Plenary report, 23 September 2026
On the proposal for a regulation of the European Parliament and of the Council on the establishment of European Business Wallets
Report A-10-2026-0240 · (COM(2025)0838 – C100305/2025 – 2025/0358(COD))
Committee on Industry, Research and Energy · Rapporteur: Eero Heinäluoma
AI:In short
Parliament's amended version of the Commission proposal for a regulation establishing European Business Wallets. It sets up a voluntary digital tool for economic operators and public sector bodies to identify, authenticate, sign, seal, submit documents and exchange attestations. It gives actions carried out through the wallets the same legal effect as actions done in person or on paper, and requires public sector bodies to accept them within 24 months of the implementing acts. It requires providers to be established in the Union, to offer core functionalities including a qualified electronic registered delivery service, and to store and process wallet data on Union infrastructure. It creates European Business Wallet owner identification data, unique identifiers, a European Digital Directory, a notification and supervision system, and rules for third-country operators and equivalent third-country systems. It amends Regulation (EU) No 910/2014 so that mandatory issuance of European Digital Identity Wallets relates only to natural persons.
Position. The Committee on Industry, Research and Energy adopts Parliament's position at first reading, amending the Commission proposal to establish European Business Wallets with rules on equivalence, core functionalities, Union-based providers, identification data, unique identifiers, a Digital Directory, supervision and third-country recognition.
Key points
- The regulation enables secure digital identification, authentication, data sharing and legally valid notifications, and supports cross-border business and competitiveness.
- Actions carried out through the core functionalities of a European Business Wallet have the same legal effect as actions lawfully carried out in person, on paper or by other compliant means.
- Providers must offer core functionalities including issuing and sharing attestations, qualified electronic signatures and seals, time stamps, a qualified electronic registered delivery service, mandate management, data export and transaction logs.
- Providers may offer additional functionalities, such as automatic translation and payment transactions, if they do not compromise security or interoperability.
- Providers must be established in the Union, not be controlled by a third country, use Union-based QERDS and cloud providers, and store and process wallet data exclusively in the Union.
- European Business Wallet owner identification data is issued by qualified trust service providers, public sector bodies or the Commission, and contains at least the official name, contact details and unique identifier.
- The European Unique Identifier is used as the unique identifier where available; otherwise a free unique identifier is created on request without undue delay.
- The Commission establishes and maintains a European Digital Directory as the trusted source of information on wallet owners, accessible to owners, providers and relevant authorities.
- Entities intending to provide wallets must notify their supervisory body, which has 30 calendar days to review; the Commission maintains a public list of notified providers.
- Member States designate supervisory bodies with powers to monitor compliance, handle complaints, impose penalties of up to 2% of total worldwide annual turnover, and cooperate with other authorities.
- Public sector bodies must enable economic operators to identify, authenticate, sign, seal, submit documents and send or receive notifications through wallets within 24 months of the implementing acts, with a transition period of up to 36 months for the secure communication channel.
- The Commission may recognise equivalent third-country business wallets and frameworks for B2B cooperation, and may allow wallets to be issued to third-country economic operators subject to identity verification and due diligence.
Who is affected
- Economic operators, including companies, self-employed persons and sole traders, who may voluntarily use European Business Wallets.
- Public sector bodies, which must accept wallets for identification, authentication, signing, sealing, submissions and notifications.
- Providers of European Business Wallets, subject to establishment, security, notification and supervision requirements.
- Small and medium-sized enterprises and smaller public sector bodies, for which support, funding and attention to limited capacity are required.
- Third-country economic operators, who may obtain wallets if their identity is verified and they hold only one set of identification data.
Figures and deadlines
- 30 calendar days for the supervisory body to review a notification.
- 15 calendar days maximum for a notifying entity to respond to a request for additional information.
- 24 months after entry into force of the implementing acts for public sector bodies to enable wallet use.
- 36 months after entry into force of the implementing acts for the transition period on the secure communication channel.
- Maximum administrative fines of 2% of total worldwide annual turnover in the preceding financial year.
- 12 months from entry into force of the Regulation for the Commission to adopt implementing acts on core functionalities, technical requirements, identification data, unique identifiers and the Digital Directory.
- Three years after entry into force for the Commission's review report, and every four years thereafter.
- One working day for providers to communicate modifications or revocations of Digital Directory information to the Commission.
Legal basis. Article 114 of the Treaty on the Functioning of the European Union.
Written by AI from the full text · every figure comes from the text · ¶ opens the paragraph · 25 Sept 2026 · Report a problem
Full text
Jump to an amendment (171)
- Amendment 1
- Amendment 1
- Amendment 2
- Amendment 3
- Amendment 4
- Amendment 5
- Amendment 6
- Amendment 7
- Amendment 8
- Amendment 9
- Amendment 10
- Amendment 11
- Amendment 12
- Amendment 13
- Amendment 14
- Amendment 15
- Amendment 16
- Amendment 17
- Amendment 18
- Amendment 19
- Amendment 20
- Amendment 21
- Amendment 22
- Amendment 23
- Amendment 24
- Amendment 25
- Amendment 26
- Amendment 27
- Amendment 28
- Amendment 29
- Amendment 30
- Amendment 31
- Amendment 32
- Amendment 33
- Amendment 34
- Amendment 35
- Amendment 36
- Amendment 37
- Amendment 38
- Amendment 39
- Amendment 40
- Amendment 41
- Amendment 42
- Amendment 43
- Amendment 44
- Amendment 45
- Amendment 46
- Amendment 47
- Amendment 48
- Amendment 49
- Amendment 50
- Amendment 51
- Amendment 52
- Amendment 53
- Amendment 54
- Amendment 55
- Amendment 56
- Amendment 57
- Amendment 58
- Amendment 59
- Amendment 60
- Amendment 61
- Amendment 62
- Amendment 63
- Amendment 64
- Amendment 65
- Amendment 66
- Amendment 67
- Amendment 68
- Amendment 69
- Amendment 70
- Amendment 71
- Amendment 72
- Amendment 73
- Amendment 74
- Amendment 75
- Amendment 76
- Amendment 77
- Amendment 78
- Amendment 79
- Amendment 80
- Amendment 81
- Amendment 82
- Amendment 83
- Amendment 84
- Amendment 85
- Amendment 1
- Amendment 2
- Amendment 3
- Amendment 4
- Amendment 5
- Amendment 6
- Amendment 7
- Amendment 8
- Amendment 9
- Amendment 10
- Amendment 11
- Amendment 12
- Amendment 13
- Amendment 14
- Amendment 15
- Amendment 16
- Amendment 17
- Amendment 18
- Amendment 19
- Amendment 20
- Amendment 21
- Amendment 22
- Amendment 23
- Amendment 24
- Amendment 25
- Amendment 26
- Amendment 27
- Amendment 28
- Amendment 29
- Amendment 30
- Amendment 31
- Amendment 32
- Amendment 33
- Amendment 34
- Amendment 35
- Amendment 36
- Amendment 37
- Amendment 38
- Amendment 39
- Amendment 40
- Amendment 41
- Amendment 42
- Amendment 43
- Amendment 44
- Amendment 45
- Amendment 46
- Amendment 47
- Amendment 48
- Amendment 49
- Amendment 50
- Amendment 51
- Amendment 52
- Amendment 53
- Amendment 54
- Amendment 55
- Amendment 56
- Amendment 57
- Amendment 58
- Amendment 59
- Amendment 60
- Amendment 61
- Amendment 62
- Amendment 63
- Amendment 64
- Amendment 65
- Amendment 66
- Amendment 67
- Amendment 68
- Amendment 69
- Amendment 70
- Amendment 71
- Amendment 72
- Amendment 73
- Amendment 74
- Amendment 75
- Amendment 76
- Amendment 77
- Amendment 78
- Amendment 79
- Amendment 80
- Amendment 81
- Amendment 82
- Amendment 83
- Amendment 84
- Amendment 85
Draft european parliament legislative resolution 568 paragraphs
on the proposal for a regulation of the European Parliament and of the Council on the establishment of European Business Wallets
(COM(2025)0838 – C100305/2025 – 2025/0358(COD))
(Ordinary legislative procedure: first reading)
The European Parliament,
–having regard to the Commission proposal to Parliament and the Council (COM(2025)0838),
–having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C100305/2025),
–having regard to Article 294(3) of the Treaty on the Functioning of the European Union,
–having regard to the opinion of the European Economic and Social Committee of 18 March 2026,
–having regard to the opinion of the Committee of the Regions of 18 July 2026,
–having regard to Rule 60 of its Rules of Procedure,
–having regard to the opinions of the Committee on the Internal Market and Consumer Protection and the Committee on Legal Affairs,
–having regard to the report of the Committee on Industry, Research and Energy (A10-0240/2026),
Read the rest (556 paragraphs)
1.Adopts its position at first reading hereinafter set out;
2.Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
3.Instructs its President to forward its position to the Council, the Commission and the national parliaments.
Amendment 1
2025/0358 (COD)
Proposal for a
REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL
on the establishment of European Business Wallets
THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,
Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,
Having regard to the proposal from the European Commission,
After transmission of the draft legislative act to the national parliaments,
Having regard to the opinion of the European Economic and Social Committee() ,
Acting in accordance with the ordinary legislative procedure,
Whereas:
(1) In its Communication of 29 January 2025 ‘A Competitiveness Compass for the EU’() the Commission announced that European Business Wallets, building on the European Digital Identity Framework, will constitute the cornerstone for conducting business in a simple, secure and digital manner within the Union, providing companies with a seamless environment in which to interact with public administrations and carry out business transactions with other economic operators.
(2) Regulation (EU) No 910/2014 of the European Parliament and of the Council() establishes the European Digital Identity Framework and introduces the European Digital Identity Wallets, intended for voluntary use by individuals, enabling users to securely store and manage their digital identity and electronic attestations of attributes, and to access a wide range of online services. The European Digital Identity Framework features new trust services, including the issuance of electronic attestations of attributes, thereby enhancing the security and reliability of online transactions and interactions.
(3) In order to foster a competitive, resilient and digital European economy, to reduce administrative burden and economic disparities within the Union, and to facilitate cross-border business, it is necessary to establish a seamless and secure environment for digital interactions among economic operators andbetween economic operators and public sector bodies in different configurations.
(4) In order to ensure trust in and a high degree of interoperability and security, as well as the technological neutrality of, European Business Wallets, the technical specifications established in Regulation (EU) No 910/2014 and subsequent implementing regulations established pursuant to that Regulation as well as the technology and standards developments and the work carried out on the basis of Recommendation (EU) 2021/946, and in particular the Architecture and Reference Framework, should apply, with the specifications laid down in this Regulation taking precedence in the event of any inconsistency. The technical trust architecture underpinning European Business Wallets should support innovative market-driven solutions and allow economic operators to easily switch between different providers, without compromising on security. It should also rely on open standards, thereby ensuring interoperability between systems and fostering innovation and market-driven solutions.
(5) In order to enhance the functioning of the digital single market, ensure interoperability and avoid duplication, reduce unnecessary administrative burdens and costs for businesses and public sector bodies, it is essential to ensure compatibility between and European Business Wallets and existing systems and solutions at both Union and national level. That endeavour should be supported by the European Digital Identity Cooperation Group. As prescribed by the Interoperable Europe Act and to enhance secure and efficient data exchanges across the Union, the implementation of the European Business Wallets should, to the extent possible, where appropriate and following technical analysis, make use of existing EU digital infrastructures and building blocks, including those developed under the Once Only Technical System, the Business Registers Interconnection System and the European Digital Identity Wallet, thereby ensuring complementarity, interoperability, and efficient use of public resources.
(6) The European Business Wallets are a digital tool for economic operators to interact securely with public sector bodies in the context of meeting reporting obligations and fulfilling administrative procedures and which enable secure interaction with other economic operators. The use of the core functionalities of the European Business Wallets to identify and authenticate, sign or seal, submit documents and send or receive notifications and request or share electronic attestations of attributes, communication logs and interaction records in a structured, commonly used and machine-readable format which will facilitate machine translation of such data, should be without prejudice to procedural requirements that might be part of an administrative procedure and that cannot be fulfilled by the core functionalities of the European Business Wallets. The core functionalities of European Business Wallets should not be used to circumvent Union or Member State laws that aim to protect the public interest by fighting against money laundering and the financing of terrorism. These procedural requirements may include any additional safeguards or verifications, such as checks to ensure the awareness or understanding of the contents of a document or the implications of the signature of a contract, or specific actions that are required as part of an administrative procedure and are not supported by the core functionalities of the European Business Wallets. Public sector bodies should therefore ensure that all relevant procedural requirements are met, including any specific actions or processes which need to be fulfilled as part of an administrative procedure and which cannot be performed through the European Business Wallets.
(7) Public sector bodies have the flexibility to decide how to ensure that they can accept European Business Wallets considering the diversity of their IT infrastructure and their needs for interoperability. This approach allows public sector bodies to maintain their existing operational frameworks, while benefiting from the advantages of the European Business Wallets. However, that flexibility should be exercised with due regard to the principle of proportionality and the need to avoid imposing disproportionate technical or administrative burden, especially on micro-enterprises and small and medium-sized enterprises (SMEs). To the extent that public sector bodies have already developed effective and secure solutions for core functionalities, those solutions should be duly taken into account.
