated sectors follows roughly a year later, expected late 2027.
- The UK’s DIATF framework became statutory on 1 December 2025, certifying private providers against GPG45 confidence levels rather than issuing one government wallet.
- US mobile driver’s licenses (mDLs) are rolling out state by state, built to the ISO/IEC 18013-5 standard.
- Verifiable credentials, a W3C standard, are the technical backbone behind most modern digital identity systems.
- Regulated firms generally still need to run their own CDD process today; genuine reliance on third-party digital identity is still the exception, not the default.
On this page
What digital identity actually meansDigital identity vs a login: a distinction worth being precise aboutThe EU Digital Identity Wallet: what’s actually mandated, and whenWhat the EUDI Wallet will actually let people doThe UK’s parallel but separate approachMobile driver’s licenses: the quieter US rolloutThe technical backbone: verifiable credentialsReusable identity and what it means for KYC specificallyWhy digital identity adoption has been slower than the hype suggestedPrivacy design: selective disclosureWhat this means for a compliance programme todayFAQsRead more
20 May 2024
Date eIDAS 2.0 (Regulation (EU) 2024/1183) entered into force
End of 2026
Deadline for every EU member state to offer at least one certified EUDI Wallet
Source: eIDAS 2.0
1 Dec 2025
Date the UK’s DIATF became statutory under the Data (Use and Access) Act 2025
What digital identity actually means
Digital identity is a verified representation of a real person’s identity that exists in electronic form, issued by a trusted source, and capable of being presented to prove who someone is without relying on a physical document. It’s not the same as an online account or a password; it’s meant to function as the electronic equivalent of a passport or driving licence, something that carries genuine, verified proof of identity rather than just access to a specific service.
Digital identity vs a login: a distinction worth being precise about
A login proves you have access to an account; it doesn’t prove who you are. Usernames and passwords, and even most two-factor authentication, verify that whoever is signing in knows a secret or controls a device, not that they’re a specific, real, verified person.
A genuine digital identity is built on identity proofing that happened at some point, a document check, a biometric match, verification against a government record, and then represents the result of that proofing in a form that can be reused and presented elsewhere, ideally without repeating the entire proofing process from scratch every time.
The EU Digital Identity Wallet: what’s actually mandated, and when
The clearest binding example of digital identity moving from concept to law is the European Union’s eIDAS 2.0 regulation, formally Regulation (EU) 2024/1183, which entered into force on 20 May 2024. It requires every EU member state to make at least one certified European Digital Identity Wallet, the EUDI Wallet, available to citizens and businesses by the end of 2026.
That deadline applies to member states providing the wallet, not to businesses accepting it. Large private-sector organisations in regulated sectors, banking, healthcare, telecoms, and large online platforms, have a separate deadline roughly a year later, late 2027, by which they’re required to accept the EUDI Wallet as an authentication method where relevant.
What the EUDI Wallet will actually let people do
The EUDI Wallet is designed to hold verified credentials, not just a single identity document: proof of age, a driving licence, educational qualifications, and financial account access, all in one wallet a person controls on their own device, rather than in each individual service’s own database. A person could, in principle, prove they’re over 18 to a retailer, prove their professional qualification to an employer, or complete identity verification for a new bank account, all using the same underlying verified credential.
The stated policy goal is interoperability: a credential verified once, to a defined standard, that’s genuinely reusable across borders and sectors, rather than every organisation running its own separate identity proofing process from scratch.
The UK’s parallel but separate approach
The UK, no longer bound by EU regulation, has built a parallel but structurally separate framework. The Digital Identity and Attributes Trust Framework, DIATF, moved from voluntary guidance to statutory footing under the Data (Use and Access) Act 2025, in force since 1 December 2025, with a formal certification mark, version 1.0, published 6 March 2026.
Rather than a single government-issued wallet like the EU model, the UK’s approach certifies private-sector Digital Verification Service providers against defined confidence levels, GPG45’s Low, Medium, High, and Very High tiers, creating a market of certified providers rather than one centralised wallet.
Mobile driver’s licenses: the quieter US rollout
In the US, the most concrete near-term digital identity development isn’t a comprehensive wallet but the mobile driver’s license, mDL, an electronic version of a state-issued driving licence stored on a phone, built to the ISO/IEC 18013-5 international standard specifically so it can be read consistently by verifiers across different states and industries. Adoption has been gradual and state-by-state rather than federally mandated, which is a meaningfully different rollout model from the EU’s binding, deadline-driven approach.
