Soda Labs

eIDAS 2 and the EU Digital Identity Wallet

Digital identity · Regulation (EU) 2024/1183

Regulator or standard-setterEuropeBuilds with privacy tech

The regime itself mandates, pilots or funds privacy-preserving technology.

What eIDAS 2 and the EU Digital Identity Wallet actually says

The clearest counterexample to the idea that regulators are uniformly against cryptographic privacy: here EU law names the technology and requires it. Recital 14 says member states should integrate privacy-preserving technologies such as zero knowledge proof, so a relying party can validate that a statement is true without seeing the data behind it. Recital 32 requires providers to be unable to see the details of users' transactions. Recital 59 requires selective disclosure of individual attributes. Member states are to make wallets available to all citizens and residents by the end of 2026. The same legal order that will bar anonymous exchange accounts in July 2027 is putting zero-knowledge credential technology into roughly 450 million hands.

The instruments that matter

Recital 14
member states should integrate privacy-preserving technologies such as zero knowledge proof into the wallet
Recital 32
wallet providers must be unable to see the details of users' transactions, a property known as unobservability
Recital 59
technical support for selective disclosure of attributes, including across attestations from several sources

What this means for confidential transactions

Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.

Compliant by default.

See how selective disclosure satisfies a supervisor without publishing your book to the world.