(7a) In order to ensure the effective deployment of European Business Wallets across the Union, public authorities at the national, regional and local level should be able to receive, process and make use of data and documents provided through European Business Wallets where relevant for the exercise of their public tasks.
(7b) In order to promote the effective implementation and widespread uptake of European Business Wallets across the Union, their deployment and use should take into account differences in digital infrastructure, administrative capacity and levels of digitalisation across Member States and regions, including rural, remote and less developed areas. Particular attention should be paid to the challenges faced by smaller municipalities and local authorities. Those challenges could be addressed, for instance, through adequate financial support, shared IT infrastructure and targeted technical assistance. Union funding instruments should facilitate the deployment and uptake of European Business Wallets, especially in less developed regions.
(7c) In order to support the consistent implementation of European Business Wallets, the Commission should provide technical guidance to Member States on how to support public sector bodies in complying with this Regulation, thereby facilitating the proper functioning of the internal market.
(7d) The early and effective use of European Business Wallets by public authorities could encourage economic operators, including SMEs, sole traders and self-employed persons, to adopt and use those wallets in their interactions with public authorities and with other economic operators, thereby contributing to the effective functioning of the internal market and reducing administrative burden.
(8) This Regulation is without prejudice to the procedural autonomy, the constitutional requirements and the judicial independence that govern the organisation and functioning of national justice systems of the Member States, as well as to the framework, integrity and procedural safeguards of judicial proceedings.
(9) This Regulation is without prejudice to the Member States’ responsibility for safeguarding national security and their power to safeguard other essential State functions, including ensuring the territorial integrity of the State and maintaining law and order.
(10) This Regulation should be without prejudice to the right of legal persons to submit ▌information only once to public sector bodies as well as to the right of Member States to continue using other systems for the submission of documents and data between competent authorities as established under Union law, such as in Regulation 2018/1724() establishing the Single Digital Gateway and Once-Only Technical System and Directive (EU) 2017/1132 establishing the Business Registers Interconnection System.
(10a) In order to encourage a broad uptake of European Business Wallets, especially by micro-enterprises and SMEs, the design and deployment of European Business Wallets should take into account the needs, as well as the limited administrative capacities and resources of smaller businesses, to deliver affordable and user-friendly solutions, offered under transparent, fair, reasonable and non-discriminatory conditions. Member States and the Commission should explore appropriate incentive mechanisms to encourage the uptake of European Business Wallets by economic operators. The mobilisation of relevant Union funding instruments could help contribute to covering the costs of initial onboarding, training or integration for SMEs.
(10b) Whilst transitioning towards a fully digital ecosystem, Member States should take the necessary measures to ensure that no barriers arise to participation in the internal market, in particular for SMEs, start-ups, self-employed persons and other actors with limited resources or digital skills, or having particular accessibility requirements.
(11) In order to reduce unnecessary administrative burden and improve competitiveness, all entities conducting economic activities, including companies, organisations, self-employed persons and sole traders acting in a business capacity and any other type of business, regardless of size, sector or legal form, should be able to use European Business Wallets on a voluntary basis. Those entities should be able to become European Business Wallet owners in a variety of ways, including through ownership, licence, subscription or any other agreement granting a right of use of a European Business Wallet, without restrictions to transparent, fair, reasonable, non-discriminatory and interoperable access to European Business Wallets, including across borders. To ensure that legally valid notifications, and documents can be exchanged, and reporting obligations fulfilled by means of European Business Wallets, it is necessary to establish a reliable and secure communication channel that can be used by European Business Wallet owners across the Union. A qualified electronic registered delivery service (‘QERDS’) should therefore be integrated as a secure communication channel in the European Business Wallets, and should enable the secure and legally valid exchange of information between parties, as provided for in Article 43 of Regulation (EU) No 910/2014.
(11a) In order to ensure interoperability and competition among solution providers, the Commission should establish a common set of technical and operational requirements, including a standardised interface, for QERDS.
(12) In order to provide a tailored solution for self-employed persons and sole traders, it is essential to ensure the seamless integration of European Digital Identity Wallets with European Business Wallets, while also preserving privacy. That integration should enable the authentication of those persons using their European Digital Identity Wallet and access trust services offered for the European Business Wallets, including the QERDS established as a secure communication channel in this Regulation, using those Wallets▌. Access to European Business Wallet services should take place in a way that clearly distinguishes whether an individual is using their European Digital Identity Wallets for business purposes or as an individual. Providers of European Business Wallets should ▌be allowed to offer the secure communication channel as a standalone service to self-employed persons and sole traders that use European Digital Identity Wallets in a business capacity, with ensured interoperability to facilitate app switching, as well as trust services such as electronic signatures and qualified and non-qualified time stamping services. Such access to the secure communication channel for self-employed persons and sole traders, should be promoted by ensuring an offer, at reasonable and affordable prices, that reflects the usage needs and is accompanied by terms of use that do not impose an undue burden on those persons. Self-employed persons and sole traders that would use the European Business Wallet should be considered data subjects under Regulation (EU) 2016/679.
(13) The European Business Wallets, in combination with Regulation (EU) 2018/1724, should support the newly proposed EU Inc., a new harmonised corporate legal regime and a starting point for the Union's 28th Regime() by providing the digital infrastructure for fully digital procedures, enabling innovative SMEs, start-ups and scale-ups to conduct EU-wide operations in a rapid and efficient manner. The Business Wallets should provide the digital infrastructure for the EU Inc.’s digital-only strategy, streamlining cross-border interactions and reducing unnecessary administrative burden, such as facilitating the secure storing and signature of contracts and certificates or submitting, receiving and sharing electronic applications and documents, including structured, machine-readable data as electronic attestations of attributes. By providing this infrastructure, the Business Wallets should help make the "digital by default" and the once-only principle a reality, facilitating the growth and development of EU companies and enhancing their competitiveness.
(14) Given the objective of creating a unified and secure digital ecosystem for electronic identification, authentication, and the exchange of electronic documents, notifications, and attestations of attributes, the inclusion of Union entities among public sector bodies covered by this Regulation, is necessary. Such an inclusion should create a coherent framework for owners of European Business Wallets to engage with all levels of public administration thereby reducing administrative complexities and driving uptake of the European Business Wallets.
(15) In order to ensure the proper issuance and integration of European Business Wallets throughout the operations and systems of Union entities, this Regulation should have due regard to the specific nature and structure of such institutions, bodies, offices and agencies. To ensure the respect of administrative autonomy and security of Union entities. They should be allowed to acquire European Business Wallets from ▌established providers of European Business Wallets, or develop their own European Business Wallets or act themselves as provider for Union entities provided that they comply with the technical requirements laid down in this Regulation. Where Union entities act as providers of European Business Wallets to other Union entities, they should also be subject to a supervisory framework. In such cases, the Commission should be tasked to ▌supervise the provision of European Business Wallets by Union entities.
(16) Regulation (EU) No 910/2014 established a framework for electronic identification and trust services in the internal market. Building on the ecosystem established by Regulation (EU) No 910/2014, the European Business Wallets should offer economic operators and public sector bodies a secure and reliable solution for digital identification and authentication, data sharing, and the delivery of legally valid notifications. The trust framework for European Business Wallets, including the use of trusted lists, should build upon the structures established under Regulation (EU) No 910/2014. The identification and authentication within the European Business Wallets framework should rely on electronic attestations of attributes, issued by trusted entities, which attest to the identity, attributes or specific roles of a natural or legal person using those solutions and enable their verification in accordance with the requirements of this Regulation.
(17) The European Business Wallets should allow individuals granted the power to act on behalf of an entity in legal, financial, and administrative matters to exercise their functions by signing any attestations, declarations, or documents executed through a legally valid electronic signature within the meaning of Regulation (EU) 910/2014, which establishes that qualified electronic signatures shall have the equivalent legal effect of a handwritten signature.
(18) To support the delegation of powers and mandates within a professional context, the European Business Wallets should incorporate a mandate and role-based secure authorisation system that governs access to services and transactions within the European Business Wallet in such a way as to support the various business needs and to preserve the integrity of the identity of the owner of that Wallet. That system should enable economic operators and public sector bodies to assign rights to authorised representatives through clearly defined technical mandates allowing the owner of a specific European Business Wallet to grant full rights to generally use the solution and act on its behalf. The authorisation system should also allow the creation of administrative mandates, within a comprehensive framework, allowing the owner of a Business Wallet to assign and manage clearly defined and restricted roles and responsibilities to various users of the solution within their organisation. The authorisation system could also enable the delegation of powers of representation by European Business Wallets owner to authorised representatives, which should be carried out under the applicable Union and national law, where that is relevant and necessary. The authorisation system should allow the use of European Digital Identity Wallets without imposing any obligation to obtain them, in accordance with the voluntary nature of such wallets. The authorisation system should ensure compatibility with the EU digital power of attorney, as established by Directive (EU) 2025/25 of the European Parliament and of the Council. This authorisation system should be robust and scalable, to ensure that economic operators and public sector bodies, as the owners of European Business Wallets, can delegate authority to multiple users, including employees or other authorised natural or legal persons, thereby facilitating the efficient and secure management of internal activities and ensuring that access to European Business Wallets and their functions is controlled, revokable, traceable and auditable. This system should govern access to services and transactions within the European Business Wallet, preserving the integrity of the owners' identities.
(18a) This Regulation should not prevent a natural or legal person from managing or operating multiple European Business Wallets on behalf of economic operators, public sector bodies, subsidiaries, affiliates, or other entities, where duly authorised to do so under applicable mandates or arrangements. That could include, for example, a business group structure in which a parent undertaking centrally manages or operates European Business Wallets on behalf of several subsidiary companies within the same corporate group.
(18b) Given the highly sensitive nature of the data exchanged via the European Business Wallet, including trade secrets and sensitive corporate attributes, it is essential that Business Wallet-relying parties adhere to strict security and transparency standards. To prevent unauthorised access to business data or the misuse of such data, Business Wallet-relying parties should be technically and legally restricted to requesting only those attributes which are strictly necessary for the administrative or commercial procedure concerned. Furthermore, where a Business Wallet-relying party processes credentials provided by a European Business Wallet, they should implement state-of-the-art security measures to ensure the confidentiality and non-repudiation of the exchange, ensuring that the European Business Wallet owner`s data is protected against unauthorised access or exfiltration.
(19) In order to facilitate the conduct of cross-border business transactions, reduce administrative burdens, and promote economic growth, it is necessary to establish a clear and predictable legal framework that recognises the legal equivalence between the use of the European Business Wallets, or their core functionalities and the secure communication channel where the latter is used by self-employed persons and sole traders, and other accepted methods for economic operators to identify, authenticate, submit documents and receive notifications when interacting with public sector bodies in the Union. To that end, the use of the core functionalities of a European Business Wallet, or the secure communication channel where the latter is offered as a standalone service to self-employed persons and sole traders, should have the same legal effect as if lawfully carried out in person, in paper form, or via any other means or process that would otherwise be deemed compliant with applicable legal, administrative, or procedural requirements. That should not prevent economic operators from continuing to use other legally valid means of carrying out such actions, where permitted under applicable law.
(20) To ensure a consistent user experience and to guarantee the utility, reliability, and interoperability of European Business Wallets across the Union, providers of European Business Wallets should implement a core set of functionalities. They should, as part of their commercial offering, while fostering innovation and responding to market needs, retain the freedom to offer additional features which comply with the security requirements laid down in this Regulation. In order to ensure uniform conditions for the development and use of the core functionalities, implementing powers should be conferred on the Commission to set out requirements and technical specifications necessary to ensure security, interoperability and seamless functioning across the Union. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council() and should include the powers to define the necessary standards and protocols for the secure communication channel. When defining those requirements and technical specifications, the Commission should ensure that they remain technologically neutral, proportionate and adaptable, taking into account the latest technological developments. The technical specifications should enable the incorporation of new models for authorisation, automation and data exchange, as they become available, while preserving interoperability and a consistent level of security and assurance.
(20a) When adopting implementing acts in a timely manner pursuant to this Regulation, the Commission should ensure that they are proportionate, technologically neutral and do not create unnecessary administrative burden.
(20b) European Business Wallets could benefit from the development and deployment of trustworthy automated transactions or AI solutions. In particular, European Business Wallets may use AI based services and solutions to support multilingual processing of transactions, including through automated translation and language-processing tools, thereby helping businesses operate more effectively across the internal market.
(20c) To facilitate the secure and trustworthy use of automated transactions or AI in the context of the European Business Wallets infrastructure, European Business Wallet users may authorise AI systems, including AI agents, to act on their behalf. The existence, validity, scope and status of authorisations granted by a European Business Wallet user should be verifiable and auditable, and should ensure a level of assurance and accountability equivalent to actions performed by a user. Member States should retain the right to regulate and approve specific solutions. Such AI systems should be fully compliant with the applicable Union and national law. The Commission should issue guidance for the purpose of achieving the required levels of interoperability, safety and security.