The technical backbone: verifiable credentials
Most modern digital identity systems, including the EUDI Wallet, are built on verifiable credentials, a W3C technical standard for issuing, holding, and presenting cryptographically signed digital claims. A verifiable credential lets a holder present proof of an attribute, such as being over a certain age or holding a valid licence, in a way a relying party can cryptographically confirm was genuinely issued by the claimed authority and hasn’t been tampered with, without necessarily contacting the issuer directly at the moment of presentation.
Reusable identity and what it means for KYC specifically
For KYC and AML compliance specifically, reusable digital identity offers a genuine efficiency case: a customer who has already been verified to a defined assurance level by one institution, or by a government-issued wallet, shouldn’t necessarily need to repeat the entire identity proofing process from scratch at every new provider they deal with.
That promise remains mostly theoretical for regulated financial services today. Firms still generally need to run their own CDD process and satisfy their own regulator that verification meets the applicable standard, even where a customer arrives holding a credential verified elsewhere. Genuine reliance on third-party digital identity for full regulatory purposes is still the exception, not the default, in most jurisdictions as of this writing.
Why digital identity adoption has been slower than the hype suggested
Digital identity has been discussed as an imminent transformation for over a decade, and the gap between that discussion and binding deployment has been wide until quite recently. Technical complexity, cross-border interoperability requirements, and genuine, well-founded privacy concerns about centralising identity data have all slowed rollout considerably.
The EU’s binding, dated legal deadline is different in kind from earlier voluntary pilots and discussion papers precisely because it removes the option to keep treating digital identity as a future consideration. A hard, dated legal deadline changes planning timelines in a way that years of conceptual discussion didn’t.
Privacy design: selective disclosure
Privacy protection is built into the newer generation of digital identity frameworks through selective disclosure: the ability to prove a specific fact, that you’re over 18, that you hold a valid professional licence, without revealing the underlying data that fact is based on, such as an exact date of birth or full document details.
This is presented as a genuine improvement over physical documents, which typically reveal everything on the document, full date of birth, address, document number, even when only one specific fact actually needed confirming.
What this means for a compliance programme today
For a compliance programme today, the practical position is preparation rather than dependency. The EU deadline for member states, the UK’s now-statutory DIATF framework, and the gradual US mDL rollout are all real, dated developments worth tracking directly rather than assuming stay theoretical, but none of them yet let a regulated firm skip its own identity verification obligations. Firms operating in or with the EU specifically should treat the 2026 wallet deadline, and the follow-on 2027 private-sector acceptance deadline, as concrete integration planning milestones, not distant possibilities.
Frequently asked questions
What is digital identity?
Digital identity is a verified representation of a real person’s identity that exists in electronic form, issued by a trusted source, and capable of proving who someone is, distinct from a login, which only proves access to an account.
What is the EU Digital Identity Wallet?
The EUDI Wallet is a digital identity credential every EU member state must make available to citizens and businesses under the eIDAS 2.0 regulation, with a binding deadline of the end of 2026.
When do businesses have to accept the EUDI Wallet?
Large private-sector organisations in regulated sectors have a separate deadline roughly a year after the member-state rollout, expected around late 2027.
What is the UK’s equivalent of the EUDI Wallet?
The UK uses the Digital Identity and Attributes Trust Framework, DIATF, which certifies private-sector providers against GPG45 confidence levels rather than issuing a single government wallet. It became statutory on 1 December 2025.
What is a mobile driver’s license (mDL)?
An mDL is an electronic version of a state-issued driving licence stored on a phone, built to the ISO/IEC 18013-5 standard, rolled out state by state in the US rather than under a single federal mandate.
What are verifiable credentials?
Verifiable credentials are a W3C technical standard for issuing and presenting cryptographically signed digital claims, letting a relying party confirm a credential’s authenticity without necessarily contacting the original issuer directly.
Can a business currently rely entirely on someone else’s digital identity verification for KYC?
Generally not yet. Most regulated firms still need to run their own customer due diligence process, even when a customer presents a credential verified elsewhere, though reusable identity is expected to reduce this over time.
What is selective disclosure?
Selective disclosure lets someone prove a specific fact, such as being over 18, without revealing the underlying data behind it, such as their exact date of birth, a privacy feature built into newer digital identity frameworks.
Why has digital identity taken so long to become real?
Technical complexity, cross-border interoperability requirements, and genuine privacy concerns about centralising identity data slowed rollout for years, until the EU’s binding, dated legal deadline changed planning timelines industry-wide.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 11 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Digital identity is a verified representation of a real person’s identity that exists in electronic form and can be presented to prove who they are, distinct from a username and password, which prove access to an account, not identity itself. The concept has moved from theory to binding law in the past two years: the EU’s eIDAS 2.0 regulation requires every member state to offer a digital identity wallet to citizens by the end of 2026.