(21) European Business Wallets should simplify the complex interactions between economic operators and public sector bodies, and should also facilitate interactions among economic operators themselves, reducing administrative burden and costs on economic operators in a broad range of economic sectors. In order to foster innovation and competitiveness, the European Business Wallets should enable sector-specific use cases and enhance operational efficiencies, while ensuring flexibility and adaptability to support the unique requirements of different sectors, including, but not limited to, agriculture, industry, energy, environment, social security coordination, with particular attention to sectors characterised by a high number of cross-border activities.
(22) The use of the European Business Wallets in such contexts can aid in the reduction of costs and promote a wide range of applications and use cases across the Union, such as Know Your Customer (KYC) and Know Your Business partner (KYB) processes, beneficial ownership verification, business permits, digital product passports, the submission of declarations, certificates and compliance data, applications for public funding, participation in public procurement procedures, access to public services, fulfilling due diligence obligations and facilitating secure cross-border data sharing and access within data spaces, such as the submission of A1 certificates concerning posted workers provided for under Regulation (EU) 883/2004. Facilitating regulatory compliance and administrative procedures could include making use of European Business Wallets in the secure submission, sharing and reuse of verified information required for public procurement, tax and VAT-related procedures, electronic declarations, such as the e-declaration of posted workers, and sustainability-related disclosure, such as environmental, social and governance reporting, as defined by Union law.
(22a) To ensure seamless integration across Union digital infrastructures and reduce unnecessary administrative burden for economic operators, European Business Wallets should enable secure access to, as well as presentation and exchange of Digital Product Passport data. To that end, the technical frameworks governing European Business Wallets and Digital Product Passports should, where appropriate, rely on common or compatible interfaces and standardised technical protocols that enable secure and efficient data exchange between both systems.
(22b) In order to facilitate cross-border business transactions and reduce unnecessary administrative burden, European Business Wallets should be able to support, through interoperable and technology-neutral implementation, business processes linked to the exchange of business data and documents between economic operators and with public sector bodies. Such processes may include, where relevant under Union or national law, the exchange of structured electronic invoices and related business documents as e-invoicing is a core digital business process that supports automation, reduces administrative burden and improves cash-flow management, in particular for SMEs.
(22c) European Business Wallets should function as an interoperable unifying architectural layer rather than an additional platform, enabling integration with existing and future national and Union-level digital gateways for efficient interaction of economic operators with public sector bodies.
(23) The establishment of the European Business Wallets alongside the Once Only Technical System is expected to create powerful synergies that maximise efficiency and operational ease. In particular, economic operators should be able to use the European Business Wallet to hold and transmit evidence retrieved from competent public authorities through the Once-Only Technical System. Where appropriate, economic operators should also be able to combine evidence held in the European Business Wallet with evidence retrieved via the Once Only Technical System in the context of public procedures. Consequently, by providing a secure digital platform for storing, combining and exchanging business documents, the European Business Wallets should facilitate the exchange ▌between public sector bodies of such documents retrieved through the ▌Once-Only Technical System. The technical system supporting such interactions should also enable the exchange of machine-readable structured data.
(23a) The Commission should provide further guidance on how possible overlaps between the requirements stemming from Regulation 2018/1724 and from this Regulation could be avoided, in order to improve synergies, efficiencies and interoperability.
(24) In order to ensure coordination between the Union’s ongoing digitalisation of judicial cooperation, the modernisation of secure cross-border information exchange, and the need to provide economic operators with efficient digital tools to interact with authorities, it is necessary to establish a coherent framework that enables smooth interaction between such relevant systems. Enhancing such coordination will reduce administrative burden, improve legal certainty, and strengthen the effectiveness of cross-border cooperation, by ensuring that communication channels used by economic operators function seamlessly within the European digital market. In that context, European Business Wallets should complement the systems set out in Regulation (EU) 2023/2844 and Regulation (EU) 2023/969, where a seamless interaction between these systems and the Business Wallets should be maintained through the Business Wallets gateway, enabling relevant authorities to maintain these systems whilst promoting simplification ▌. The framework for European Business Wallets should remain technologically neutral, so that different compliant solutions can coexist and reflect national specificities while remaining fully interoperable.
(25) To facilitate a flexible and efficient exchange of information and services when using European Business Wallets, and to ensure seamless integration of European Business Wallets with existing digital identity solutions, it should be possible to use European Digital Identity Wallets, notified electronic identification means and electronic attestations of attributes for onboarding to and access management of the European Business Wallets, so that access to the European Business Wallet does not depend on the use of a specific digital identity solution. This should enable European Business Wallet users to leverage existing digital identities and electronic attestations of attributes to access European Business Wallets, thereby streamlining the onboarding process and enhancing the overall user experience. The use of electronic attestations of attributes in the context of the European Business Wallets should cater to the diverse needs of European Business Wallet owners and may be used to issue and enable the secure and trustworthy verification of key attributes, such as an owner's current address, VAT registration number, tax reference number, Legal Entity Identifier (LEI), Economic Operator Registration and Identification (EORI) number and excise number. European Business Wallets should support a wide range of use cases, from simple authentication and identification to more complex transactions and interactions.
(26) In order to ensure the highest level of security and trustworthiness for the operation of European Business Wallets, providers of European Business Wallets should ensure that each European Business Wallet they provide is pre-configured to interact with certain trust services, which are required to enable the core functionalities of European Business Wallets, including the creation of qualified electronic signatures, the creation of qualified electronic seals, and the issuance and validation of qualified and non-qualified electronic attestations of attributes. To support these functionalities, European Business Wallets should allow for the sharing ▌storage, and verification of specific information and documents relating to the owner, such as messages and documents for the secure communication channel, signed and sealed documents, and sets of attributes for attestation-related services.
(27) To allow for the legal recognition of electronic attestations of attributes presented via European Business Wallets, it is necessary to allow for the creation and validation of linked attestations, whereby one attestation is cryptographically linked to another in a manner that allows the verification of the authenticity and integrity of each individual attestation, and of all linked attestations collectively. To that end, the European Business Wallet infrastructure should, through the use of the chain of attestations, enable the submission of a single instance of an attestation and facilitate its subsequent reuse across relevant procedures. Such functionality should allow European Business Wallet owners to transmit a reference to a document where appropriate with a cryptographic element, such as a hash key to a sealed attestation issued by a European Business Wallet, thereby attesting to the integrity and authenticity of the original submission.
(27a) In order to ensure a competitive market for providers of European Business Wallets, to enhance consumer choice and avoid vendor lock-in, European Business Wallet owners should be able to export their data, including issued European Business Wallet owner identification data, electronic attestations of attributes, communication logs, and interaction records, in a structured, commonly used and machine-readable format to another European Business Wallet.
(28) In order to ensure that the standards and technical specifications for European Business Wallets ensure interoperability across various solutions, it is necessary to define the standards and protocols for the core functionalities and technical requirements for European Business Wallets in an Annex to this Regulation. The common protocols and interfaces should be clear and unambiguous to avoid giving rise to different interpretations. The Annex should set out the requirements for the implementation of European Business Wallets. To ensure the long-term viability and effectiveness of the European Business Wallets, implementing powers should be conferred on the Commission to establish and update the procedures and technical specifications on the implementation of core functionalities, thereby allowing for the integration of additional features and new technologies that would enable new use cases, such as agentic AI or the provision of a digital identity to an owner’s asset, and enabling the European Business Wallets to continue to support the evolving needs of economic operators in a secure and trustworthy manner. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council. To the extent possible, the standards and technical specifications of the European Business Wallet should take into account relevant technical solutions and standards used by existing ICT systems of economic operators, thereby facilitating their alignment and interoperability with the European Business Wallets. To ensure the timely development and deployment of European Business Wallets throughout the Union, the implementing acts set out in this Regulation should be adopted within a limited timeframe after this Regulation comes into force. In exercising those powers, the Commission should keep the European Parliament fully and promptly informed, given the structural importance of those implementing acts for the Union’s trust infrastructure. In order to support interoperability and foster innovation, providers are encouraged to release the source code of the application software of European Business Wallets under an open source licence.
(29) To support the timely development of the market for European Business Wallets, the adoption of the implementing acts on core functionalities and the accompanying technical specifications should be prioritised and completed within a short period following the entry into force of this Regulation in order to enable providers to develop compliant European Business Wallet solutions without undue delay. Where appropriate, these should build on the existing standards including those set out in the Architecture and Reference Framework provided for in the context of Regulation (EU) No 910/2014, to support the re-use of familiar technical standards and uptake of the European Business Wallets.
(30) To ensure the high level of trust, functionality, and security of European Business Wallets for the cross-border provision of their services, and in particular to mitigate the risk of fraud, providers of European Business Wallets should be subject to clear and proportionate requirements and obligations as laid down in this Regulation, without being subject to additional national requirements. Providers should notify the relevant Member State supervisory body without undue delay of any substantive changes to their services or overall structure which could impact the compliance of the provider with this Regulation.
(30a) To facilitate the trusted participation of economic operators, providers of European Business Wallets should ensure that European Business Wallets and supporting infrastructure are secure-by-design by default and comply with the relevant cybersecurity requirements laid down in Directive (EU) 2022/2555. Providers should ensure appropriate safeguards for data access, storage and transfer, while taking into account the risks associated with centralised components and dependencies. Where appropriate, governance and implementation models should avoid excessive concentration of critical functions and ensure resilience through secure and reliable architectures, thereby supporting trust and the proper functioning of the internal market.
(30b) Given the key role of European Business Wallets in the Union’s digital infrastructure, the providers of European Business Wallets and qualified trust service providers should be ready to adapt to the quantum era and ensure they are prepared to transition to post-quantum cryptography in advance of the quantum breakthrough.
(31) To ensure proper supervision in line with this Regulation, entities that would like to become providers of European Business Wallets should be required to notify their intention to provide such European Business Wallets to the supervisory bodies prior to offering their services so that supervisory bodies can assess whether providers meet the relevant requirements of this Regulation. In order to safeguard the integrity and accountability of European Business Wallet providers and to ensure the security of data stored or exchanged in the European Business Wallets ecosystem, providers should be established within the Union. This should ensure that such providers fall under the jurisdiction and supervision of a competent body in a Member State, allowing for effective enforcement of this Regulation and the protection of users' rights and data. Furthermore, providers of European Business Wallets should not present a risk to the security of the Union, namely by not being subject to either direct or indirect control by a third country or by a third-country entity, to ensure that the Union's critical digital infrastructure remains secure and resilient. In line with the requirements set out in this Regulation, the Commission may adopt implementing acts to ensure cooperation and interoperability with solutions established or endorsed by like-minded partners of the Union.
(31a) The concept of control should be understood in line with Regulation (EU) 2026/1386, and in particular having due regard to a company´s ownership structure and significant funding, specific governance arrangements, such as golden shares, or other features aimed at influencing management decisions. In addition, the applicability of third-country laws that impact jurisdiction over the company or its data should be considered. Ownership and governance of a provider of European Business Wallets should be subject to regular monitoring by supervisory bodies for the entire period during which they provide a European Business Wallet.
(31b) To ensure a high level of security, trust and resilience within the European Business Wallets ecosystem and to safeguard the Union’s digital sovereignty, providers of QERDS, as well as cloud computing service providers, should be established in the Union, have their principal place of business and main operations in the Union and not present a risk to the security of the Union. In particular, they should not be subject to control by a third country or by a third-country entity. To that end, the storage and processing of data within European Business Wallets should take place exclusively on infrastructure located within the Union and subject to Union law. Establishing such infrastructure within the Union serves to limit exposure to the extraterritorial application of laws of third countries, enables effective supervision by the competent authorities and contributes to the protection of sensitive business information, while simultaneously strengthening the Union's capacity to provide secure and trustworthy digital services to economic operators and public sector bodies.
(32) The Union must protect its security interest against providers and suppliers which could represent a persistent security risk due to the potential interference from third countries. To that end, it is necessary to reduce the risk of strategic dependencies on high-risk suppliers in the internal market, including in the ICT supply chain, as they could have potentially serious negative impacts on the security of economic operators and public sector bodies across the Union and the Union’s critical infrastructure, especially with regards to the integrity, confidentiality and availability of data and services. Any restrictions should be based on a proportionate risk assessment and corresponding mitigation measures as defined in Union policies and laws. Such limitations may apply, for example, to high-risk suppliers, as identified under Union law.
(32a) To ensure that digital services are user-firendly and accesible, European Business Wallet providers should ensure that their services are accessible for persons with disabilities, in accordance with Directive (EU) 2019/882.
(33) In order to establish the identity of economic operators in a secure and reliable manner, this Regulation should allow for the use of qualified electronic attestations of attributes to issue European Business Wallet owner identification data. Qualified electronic attestations of attributes can be easily updated or revoked. The use of qualified electronic attestations of attributes for establishing the identity of economic operators provides an efficient, and secure solution that is suited to the needs of the digital economy. Qualified trust service providers issuing these attestations are regulated under Regulation (EU) No 910/2014 and are subject to strict requirements and scrutiny, ensuring a high level of security and trust in the issuance process. The authentic sources used to verify the data contained in the qualified electronic attestations of attributes are business registers and other registers, and the use of the Business Registers Interconnection System (‘BRIS’) and the Beneficial Ownership Registers Interconnection System (‘BORIS’) should be promoted to facilitate the verification of this data, thereby ensuring the accuracy and reliability of the identification data.
(34) This Regulation should not affect the functioning or the role of business registers as authentic sources and should not alter the way they operate or the data filed therein but rather build upon and complement the existing infrastructure. Member States should, in a timely manner, ensure that business registers are digitally accessible and technically capable of issuing electronic attestations of attributes. In this regard, where electronic attestations of attributes are issued by or on behalf of an authentic source, such as a business register, the register could directly issue the relevant data, further enhancing the security and reliability of the identification process.
(35) Regulation (EU) No 910/2014 requires Member States to ensure that measures are taken to allow qualified trust service providers to verify by electronic means, at the request of the user, the authenticity of the attributes listed in Annex VI of Regulation (EU) No 910/2014, such as educational and professional qualifications, titles and licenses, powers and mandates to represent natural or legal persons, public permits and licenses and financial and company data. The European Business Wallets framework should build on this existing requirement that should cover all official data that is relevant for economic operators in the context of the European Business Wallets and enable the electronic verification of attributes to facilitate the issuance of European Business Wallet owner identification data and other electronic attestations of attributes.
(36) As all economic operators and entities conducting economic activities should be able to use European Business Wallets, including self-employed persons and sole traders, European Business Wallet owner identification data should be provided in a manner that is specifically designed to verify their identity and attested attributes within a business context. To ensure consistency with existing Union frameworks and facilitate cross-border interoperability, the European Business Wallet framework should use the European Unique Identifier (EUID) provided by the codified Company Law Directive (EU) 2017/1132() and Commission Implementing Regulation (EU)2021/369() as well as Regulation (EU) 2024/1624() and Commission Implementing Regulation (EU) 2021/369(). Companies and other legal entities as well as arrangements such as trusts are assigned a European Unique Identifier to enable their unequivocal identification in cross-border situations. The European Unique Identifier is currently made publicly accessible through BRIS and used by BORIS. Accordingly, the European Business Wallet framework should rely on the issuance and recording process of European Unique Identifiers as the means of verifying the identity of economic operators to which European Unique Identifiers are provided in accordance with Directive (EU) 2017/1132. The European Business Wallet framework should rely on the issuance and recording process of European Unique Identifiers for other economic operators falling under Directive (EU) 2015/849.
(36a) To ensure the effective functioning and widespread use of European Business Wallets, Member States should ensure that all requests for a unique identifier by economic operators and public sector bodies established in their territory are carried out without undue delay. Where appropriate, such identifiers should be derived from or linked to identifiers already used in national registers, notably company registers or other official registers, in order to promote interoperability and avoid duplication. Member States should ensure that unique identifiers are assigned automatically at the time of registration of a new company or other legal entity in a national register. Member States should also lay down procedures to ensure that economic operators that are not subject to registration in national company registers can be issued such an identifier by a competent national authority, thereby enabling all economic operators to make effective use of European Business Wallets.
(37) To ensure that all European Business Wallet owners can be reliably identified and their electronic attestation of attributes are associated with a unique entity, it is also necessary to assign a unique identifier to other economic operators and public sector bodies that do not yet have such an identifier under Union law. A unique identifier should, upon the request of the economic operator, be created, without undue delay. To ensure uniform conditions for the implementation of unique identifiers, in particular their effectiveness and consistency, implementing powers should be conferred on the Commission to specify the detailed requirements for the unique identifiers. Those powers should be exercised in accordance with Regulation (EU) No 182/2011. Given the diverse approaches among Member States regarding the registration of some economic operators and public sector bodies, it is important to ensure transparency and accessibility for providers of European Business Wallet owner identification data. To this end, Member States should notify to the Commission the authentic sources that are relevant for the issuance of European Business Wallet owner identification data.
(37a) In order to ensure that European Business Wallets can be effectively used, the framework for unique identifiers should support hierarchical and operational identifiers reflecting the structure and activities of economic operators by accommodating complex business structures, such as subsidiaries, branches, establishments or operational units that require distinct identification. The identifier framework should allow for the association of identifiers with such entities while maintaining a clear link to the economic operator to which they belong. Such flexibility is necessary to ensure interoperability with existing business systems and to support compliance processes, including electronic invoicing and reporting obligations. Furthermore, where natural persons act in various economic capacities, notably as self-employed persons, sole traders, entrepreneurs or representatives of legal entities, the framework could provide for the assignment of identifiers reflecting such distinct roles, insofar as necessary for the purposes of European Business Wallets and where relevant regulation in the Member State concerned allows it.
(38) In order to ensure the efficient, secure, and transparent functioning of the European Business Wallet framework, it is necessary to establish a European Digital Directory, that includes personal data of economic operators. The Commission should be empowered to set up and maintain this Directory, as a trusted source of information on economic operators and public sector bodies using European Business Wallets. The Directory should enable European Business Wallet owners to be easily contacted to promote legal certainty in relation to dealings between businesses and in relation to interactions with public sector bodies, particularly in the view of promoting trade between Member States. European Business Wallet Providers, liaising with the Commission, should submit the necessary information to support the functioning of the European Digital Directory and collaborate with the relevant qualified trust service providers, providers of electronic attestations of attributes issued by or on behalf of a public sector body responsible for an authentic source, and authentic sources, to ensure that the data submitted remains accurate. Such actions should not indirectly create a requirement for economic operators to update such information. In this regard the Digital Directory will rely on the information made available by business registers including, but not limited to, those accessible through BRIS while ensuring that such information will not be duplicated.
(39) Regulation (EU) 2016/679 and Regulation (EU) 2018/172 of the European Parliament and of the Council apply to all personal data processing activities under this Regulation. Where the operation of the European Digital Directory includes the processing of personal data this will be carried out in accordance with Regulation (EU) 2018/1725. The relevant data protection principles, such as the data minimisation and purpose limitation principle, obligations, such as data protection by design and by default, and include, where appropriate, features of pseudonymisation and anonymisation should apply to all personal data processing under this Regulation.
(40) In order to ensure that regulatory burdens remain proportionate, ex post supervision of providers of European Business Wallets and monitoring of their activities should be provided for, along with proportionate rather than requiring prior compliance verification▌. This approach should allow for a more flexible, risk-based and efficient regulatory environment, while maintaining the necessary safeguards to protect users and ensure compliance with the requirements of the European Business Wallets framework. The notification process for providers of European Business Wallets should be clear, transparent, streamlined and efficient, with well-defined requirements and timelines for applicants. National supervisory authorities should, however, be given adequate time to review, assess, and validate the notified information to ensure that the providers comply with the relevant requirements laid down in this Regulation ▌.
(41) In order to ensure transparency and accountability in the European Business Wallet ecosystem, a publicly available list of notified providers of European Business Wallets should be established and maintained by the Commission. That list should include information transmitted by the national supervisory bodies concerning providers, including qualified trust service providers, that have completed the notification process. Making that information publicly available should enable users to verify the authenticity and trustworthiness of providers, complying with the requirements and obligations for providers of European Business Wallets laid down in this Regulation thereby promoting a high level of security and trust in the European Business Wallet ecosystem. That list should be updated without undue delay following the completion of the notification process in order to ensure legal certainty for entities intending to provide European Business Wallets and for users of such services.
(42) Effective oversight by supervisory bodies, vested with sufficient powers and provided with adequate resources, is essential to ensure that European Business Wallets made available in the Union comply with the requirements laid down in this Regulation. To best ensure such oversight and relevant expertise, Member States should designate the ▌ supervisory body or bodies for the purposes of supervising the application and enforcement of this Regulation ▌. Member States should ensure the effective supervision of providers of European Business Wallets, especially as regards the requirements on being established in the Union and complying with applicable cybersecurity requirements, including those relating to the identification of high-risk suppliers. Providers of European Business Wallets should provide the needed information for assessment of compliance with those requirements. The Commission should issue guidance, where necessary, specifying the information necessary for establishing proof of compliance.
(43) Due consideration should be given to ensuring effective cooperation between supervisory bodies designated under this Regulation, Article 46b of Regulation (EU) No 910/2014 and the competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the European Parliament and of the Council()Since the competent authorities are distinct entities, they should cooperate closely and in a timely manner, including by exchanging relevant information to ensure effective supervision and compliance of European Business Wallet providers with the applicable obligations under Regulation (EU) No 910/2014 and Directive (EU) 2022/2555.
(44) To ensure the enforcement of this Regulation, national supervisory bodies should be empowered to impose administrative fines. It is necessary to specify the upper limit of administrative fines and the criteria for their determination in order to promote equal treatment of providers of European Business Wallets across the Union regardless of their Member State of establishment. The competent supervisory authority should assess each case individually, taking into account all relevant circumstances, including the nature, gravity, recurrence and duration of the infringement, its consequences and any measures taken to ensure compliance and mitigate harm. In this regard, Member States should notify the Commission of the rules laid down in national law allowing the supervisory body to impose penalties by [Publications Office, insert the date 12 months after the entry into force of this Regulation] and should notify the Commission without delay of any subsequent amendments to those rules.
(45) In order to ensure the proper functioning of the internal market and to protect the rights of economic operators, it is necessary to establish a mechanism enabling the Commission to intervene in cases where a provider of European Business Wallets is found, supported by objective evidence, to be repeatedly non-compliant with the requirements of this Regulation and where no effective, timely and proportionate measures have been taken by the competent supervisory authority to remedy the situation. This mechanism should allow for the Commission to carry out an evaluation of compliance, consult with the Member States concerned and the provider, and adopt implementing acts to provide for corrective or restrictive measures. This should enable the Commission to take swift and effective action to address any non-compliance and to ensure that the European Business Wallets are used in a secure and trustworthy manner.
(46) The Cooperation Group established pursuant to Regulation (EU) No 910/2014 should be given the additional responsibility for the coordination of national practices and policies related to this Regulation and facilitate discussions between competent authorities regarding the Regulation's application and enforcement, thereby delivering on the objectives of the Cooperations Group’s establishment and retaining expertise for the benefit of implementing the European Business Wallet framework. Member States may appoint additional members to the European Digital Identity Cooperation Group established pursuant to Regulation (EU) No 910/2014, as the tasks of the Cooperation Group will be extended to cover issues related to European Business Wallets. The Commission should furthermore ensure that a wide range of relevant stakeholders will be invited to participate in its work, where appropriate, to enable a fruitful cooperation on emerging policy initiatives in the field of digital identity wallets, European Business Wallets, electronic identification means and trust services.
(46a) The Digital Identity Cooperation Group should support the implementation of European Business Wallets. It should act as a platform for sharing best practices concerning the most relevant use-cases for European Business Wallets, especially with regard to SMEs and procedures that are particularly relevant for companies engaged in cross-border activities. Furthermore, in order to facilitate cross-border interoperability and ensure compatibility between European Business Wallets and existing systems and solutions at both Union and national level, the European Digital Identity Cooperation Group should facilitate cooperation and information sharing on technical and operational issues to ensure the proper implementation and functioning of European Business Wallets, with a view to avoiding unnecessary transition costs or duplication of infrastructures.
(47) In order to support effective take-up and interoperability, all public sector bodies should be required to enable the use of the European Business Wallet in all relevant administrative procedures for the purposes of identification and authentication, signing or sealing documents, submitting documents and sending or receiving notifications. To facilitate the effective implementation and deployment of European Business Wallets, Member States should provide public authorities, especially at local level, with the necessary financial resources and targeted technical assistance. In this regard, public sector bodies should by ▌24 months after the entry into force of the implementing acts provided for in this Regulation ▌ ensure that the use of European Business Wallets by economic operators is possible and that, where the receipt or communication of documents or notifications is concerned, they are able to access the Business Wallets’ secure communication channel. To ensure seamless and interoperable application of this Regulation ▌, public sector bodies should own or have a right to use a European Business Wallet for the purposes of receiving or sending documents and notifications. However, while it is necessary for all public sector bodies to accept the usage of European Business Wallets, attention should be paid to the capacity of smaller public sector bodies to comply with that obligation. To ensure acceptability, Member States should ensure that there is adequate and appropriate support to smaller public sector bodies, including, where possible, that affordable European Business Wallets are available for use by such entities. The obligation for public sector bodies to accept European Business Wallets by economic operators should not affect systems used for the exchange or submission of documents or data between competent authorities. In order to ensure cost-effective implementation, Member States should be able to prioritise implementation and use-cases with the highest administrative or cross-border relevance.
(48) In order to avoid disrupting existing interactions between economic operators and public sector bodies, it is necessary to enable a transition period until ▌ 36 months after the entry into force of the relevant implementing acts provided for in Articles 5(5) and 6(5) of this Regulation ▌. During such period public sector bodies may choose not to offer the European Business Wallets' secure communication channel and instead support alternative solutions already in place which enable economic operators to communicate with public sector bodies prior to offering the European Business Wallets’ secure communication channel. In order to ensure an adequate level of security and interoperability, any alternative solution used during this transition period should comply with the requirements for Qualified Electronic Registered Delivery Services set out in Regulation (EU) No 910/2014 and offer a gateway to European Business Wallets. The gateway should enable users of European Business Wallets to access the alternative solutions used during the transition period. After this period, public sector bodies should support the secure communication channel of the European Business Wallets to ensure a harmonised and efficient means of communication across the Union, to the benefits of European businesses and the proper functioning of the internal market.
(48a) In order to support the efficient and coherent implementation and wide uptake of European Business Wallets, the Commission and Member States should raise awareness of European Business Wallets with economic operators, especially SMEs, and public sector bodies. In addition, the Commission should, in close cooperation with Member States, develop and regularly update a comprehensive and forward-looking Implementation Roadmap. That Roadmap should extend beyond the initial deployment phase, and identify key milestones and priority use-cases and practical applications in business-to-government (B2G), government -to- business (G2B) and business-to-business (B2B) interactions, especially for SMEs. It should also take into account the need to ensure cross-border interoperability and interoperability with existing digital solutions at both Union and national level, with a view to facilitating uptake by economic operators and supporting public sector bodies at all levels, including those with limited administrative or technical capacity.
(49) European Business Wallets contribute to the provision of a cross-border digital public service within the meaning of the Interoperable Europe Act (EU) 2024/903. The assessment required under that Regulation has been carried out, and the resulting report will be published on the Interoperable Europe Portal.
(50) To ensure that the European Business Wallets ecosystem continues to meet the needs of economic operators and public sector bodies, it is necessary to assess its implementation and impact in light of the purpose of this Regulation. The evaluation should, in particular, take into account the risk of legal fragmentation within the internal market regarding the electronic submission of documents and attestations of attributes as well as the technological developments and progression of the market for European Business Wallets and associated trust services. The evaluation should furthermore assess whether this Regulation has reduced administrative burden and compliance costs, especially for SMEs and smaller public sector bodies and supported the wide uptake of European Business Wallets and their respective usage for cross-border business, as well as identified obstacles to the interoperability of national and European systems.
(51) To avoid duplication and reduce administrative burden, public sector bodies should not require the same information or documents to be submitted again through physical or alternative digital means, or in the inverse, once these have been validly transmitted via the European Business Wallet in accordance with this Regulation. Accordingly, Member States should not adopt or maintain additional national requirements regarding matters falling within the scope of this Regulation, unless explicitly provided for herein, since this would affect its direct and uniform application.
(52) In order to enable effective access to Union procedures and markets and facilitate the participation of economic operators established outside the Union in the European Business Wallet framework, it is necessary to enable providers of European Business Wallets to issue European Business Wallets to such operators, provided that their identity can be verified with a high level of certainty. To prevent duplicate registrations and safeguard the integrity of the internal market, such operators should not be allowed to obtain more than one set of European Business Wallet owner identification data and one unique identifier. Member States’ should cooperate to mitigate the risk of duplicate registrations and ensure the uniqueness of registrations of economic operators established outside of the Union.
(53) The implementing act concerning the requirements and procedures for the unique identifier should encompass the conditions for their issuance to third country economic operators. In particular, it should set the conditions that promote coordination between providers of European Business Wallet owner identification data, ensuring that each third country economic operator is attributed only one unique identifier for the purpose of the European Business Wallet owner identification data. Prior to the provision of a European Business Wallet to an economic operator established outside the Union the relevant provider should confirm that the conditions for verifying the identity of the economic operator have been met. That should allow economic operators from third countries to use European Business Wallets, while preserving the security and trustworthiness of the ecosystem. In addition, providers should carry out appropriate checks to verify that third-country economic operators are not engaged in activities contrary to the Union’s security, including breaches of Union restrictive measures or involvement in money-laundering or terrorist financing.
(54) In order to ensure legal certainty, preserve a high level of trust and guarantee uniform conditions for the implementation of the recognition and interoperability of business wallets or similar solutions and framework from like-minded third countries and to support and promote partnerships and cooperation, implementing powers should be conferred on the Commission to set the conditions under which such similar solutions or framework benefit from the provisions of this Regulation. Before adopting those implementing acts, the Commission should conduct a comprehensive assessment to ensure that the third-country solution offers an equivalent level of protection to that guaranteed within the Union. In particular, the Commission should evaluate data protection standards to prevent the unlawful processing of sensitive business data and ensure compliance with cybersecurity requirements to mitigate the risk of unauthorised access or systemic disruption. Furthermore, the independence of the third-country system and its providers from high-risk government control should be scrutinised to ensure that the wallet infrastructure remains resilient against extraterritorial interference, which could compromise the integrity of digital transactions and the autonomy of Union entities. Those implementing powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council. Once an equivalence has been established with the implementing act, the Commission should endeavour to negotiate mutual recognition agreements with the third countries, where appropriate.
(55) Regulation (EU) No 910/2014 offers a secure and convenient means for Union citizens and residents in the Union as defined by national law, to identify themselves and access online services. It requires Member States to ensure that European Digital Identity Wallets are provided to legal persons, despite a lack of clarity on the specific technical implementation of European Digital Identity Wallets for legal persons. This uncertainty about the purpose and functioning of the European Digital Identity Wallets for legal persons increases legal and technical complexity for Member States. It is therefore necessary to amendment Article 5a of Regulation (EU) No 910/2014 to ensure that the mandatory issuance of European Digital Identity Wallets relates only to natural persons.
(56) The framework established by this Regulation should provide a secure, Union-wide digital infrastructure and should therefore constitute the principal instrument for such purposes. To fully realise the benefits of the European Business Wallet framework for both economic operators and public sector bodies, it is necessary to promote its use as the default tool for secure digital identification, authentication, and the exchange of electronic documents and attestations of attributes.
(57) To ensure a coherent and horizontal application across sectors of Union legislation, reduce administrative cost on economic operators and to improve budgetary efficiency, Union law concerning electronic identification, authentication, or the exchange of electronic documents, notifications, or attestations of attributes, particularly where specific technical requirements, systems, or protocols are established, should be applied in a manner consistent with this Regulation. Accordingly, any future legislative or non-legislative initiatives in these fields should adhere to the Business-Wallet-by-Default principle and should be designed and developed to build upon and enable the use of European Business Wallets. Where such alignment is not possible, the Commission should provide a written justification through an Impact Assessment, accompanying the relevant initiative, setting out the reasons for not enabling the use of European Business Wallets. ▌
(57a) The Commission should evaluate and review this Regulation by [three years from the date of entry into force of this Regulation] and every four years thereafter and report to the European Parliament and the Council. That review is essential for assessing the continued relevance of the prescribed core functions and technical specifications, especially those associated with the QERDS as a secure communication channel, in the context of the latest technological advancements. Furthermore, the Commission should evaluate the notification procedures for providers of European Business Wallet, as well as the implementation and effectiveness of the rules on penalties established by Member States, to evaluate market developments and compliance levels. The Commission should assess the overall uptake of European Business Wallets and evaluate the achievement of the expected indirect benefits, such as, enhanced competitiveness, as well as, facilitated fraud reduction and environmental sustainability. Based on the results, the Commission should evaluate whether it is necessary to modify the scope of this Regulation or its specific provisions, in particular when assessing whether new core functionalities should be added. Any such modification should be accompanied by an Impact Assessment.
(58) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council(), and delivered an opinion on [insert date].
HAVE ADOPTED THIS REGULATION:
Chapter I - Subject matter, scope and definitions
Article 1
Subject matter
This Regulation enables secure digital identification and authentication, data sharing and legally valid notifications, reduces administrative burdens and compliance costs, and supports cross-border business and competitiveness. In particular, it:
(1) establishes a secure framework for the provision of European Business Wallets;
(2) establishes the principle of equivalence, giving equivalent legal effect to actions and transactions carried out through a European Business Wallet as to actions and transactions lawfully carried out in person, in paper form, or via any other means or processes that would be deemed compliant with applicable legal, administrative, or procedural requirements;
(3) establishes rules for the issuance of European Business Wallet owner identification data for the identification of economic operators and public sector bodies;
(4) establishes the European Digital Directory;
(5) designates the European unique identifier (EUID), as established and governed by Directive (EU) 2017/1132, as the unique identifier for European Business Wallet owners, and establishes a ▌ unique identifier for European Business Wallets owners to whom the European Unique Identifier is not available;
(6) lays down the notification mechanism under which providers of European Business Wallets shall be established;
(7) lays down obligations for public sector bodies concerning European Business Wallets;
(8) provides a framework for the supervision of Union entities, where such public sector bodies provide European Business Wallets to other Union entities;
(9) provides a framework for the recognition of third-country systems similar to the European Business Wallets which offer the same level of security, trust and digital standards as European Business Wallets, and the issuance of European Business Wallets to third country economic operators.
Article 2
Scope
1. This Regulation applies to the provision and acceptance of European Business Wallets and the issuance and acceptance of European Business Wallet owner identification data, and to the use of European Business Wallets by economic operators and public sector bodies.
2. This Regulation is without prejudice to the existing systems and procedures mandated by Union law governing the exchange of documents and data between competent authorities.
Article 3
Definitions
For the purposes of this Regulation, the following definitions apply:
(1) ‘European Business Wallet’ means a digital solution that allows European Business Wallet owners to securely request, receive, combine, store, manage, and present European Business Wallet owner identification data and electronic attestations of attributes to European Business Wallet-relying parties and other entities using European Business Wallets and European Digital Identity Wallets for the following purposes:
(a) to ▌ provide the verified proofs required by a European Business Wallet-relying party for authentication;
(b) to access and use electronic attestations of attributes, electronic signatures, electronic seals, electronic registered delivery services, and electronic time stamps;
(c) to create, manage or delegate mandates and roles to authorised representatives and users;
and that may support additional functionalities in accordance with this Regulation;
(2) ‘European Business Wallet owner identification data’ means a set of data that enables the establishment of the identity of a European Business Wallet owner and that is issued by a provider of European Business Wallet owner identification data;
(3) ‘provider of European Business Wallet owner identification data’ means a qualified trust service provider or public sector body or the Commission issuing European Business Wallet owner identification data;
(4) ‘economic operator’ means any natural or legal person, or a group of such persons, including temporary associations of undertakings, acting in a commercial, non-commercial or professional capacity for purposes related to their trade, business, craft or profession;
(5) ‘public sector body’ means a Union entity, a national, state, regional or local authority, a body governed by public law or an association formed by one or several such entities or bodies , or a private entity mandated by ▌ such entities, authorities, bodies or associations to provide public services, when acting under such a mandate;
(6) ‘Union entity’ means a Union institution, body, office and agency set up by or pursuant to the Treaty on European Union, the Treaty on the Functioning of European Union or the Treaty establishing the European Atomic Energy Community;
(7) ‘European Business Wallet owner’ means an economic operator or public sector body that owns or has a right of use of a European Business Wallet;
(8) ‘trust service’ means trust service as defined in Article 3, point (16) of Regulation (EU) No 910/2014;
(8a) ‘trust service provider’ means a trust service provider as defined in Article 3, point (19), of Regulation (EU) No 910/2014;
(8b) ‘qualified trust service provider’ means qualified trust service provider as defined in Article 3, point (20), of Regulation (EU) No 910/2014;
(9) ‘attribute’ means attribute as defined in Article 3, point (43) of Regulation (EU) No 910/2014;
(10) ‘electronic attestations of attributes’ means electronic attestations of attributes as defined in Article 3, point (44) of Regulation (EU) No 910/2014;
(11) ‘qualified electronic attestation of attributes’ means qualified electronic attestation of attributes as defined in Article 3, point (45) of Regulation (EU) No 910/2014;
(12) ‘European Digital Identity Wallet’ means European Digital Identity Wallet as defined in Article 3, point (42) of Regulation (EU) No 910/2014;
(13) ‘electronic signature’ means an electronic signature as defined in Article 3, point (10) of Regulation (EU) No 910/2014;
(14) ‘qualified electronic signature’ means a qualified electronic signature as defined in Article 3, point (12) of Regulation (EU) No 910/2014;
(15) ‘electronic seal’ means an electronic seal as defined in Article 3, point (25) of Regulation (EU) No 910/2014;
(16) ‘qualified electronic seal’ means qualified electronic seal as defined in Article 3, point (27) of Regulation (EU) No 910/2014;
(17) ‘qualified electronic time stamp’ means a qualified electronic time stamp as defined in Article 3, point (34) of Regulation (EU) No 910/2014;
(18) ‘authorised representative’ means a natural or legal person acting on behalf of the European Business Wallet owner in executing and operating functions of a designated European Business Wallet on the basis of an authorisation granted by a European Business Wallet owner;
(19) ‘mandate’ means the authorisation granted by a European Business Wallet owner to an authorised representative, enabling that representative to act on behalf of the owner in executing and operating functions of a designated European Business Wallet;
(19a) ‘automated transaction’ means a transaction executed by an authorised digital or AI systems, including those approved in accordance with Union or national law by Member States, performing actions under a valid, auditable and revocable authorisation issued by the European Business Wallet owner or authorised user, in full compliance with Union law;
(20) ‘electronic document’ means an electronic document as defined in Article 3, point (35) of Regulation (EU) No 910/2014;
(21) ‘qualified electronic registered delivery service’ means a qualified electronic registered delivery service as defined in Article 3, point (37) of Regulation (EU) No 910/2014;
(22) ‘user’ means a natural or legal person, or a natural person representing another natural person or a legal person, that uses European Business Wallets ▌provided in accordance with this Regulation;
(23) ‘European Business Wallet-relying party’ means a natural person, an economic operator or public sector body that relies upon European Business Wallets;
(24) ‘European Business wallet unit attestation’ means a data object that describes the components of the European Business Wallet unit or allows authentication and validation of those components;
(25) ‘European Business Wallet unit’ means a unique configuration of a European Business Wallet solution that includes European Business Wallet front-end and European Business Wallet back-end, wallet secure cryptographic applications and wallet secure cryptographic devices provided by a provider to a European Business Wallet to a specific European Business Wallet owner;
(26) ‘European Business Wallet solution’ means a combination of software, hardware, services, settings, and configurations, including European Business Wallet front-end and back-end, one or more wallet secure cryptographic applications and one or more wallet secure cryptographic devices;
(27) ‘critical assets’ means assets within or in relation to a European Business Wallet unit of such extraordinary importance that where their availability, confidentiality or integrity are compromised, that would have a very serious, debilitating effect on the ability to rely on the European Business Wallet unit or have significant operational, financial or reputational impact on the European Business Wallet owner;
(28) ‘wallet secure cryptographic application’ means an application that manages critical assets by being linked to and using the cryptographic and non-cryptographic functions provided by the wallet secure cryptographic device;
(29) ‘wallet secure cryptographic device’ means a tamper-resistant device that provides an environment that is linked to and used by the wallet secure cryptographic application to protect critical assets and provide cryptographic functions for the secure execution of critical operations;
▌
(32) ‘electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source’; means a electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source as defined in Article 3, point (46) of Regulation (EU) No 910/2014;
(33) ‘authentic source’ means authentic source as defined in Article 3, point (47) of Regulation (EU) No 910/2014;
(33a) ‘incident’ means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555;
(33b) ‘significant incident’ means an incident within the meaning of Article 23(3) of Directive (EU) 2022/2555;
(34) ‘attestation scheme’ means a set of rules applicable to one or more types of electronic attestation of attributes;
(35) ‘catalogue of schemes means a digital repository listing schemes for the electronic attestation of attributes registered in accordance with this Regulation and that is maintained and published online by the Commission;
(36) ‘European unique identifier’ means the European Unique Identifier referred to in Directive (EU) 2017/1132;
(37) ‘national register’ means an official database or system established and maintained by or on behalf of a national government or its designated authority, which records, stores, and manages information pertaining to legal entities, including but not limited to companies, partnerships, foundations, associations as well as businesses as natural persons such as sole-traders and self-employed persons or other registrable persons or organisations;
(38) ‘API’ or ‘Application Programming Interface’ means a set of definitions and protocols for building and integrating application software to share data;
(39) ‘submission’ or ‘submit 'means any transmission of structured or unstructured data, files, forms, or records by between a public sector body and an economic operator or between economic operators or between public sector bodies, where such transmission is required, requested, or permitted under Union or national law, and is intended to support a legal, administrative, or procedural purpose;
(40) ‘notification’ means any transmission of information, decisions, requests, or acknowledgements between a public sector body and an economic operator or between economic operators or between public sector bodies, which is required, requested, or permitted under Union or national law, and which is intended to produce legal effects or inform the recipient of rights, obligations, or procedural developments;
(41) ‘administrative procedure’ means a sequence of actions, defined by Union or national law, that must be taken by economic operators or public sector bodies to comply with obligations, provide information, or obtain a decision, authorisation, or benefit from a public sector body in the exercise of administrative functions;
(42) 'European Business Wallet front-end' means the user interface component, regardless of platform or form factor, that interacts with ▌ and is part of the European Business Wallet unit;
(43) 'European Business Wallet back-end' means the server-side components, including software, services, and infrastructure, that provide the necessary functionality and support for the European Business Wallet front-end, and form part of the European Business Wallet unit.
Chapter II – European Business Wallets
Article 4
Principle of equivalence
Where a European Business Wallet owner or an authorised representative makes use of any of the core functionalities of a European Business Wallet referred to in Article 5(1), the resulting action shall have the same legal effect as if the action had been lawfully carried out in person, in paper form, or via any other means or processes that would be deemed compliant with applicable legal, administrative, or procedural requirements.
Where a self-employed person or a sole trader makes use of the qualified electronic registered delivery service as a standalone service in accordance with Article 5(3), the resulting action shall have the same legal effect as if the action had been lawfully carried out in person, in paper form, or via any other means or processes that would be deemed compliant with applicable legal, administrative, or procedural requirements.
Article 5
Core functionalities of European Business Wallets
1. Providers of European Business Wallets shall ensure that the European Business Wallets they provide offer the following core functionalities, allowing owners to utilise any combination of those functionalities at their own discretion:
(a) securely issue, request, obtain, select, combine, store, delete, share and present electronic attestations of attributes;
(b) selectively disclose European Business Wallet owner identification data and attributes contained in electronic attestations of attributes, in the context of the functionalities listed in points (a) and (f);
(c) request and share European Business Wallet owner identification data and electronic attestations of attributes in a secured way between European Business Wallets and European Digital Identity Wallets and with European Business Wallet-relying parties;
(d) sign by means of qualified electronic signatures and seal by means of qualified electronic seals, as applicable;
(e) bind data in electronic form to a particular time by means of qualified electronic time stamps;
(f) securely issue, on behalf of the European Business Wallet owner, electronic attestations of attributes for data for which the European Business Wallet owner is the primary source to European Business Wallets and European Digital Identity Wallets;
(g) link electronic attestations of attributes ▌ issued pursuant to point (f) to other electronic attestations of attributes forming part of a chain;
(h) enable the use of qualified and non-qualified electronic attestations of attributes to allow authentication of European Business Wallet owners and their authorised representatives ▌;
(i) transmit and receive electronic documents and data including by means of a qualified electronic registered delivery service, which complies with Article 7(2) and the requirements set out in the Annex, and is capable of supporting confidentiality and integrity;
(j) authorise multiple users to access and operate the European Business Wallet of the owner, with the possibility to enable delegations of powers and to create auditable and clearly defined and restricted mandates and roles and for the European Business Wallet owner to manage and revoke such authorisations;
(ja) enable the European Business Wallet owner and its authorised representatives, to act in different roles or mandates within the same European Business Wallet, while ensuring a clear attribution of actions and appropriate logical separation between such roles, mandates or activities;
(k) authorise European Business Wallet-relying parties to request electronic attestations of attributes issued to the European Business Wallet owner, which are strictly necessary for the purpose of the transaction and prevent unnecessary processing, and for the European Business Wallet owner to manage and revoke such authorisations;
(l) export their data, including issued European Business Wallet owner identification data, electronic attestations of attributes, communication and transaction logs, and interaction records, in a structured, commonly used and machine-readable format, at the request of the owner or in the event of termination of service or revocation of the notification of the provider of the European Business Wallet and to import the data exported from a European Business Wallet unit to enable data portability across providers of European Business Wallets;
(m) access a log of all communication and transactions;
(n) access a common dashboard for accessing, storing and verifying communications exchanged through the qualified electronic registered delivery service referred to in point (i).
2. Providers of European Business Wallets may offer additional functionalities beyond those listed in paragraph 1 provided that such functionalities do not interfere with the security requirements set out in Article 6(2), point (c), or compromise the confidentiality, availability, security or integrity of the minimum core functionalities, and the reliability and interoperability of the European Business Wallets they provide. Such additional functionalities may support interoperability with company IT systems through standardised interfaces where appropriate. Such additional functionalities shall not be used to make access to the core functionalities conditional upon the use of optional services.
2(a) Such additional functionalities may include the following, but not limited to:
(a) enable the processing of electronic documents and metadata, and certified attributes in machine-readable formats, and facilitate comprehension, for example, via automatic translation of electronic attestations, documents, and communications where the relevant jurisdiction provides a framework to recognise corresponding automatic translations, while ensuring that all translated outputs remain linked to their source credentials and preserve the integrity, authenticity, and verifiability of the original certified attributes;
(b) authorise payment transactions and enable automatic payments, such as invoices issued by suppliers authenticated by the European Business Wallet.
3. Providers of European Business Wallets shall enable the provision of the qualified electronic registered delivery service referred to in paragraph 1, point (i) as a standalone service to users of European Digital Identity Wallets.
4. Providers of European Business Wallets shall implement the functionalities referred to in paragraph 1 in accordance with the requirements set out in the Annex.
5. The Commission shall by … [12 months from the date of entry into force of this Regulation], by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the core functionalities of European Business Wallets referred to in paragraph 1 of this Article, including those essential for interoperability and security and for wallet-to-wallet transactions between European Business Wallets and European Digital Identity Wallets. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.
Article 6
Technical requirements for European Business Wallets
1. Providers of European Business Wallets shall ensure that the European Business Wallets they provide support common protocols and interfaces and comply with the reference standards and specifications set out in paragraph 5 as well as with the technical requirements set out in the Annex:
(a) for the issuance of European Business Wallet owner identification data, qualified and non-qualified electronic attestations of attributes and qualified and non-qualified certificates to European Business Wallets;
(b) for European Business Wallet-relying parties to request and validate European Business Wallet owner identification data and electronic attestations of attributes;
(c) for the sharing and presenting to European Business Wallet-relying parties of European Business Wallet owner identification data, electronic attestation of attributes and of selectively disclosed data;
(d) to allow interaction with the European Business Wallets automatically without manual intervention or through direct user action, where such automated transactions, including those enabled by digital or AI systems, are verifiable and auditable and ensure an equivalent level of assurance and accountability as interactions performed by a European Business Wallet user, in full compliance with EU and national law;
(e) to securely onboard the European Business Wallet owner remotely via a▌ representative empowered to carry out the onboarding process with an electronic identification means of that authorised representative which meets the requirements of Regulation (EU) No 910/2014 with regard to the assurance level ▌ ‘high’;
(f) for multidirectional interaction between European Business Wallets, and between European Business Wallets and European Digital Identity Wallets for the purpose of receiving, validating and sharing European Business Wallet owner identification data and electronic attestations of attributes in a secure manner;
(g) for authenticating European Business Wallet-relying parties by implementing authentication mechanisms, where authentication is required;
(h) for European Business Wallet-relying parties to verify the authenticity and validity of European Business Wallets, where ▌required;
(i) for the provision of the qualified electronic registered delivery service referred to in Article 5(1), point (i), including an interface to the European Digital Directory established pursuant to Article 10;
(j) for the assigning to each European Business Wallet owner, for the purposes of the qualified electronic registered delivery service referred to in Article 5(1), point (i) and the European Digital Directory referred to in Article 10, at least one unique digital address;
(k) for the provision of wallet unit attestations to all European Business Wallet units, containing public keys and corresponding private keys protected by a wallet secure cryptographic device;
(l) for the management of critical assets, for the use of at least one wallet secure cryptographic application and wallet secure cryptographic device and, where critical assets relate to performing electronic identification at assurance level high, for ensuring that such cryptographic operators or other operations processing critical assets are performed in accordance with the requirements for the characteristics and design of electronic identification means at assurance level highas set out in Commission Implementing Regulation (EU) 2015/1502.
2. Providers of European Business Wallets shall also:
(a) ensure that the European Business Wallet owner identification data is uniquely and securely attributed to the European Business Wallet of the owner;
(b) ensure that, for the purposes of the functionality referred to in Article 5(1), point (j):
mappings between roles and attributes are verifiable, auditable, revocable and traceable to their legitimate issuers;
– conflicts of roles, over-delegation, or expired authorisations are automatically detected and prevented in real time;
– all authorisation logic is interoperable between European Business Wallets across Member States.
(c) ensure security-by-design and implement and document security controls that provide reasonable assurance;
(ca) ensure that data related to European Business Wallets is processed and stored exclusively within the Union;
(cb) ensure that for the purpose of the functionality referred to in Article 5(1), point (l), the owners of the European Business Wallet are provided with mechanisms to achieve unhindered data portability;
(d) provide validation mechanisms, in order to ensure that the authenticity and validity of European Business Wallets can be verified;
(e) provide a mechanism enabling European Business Wallet owners to easily request technical support and report technical problems or any other incidents having a negative impact on the use of European Business Wallets in a timely and effective manner;
(ea) provide a mechanism ensuring that the access to European Business Wallets and their functionalities is controlled and auditable;
(f) ensure that the validity of the European Business Wallets can be revoked in the following circumstances:
– upon the explicit request of the European Business Wallet owner or authorised representative, where the authorisation includes this power;
– where the security of the European Business Wallet has been compromised;
– where the security of the provider of the European Business Wallet as trust service provider, as defined in Article 3, point (19), of Regulation (EU) No 910/2014, has been compromised;
– upon the permanent or temporary cessation of activity of the European Business Wallet owner;
– where the provider of the European Business Wallet is not included in the list referred to in Article 12(3).
(g) without undue delay, notify to the Commission:
– the mechanism allowing for the validation of the European Business Wallet owner identification data;
– the mechanism by which to validate the authenticity and validity of European Business Wallets.
3. The Commission shall make available the information notified pursuant to paragraph 2, point (g) of this Article to the public through a secure channel, in electronically signed or sealed form suitable for automated processing.
4. Providers of European Business Wallets shall implement the technical requirements provided for in paragraphs 1 and 2 in accordance with the requirements set out in the Annex and implementing acts, pursuant to paragraph 5.
5. The Commission shall by … [12 months from the date of entry into force of this Regulation], by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the technical features of European Business Wallets including those critical for interoperability and security, provided for in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.
5a. Providers of European Business Wallets shall ensure that the storage and processing of data associated with European Business Wallets takes place on infrastructure located within the Union and subject to Union law. Such infrastructure shall be established and structured in a way that ensures that the competent supervisory authorities within the Union are able to exercise effective oversight and enforcement in accordance with this Regulation.
Article 7
Requirements and obligations for providers of European Business Wallets
1. European Business Wallets shall be provided by providers of European Business Wallets that are included in the list established pursuant to Article 12(3).
2. Given the role of European Business Wallets in the Unions digital infrastructure, providers of European Business Wallets shall be established in the Union, have their principal place of business and main operations in the Union and not present a risk to the security of the Union. In particular they shall not be subject to either direct or indirect control by a third country or by a third-country entity, including through rights or arrangements that enable a third-country public authority or entity to determine or materially influence strategic decisions concerning the governance, compliance, risk management, security policies or regulatory alignment of providers.
European Business Wallet providers shall only use providers of qualified electronic registered delivery services and cloud computing service providers that comply with the requirements set out in the first subparagraph. Those providers shall ensure that European Business Wallet data are stored, processed and transferred exclusively within the Union.
The data generated by using European Business Wallets shall not be used to train or fine-tune any AI system operated by a third country or a legal entity established in a third country.
3. Providers of European Business Wallets shall comply with the requirements set out in Article 19a of Regulation (EU) 910/2014. That obligation shall not apply to providers of European Business Wallets that are qualified trust service providers.
4. Providers of European Business Wallets shall comply with the applicable cybersecurity requirements laid down in Union and national law, including those relating to the identification of high-risk suppliers, as well as the requirements set out in Directive (EU) 2022/2555. Providers of European Business Wallets shall be considered part of the Union’s critical digital infrastructure pursuant to Directive (EU) 2022/2555 Annex 1 and may be identified as critical entities pursuant to Directive (EU) 2022/2557.
5. ▌Providers shall also ensure that their suppliers of software and security solutions as well as their cloud service providers that host European Business Wallets data comply with ▌ requirements laid down in Union and national law and conform to the relevant security standards and requirements.
6. Providers of European Business Wallets shall:
(a) implement appropriate technical and organisational measures to ensure the security, confidentiality, integrity, authenticity, interoperability, and availability of the European Business Wallets they provide with other European Business Wallets and European Digital Identity Wallets;
(b) ensure that European Business Wallet owners and their authorised representatives are clearly informed, in a user-friendly, concise and accessible manner, about the terms and conditions of use of the European Business Wallet, and of any change thereof, including the scope and limitations of core and additional functionalities, cybersecurity standards, and the European Business Wallet owner’s rights with regard to data portability, redress, and termination of service;
(c) ensure that authorised representatives of European Business Wallet owners and their authorised representatives are clearly informed, in a user-friendly, concise and accessible manner, about their rights and obligations in relation to their European Business Wallet unit, in particular, the right to request revocation of their wallet unit attestation, using the authentication mechanism provided in point 1 of the Annex;
(d) cooperate with the competent supervisory bodies referred to in Article 13(1), or with the Commission in the cases referred to in Article 13(10) and 15(1) and respond without undue delay to any request for information or documentation necessary to verify compliance with this Regulation;
(e) notify without undue delay the relevant national supervisory bodies, or the Commission in the cases referred to in Article 15(1), of any substantive changes to their services, including the intention to suspend or terminate services, or overall structure which may impact the compliance of the provider with this Regulation;
(f) notify without undue delay European Business Wallet owners in the event of suspension, revocation or voluntary termination of the services offered by the providers of European Business Wallet`s services and of the removal of the provider of European Business Wallet from the list established pursuant to Article 12(3) and ensure the transfer or deletion of the European Business Wallet owner data in accordance with the European Business Wallet owners instructions, including European Business Wallet owner identification data;
(g) ensure that the information on European Business Wallet owners, pursuant to Article 10(2), is notified to the Commission and that the information initially submitted to the Commission is kept up to date and corroborated by the providers of the European Business Wallet owner identification data issuing through the issuance of the unique identifiers referred to in Article 8(5), point (b).
(ga) ensure that their services are user friendly and accessible, taking into account diverse needs, including those of persons with disabilities, in accordance with Union law.
Article 8
European Business Wallet owner identification data
1. Providers of European Business Wallet owner identification data shall issue European Business Wallet owner identification data to European Business Wallets of European Business Wallet owners. Where European Business Wallet owners are Union entities, the Commission shall issue European Business Wallet owner identification data to the European Business Wallets of those Union entities.
2. Member States shall notify to the Commission the relevant authentic sources for the verification of the required attributes for the issuance of the European Business Wallet owner identification data. On the basis of the information received pursuant to this paragraph, the Commission shall make available on the Commission’s website, in a machine-readable format, a list of the notified relevant authentic sources.
3. European Business Wallet owner identification data shall be issued in a format compliant with one of the standards listed in Annex II of Commission Implementing Regulation (EU) 2024/2979 and as:
(a) qualified electronic attestations of attributes, when provided by qualified trust service providers;
(b) electronic attestations of attributes issued by or on behalf of a public sector body responsible for an authentic source▌
(c) electronic attestations of attributes, when provided by the Commission.
4. European Business Wallet owner identification data issued by the Commission shall have the same legal effect as qualified electronic attestations of attributes and attestations of attributes issued by, or on behalf of, a public sector body responsible for an authentic source.
5. European Business Wallet owner identification data shall contain at least the following attributes:
(a) the official name and contact details of the economic operator or public sector body, as recorded in the relevant register or official record;
(b) the relevant unique identifier attributed in accordance with Article 9.
6. The Commission shall establish and maintain an attestation scheme for European Business Wallet owner identification data. That scheme shall be listed in the catalogue of schemes for the attestation of attributes referred to in Article 8 of Implementing Regulation (EU) 2025/1569.
7. The Commission shall, by… [12 months from the date of entry into force of this Regulation] by means of implementing acts, set out harmonised requirements for European Business Wallet owner identification data issued pursuant to this Article, including procedures for Member States to notify to the Commission the relevant authentic sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.
Article 9
Unique identifiers
1. Where an economic operator has been attributed a European Unique Identifier, that identifier shall be used as the unique identifier referred to in Article 8(5), point (b) of this Regulation.
2. Where an economic operator or public sector body has not been attributed a European Unique Identifier, a unique identifier shall upon the request of the economic operator be created free of charge and without undue delay in accordance with the implementing act referred to in paragraph 4. Member States shall ensure that a competent national authority is designated for that purpose.
3. Where a public sector body is a Union entity, the Commission shall create and attribute a unique identifier to that Union entity in accordance with paragraph 4 of this Article.
4. The Commission shall, by … [12 months from the date of entry into force of this Regulation] by means of implementing acts, establish specifications, requirements and procedures relating to the unique identifier referred to in paragraph 2 of this Article, including measures to ensure that European Business Wallet owners are not attributed more than one unique identifier. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.
4a. The unique identifier framework established pursuant to this Article shall support the identification of subsidiaries, branches, establishments or other operational units of economic operators, where necessary for administrative procedures or digital transactions.
4b. Where relevant laws of the Member State concerned allow it, the unique identifier framework may enable natural persons engaged in economic activity to be associated with different identifiers corresponding to their distinct economic roles.
Article 10
European Digital Directory
1. The Commission shall establish, operate and maintain a European Digital Directory which shall act as the trusted source of information for European Business Wallet owners and shall take the form of a web application comprising of two easily accessible interfaces:
(a) a machine-readable interface exposed through an API for automated system-to-system communication;
(b) a secure, web-based platform that provides access to authenticated and authorised users via an online portal for European Business Wallet users.
2. For the purpose of maintaining the European Digital Directory, providers of European Business Wallets shall, upon the provision of a European Business Wallet, provide to the Commission the categories of information set out in the implementing act referred to in paragraph 6. The Commission shall ensure that the information is included in the European Digital Directory in a secure manner and in accordance with the relevant data protection principles.
3. The Commission shall ensure that the relevant information shall be included in the European Digital Directory.
4. The Commission shall make the European Digital Directory only accessible to European Business Wallet owners and their authorised representatives and providers of European Business Wallets and relevant Member State authorities.
5. Any modification or revocation concerning the information referred to in paragraph 2 shall, without undue delay and in any event within one working day, be communicated by the providers of European Business Wallet directly to the Commission for the purpose of maintaining the European Digital Directory.
6. The Commission shall, by … [12 months from the date of entry into force of this Regulation] by means of implementing acts, establish standards and technical specifications for the unique digital addresses and the categories of information to be communicated to the Commission for the purpose of the European Digital Directory. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.
Article 11
Notification of providers of European Business Wallets
1. Entities that intend to provide European Business Wallets shall notify that intention together with the information listed in paragraph 2 to the competent supervisory body.
2. The notification referred to in paragraph 1 shall include the following information:
(a) the entity’s legal name, any commercial names used, website URL, contact email, telephone number, and physical address;
(b) the entity’s register number issued by a national register, where available
(c) a description of how the core functionalities, set out in Article 5(1) shall be offered by the European Business Wallets the entity intends to provide;
(ca) proof of compliance with Article 7;
(d) a description of any additional functionalities supported by the European Business Wallets the entity intends to provide and a description of how they comply with the security-by-design technical requirement set out in Article 6(2), point (c);
(e) a declaration of conformity with the requirements of this Regulation.
The Commission shall issue guidance, where necessary, for the purposes of the first subparagraph, point (ca), specifying the information necessary for establishing proof of compliance.
▌
4. Upon receipt of a notification, the supervisory body shall have 30 calendar days to review the information submitted.
When that review leads the supervisory body to conclude that the information is complete and the relevant requirements of this Regulation are met, the supervisory body shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(3).
5. When that review leads the supervisory body to conclude that the information is not complete or the relevant requirements laid down in this Regulation are not met, it shall request additional information or explanations from the notifying entity and set a reasonable deadline, not exceeding 15 calendar days, for response. If that information or those explanations allow the supervisory body to conclude that the information is complete and that the relevant requirements laid down in in this Regulation are met, it shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(3). If not, or no response is received, the supervisory body shall inform the notifying entity that it will not be added to the list referred to in Article 12(3).
6. Where the supervisory body has not provided the notifying entity with a substantive response on the outcome of the review referred to in paragraph 4 within 30 calendar days of receiving the notification, the ▌ supervisory body shall inform the notifying entity of the reason for the delay and shall complete the review within an additional 15 calendar days. When that review leads to the conclusion by the supervisory body that all information is complete and the relevant requirements of this Regulation are met, the Commission within two working daysshall add that provider to the list referred to in Article 12(3)
7. Member States shall ensure that notifying entities have the right to an effective judicial remedy against a decision of the supervisory authority, without prejudice to any other administrative or non-judicial remedy, in cases where the supervisory authority refuses to list them as a provider of European Business Wallets or takes no decision within a reasonable timeframe.
Article 12
List of notified providers of European Business Wallets
1. Supervisory bodies shall inform the Commission of any changes to the information provided pursuant to Article 11, within 24 hours of having become aware of any changes.
2. The information provided by the supervisory bodies referred to in Article 11 and Article 12(1) shall include the following:
(a) the purpose of the submission, which may be one of the following:
– the registration of a notified provider of European Business Wallets not previously present on the list referred to in paragraph 3;
– a change to previously submitted information regarding providers of European Business Wallets currently present on the list referred to in paragraph 3;
– a request to remove a provider of European Business Wallets from the list referred to in paragraph 3;
(b) name and, where applicable, the commercial name of the provider of European Business Wallets;
(c) the Member State in which the provider of European Business Wallets has its principal place of establishment;
(d) the name of the competent supervisory body;
(e) an indication whether the provider of European Business Wallets is a qualified trust service provider complying with Article 7(2) of this Regulation.
3. On the basis of the information received pursuant to this Article, the Commission shall establish and maintain on the Commission’s website, in a machine-readable format, a list of providers of European Business Wallets. Based on the information received, the Commission shall add or revoke a provider and update the list within 24 hours of receiving the information.
Article 13
Governance and supervision
1. Member States shall ensure the effective governance and supervision of providers of European Business Wallets. Each Member State shall designate a supervisory body for the purposes of this Regulation.
1a. Member States shall notify to the Commission the names and the addresses of their supervisory body designated pursuant to paragraph 1 and any subsequent changes thereto. The Commission shall publish a list of the notified supervisory bodies.
2. Those supervisory bodies shall be responsible for supervisory tasks as regards providers of European Business Wallets having their principal place of establishment in that Member State.
3. Member States shall ensure that the supervisory bodies referred to in paragraph 1 have the necessary powers and adequate resources for the exercise of their tasks and for the enforcement of the obligations under this Regulation in an effective, efficient and independent manner.
4. The role of national supervisory bodies referred to in paragraph 1 shall be to:
(a) monitor compliance with the requirements laid down in this Regulation and take action, if necessary, in relation to providers of European Business Wallets ▌
(b) act as the main liaison office for providers of European Business Wallet owner identification data, facilitating access to information from relevant national authorities and registries, where necessary, for the issuance of European Business Wallet owner identification data and unique identifiers.
5. The tasks of the supervisory bodies referred to in paragraph 1 shall include the following:
(a) review and assess the notifications submitted in accordance with Article 11;
(b) set up a complaint mechanism whereby substantiated complaints can be filed, particularly those made by European Business Wallets owners, that a provider of European Business Wallets fails to comply with any of its obligations under this Regulation, investigate such complaints and to take action if necessary in a transparent manner and within a reasonable timeframe;
(c) verify the existence and correct application of termination plans where a provider of European Business Wallets ceases its activities, including how information is kept accessible and how data export is to be enabled in accordance with Article 5(1), point (l);
(d) ensure that providers of European Business Wallets remedy any failure to fulfil the requirements laid down in this Regulation;
(e) impose penalties in accordance with paragraphs 6 to 9;
(f) without undue delay, inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant incident of which it becomes aware in the performance of its tasks and, in the case of a significant incident which concerns other Member States, to without undue delay inform the single point of contact designated or established pursuant to Article 8(3) Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of Regulation (EU) No 910/2014 in the other Member States concerned, and to inform the public or require the provider of European Business Wallets to do so where the supervisory body determines that disclosure of the breach of security or loss of integrity would be in the public interest;
(g) cooperate with supervisory authorities established pursuant to Article 51 of Regulation (EU) 2016/679, in particular, by informing them, without undue delay, where personal data protection rules appear to have been breached and about security breaches which appear to constitute personal data breaches;
(h) cooperate, as appropriate, with other national supervisory bodies;
(i) set up and ensure clear publicity of a complaint mechanism whereby complaints can be filed by providers of European Business Wallets in accordance with Article 11(7);
(j) report regularly to the Commission on its main activities;
(k) request that the Commission revoke the inclusion in the list established pursuant to Article 12(3) of a provider of European Business Wallets if the supervisory body determines that the provider no longer meets the requirements laid down in this Regulation or that the provider has failed to comply with the obligations imposed by this Regulation;
(l) cooperate with the supervisory authorities designated pursuant to Article 46b of Regulation (EU) No 910/2014 by the Member States, in particular, to ensure that economic operators established outside the Union are issued only one set of European Business Wallet owner identification data and European business Wallet unique identifier.
6. Member States shall lay down the rules allowing the supervisory body referred to in paragraph 1 of this Article to impose penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented. Those penalties shall be effective, proportionate and dissuasive. Those rules shall not affect Article 31 of Directive (EU) 2022/2555 and Article 83 of Regulation (EU) 2016/679.
7. By [Publications Office, insert the date 12 months after the entry into force of this Regulation] Member States shall notify the Commission of the rules laid down by Member States in accordance with paragraph 6 and shall notify the Commission without undue delay of any subsequent amendments to the rules. The Commission shall regularly update and maintain an easily accessible public register of those rules.
8. Member States shall take into account the following non-exhaustive and indicative criteria for the imposition of penalties in accordance with paragraph 6:
(a) the nature, gravity, scale and duration of the infringement;
(b) any action taken by the infringing party to mitigate or remedy the damage caused by the infringement;
(c) any previous infringements by the infringing party;
(d) the financial benefits gained or losses avoided by the infringing party due to the infringement, insofar as such benefits or losses can be reliably established;
(e) any other aggravating or mitigating factor applicable to the circumstances of the case;
(f) the infringing party’s total annual turnover in the preceding financial year in the Union.
Member States shall ensure that infringements of this Regulation committed by providers of European Business Wallets be subject to administrative fines of a maximum of 2% of the total worldwide annual turnover in the preceding financial year.
9. Where the legal system of a Member State does not provide for administrative fines being imposed by administrative authorities, fines initiated by the supervisory body and imposed by competent national courts, which have an equivalent effect to the administrative fines imposed by supervisory bodies, shall be considered to comply with the requirements laid down in paragraph 6. In any event, the fines imposed shall be effective, proportionate and dissuasive. That Member State shall notify to the Commission the provisions of the laws which it adopts pursuant to this paragraph by [Publications Office, insert the date 12 months after the entry into force of this Regulation] and, without undue delay, any subsequent amendment law or amendment affecting them.
10. In circumstances which justify an immediate intervention to preserve the proper functioning of the internal market and where the Commission has sufficient reason supported by objective evidence to consider that the European Business Wallets provided by a provider are repeatedly non-compliant with the requirements laid down in this Regulation and no effective measures have been taken by the competent supervisory authority, the Commission shall carry out an evaluation of compliance. The Commission shall inform the relevant authorities accordingly and the provider shall cooperate as necessary.
11. Based on the evaluation, the Commission may decide that a corrective or restrictive measure is necessary, and after consulting the Member States concerned and the provider, the Commission may determine the appropriate course of action and shall provide appropriate justifications for the chosen action to the Member States and provider concerned. The Commission shall take into account the nature and severity of the non-compliance, as well as the potential impact on the internal market and the rights of economic operators.
12. On the basis of the consultation, the Commission may adopt implementing acts to provide for corrective or restrictive measures, including temporarily suspending the provider from the list of notified providers or requiring the provider to take specific actions to bring the European Business Wallets into compliance with the Regulation. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.
13. The Commission shall immediately communicate the implementing acts to the provider and Member States shall implement those implementing acts without delay and inform the Commission accordingly. These measures shall be applicable for the duration of the exceptional situation that justified the Commission’s intervention, provided that the European Business Wallets concerned are not brought into compliance with this Regulation.
Article 14
European Digital Identity Cooperation Group
The European Digital Identity Cooperation Group established pursuant to Article 46e of Regulation (EU) No 910/2014 shall be responsible for facilitating cooperation and information sharing among Member States and the Commission on matters related to the European Business Wallets. This shall include sharing best practices, discussing technical and operational issues, and coordinating efforts to ensure the proper implementation and functioning of the European Business Wallets.
Article 15
Governance and supervision of Union entities that provide European Business Wallets to other Union entities
1. Where a Union entity provides European Business Wallets to other Union entities the Commission shall be its supervisory body.
2. The role of the Commission acting as a supervisory body in accordance with paragraph 1 shall be to monitor compliance with the requirements laid down in this Regulation and take action, if necessary, in relation to providers of European Business Wallets, by means of ex post supervisory activities.
3. When acting as a supervisory body in accordance with paragraph 1, the Commission shall perform the tasks referred to in Article 13(5) points a, b, c, d, h and k.
The Commission shall submit a report to the European Parliament and the Council on its main activities in this respect.
Chapter III – Acceptance of the European Business Wallets
Article 16
Obligations on public sector bodies
1. By ▌ 24 months after the entry into force of the implementing acts referred to in Articles 5 and 6, public sector bodies shall enable economic operators to take the following actions by using the core functionalities of European Business Wallets as set out in Article 5(1):
(a) identify and authenticate;
(b) sign or seal;
(c) submit documents;
(d) send or receive notifications.
The actions listed in points (a) to (d) of the first subparagraph shall take place for the purpose of meeting a reporting obligation or fulfilling an administrative procedure.
1a. Member States shall provide support and solutions to smaller public sector bodies to ensure that they have the capacity to enable economic operators to take the actions listed in paragraph 1, and, where possible, shall ensure the availability of European Business Wallets for use by smaller public sector bodies.
2. For the purposes of paragraph 1, points (c) and (d), public sector bodies shall have European Business Wallets, including the qualified electronic registered delivery service referred to in Article 5(1), point (i). Public sector bodies may also make use of European Business Wallets for the purposes referred to in paragraph 1, points (a) and (b), of this Article.
3. By way of derogation from paragraph 2 and until ▌36 months after the date of entry into force of the implementing acts referred to in Articles 5 and 6, public sector bodies may choose not to offer the qualified electronic registered delivery service referred to in Article 5(1), point (i), and support instead other existing alternative solutions which enable economic operators to take the actions listed in paragraph 1, points (c) and (d), provided those solutions:
(a) comply with the requirements applicable to qualified electronic registered delivery services set out in Regulation (EU) No 910/2014;
(b) offer a gateway that enables European Business Wallet owners to submit documents and send and receive notifications using the qualified electronic registered delivery service referred to in Article 5(1), point (i).
After the expiry of the derogation period laid down in this paragraph, public sector bodies may continue to support the alternative solutions referred to in that subparagraph but shall, in accordance with paragraph 2, have European Business Wallets, including the qualified electronic registered delivery service referred to in paragraph 1 of Article 5(1), point (i).
Chapter IV - International aspects
Article 17
Business wallets and other similar instruments and frameworks offered in third countries
1. The Commission may adopt, for the purpose of cooperation and interoperability within B2B contexts, implementing acts establishing that business wallets or solutions offering similar functions that are issued by providers established in third countries are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that such business wallets or solutions offer an equivalent level of security and standards regarding authentication, data protection and data integrity to European Business Wallets, are supported by reliable trust frameworks, and are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.
2. The Commission may adopt, for the purpose of cooperation and interoperability within B2B contexts, implementing acts establishing that third country frameworks for systems offering similar functions as the European Business Wallets are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that the solutions provided under that framework offer an equivalent level of security and standards regarding authentication, data protection and data integrity to European Business Wallets, are supported by reliable trust frameworks and interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19.
2a. The equivalency decisions provided for in paragraphs 1 and 2 shall cover a period not exceeding three years. During that period, the Commission shall endeavour to negotiate a mutual recognition agreement with the third country. In the absence of such a mutual recognition agreement, the equivalency decisions referred to in paragraphs 1 and 2 may be renewed once for a further period of three years .
Neither the equivalency decisions nor the mutual recognition agreements referred to in the first subparagraph shall constitute recognition or authorisation of the provision of European Business Wallet services within the Union by third-country providers.t
3. Prior to the adoption of the implementing acts referred to in paragraphs 1 and 2 and the mutual recognition agreements provided for in paragraph 2a, the Commission shall carry out a thorough assessment of the third-country business wallets, solutions or frameworks, assessing in particular the equivalence of cybersecurity and data protection standards, and the independence of the providers or systems from the control of high-risk entities or third countries. Following the assessment, the Commission shall evaluate whether the assurances can be considered as equivalent to the requirements under this Regulation without constituting recognition or authorisation for the provision of European Business Wallet services within the Union.
4. The Commission shall after the adoption of the implementing acts referred to in paragraphs 1 and 2, monitor on an annual basis whether the third-country business wallets, solutions or frameworks continue to offer assurances that are equivalent. If a Member State identifies a risk regarding a third-country system that has been recognised as equivalent under paragraph 1 or 2, it shall without undue delay provide a report and refer the matter to the Commission. Where monitoring or other available information reveals that those assurances can no longer be considered as equivalent to the requirements under this Regulation, the Commission shall without undue delay and to the extent necessary, repeal, amend or suspend the act referred to in paragraphs 1 and 2 by means of an implementing act.
5. The Commission shall publish on its website a list of frameworks, business wallets or systems offering similar functions that are issued by providers established in third countries in relation to which the Commission has adopted an implementing act pursuant to this Article.
Article 18
Issuing of European Business Wallets to economic operators established outside the Union
1. Providers of European Business Wallets may provide European Business Wallets to economic operators established in a third country under the condition that such economic operators have been issued European Business Wallet owner identification data and a unique identifier in accordance with this Article.
2. For the purposes of this Article, economic operators shall request only one set of European Business Wallet owner identification data from one provider of European Business Wallet owner identification data.
3. Where an economic operator established outside the Union requests a European Business Wallet, the provider of European Business Wallets shall notify this request to the supervisory body of the Member State in which the provider is notified.
4. Providers of European Business Wallets shall request European Business Wallet owner identification data from a provider of European Business Wallet owner identification data on behalf of the economic operator established in a third country.
4a. Providers shall carry out appropriate customer due diligence prior to granting access to services or establishing a business relationship, including the identification and verification of the economic operator and its ultimate beneficial owners or entities exercising control over it, and verify whether the economic operator:
(a) is subject to Union restrictive measures in force;
(b) has been designated under Union or national regimes for money-laundering, terrorist financing or serious organised crime;
Where such risks are identified and cannot be effectively mitigated, the provider shall refuse to issue the European Business Wallet and shall inform the competent supervisory body.
5. Providers of European Business Wallet owner identification data may issue European Business Wallet owner identification data and unique identifiers without undue delay pursuant to Articles 8 and 9 to economic operators established outside the Union, provided that:
(a) the identity proofing and verification of those economic operators fulfils one or, when needed, a combination, of the methods for verification of identity set out in Article 24 (1a) of Regulation (EU) No 910/2014;
(b) the economic operator has not been issued another set of European Business Wallet owner identification data.
6. Member States shall cooperate to ensure that providers of European Business Wallet owner identification data can verify that an economic operator established outside the Union has not yet been issued European Business Wallet owner identification data.
6a. The Commission shall establish a list of reference standards and, where necessary, establish technical specifications for issuing European Business Wallet owner identification data, including unique identifiers, to economic operators established outside the Union as part of the implementing acts referred to in Articles 8(9) and 9(4).
Chapter V – Final provisions
Article 19
Committee procedure
The Commission shall be assisted by the committee established by Article 48 of Regulation (EU) No 910/2014. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.
Article 20
Amendment to Regulation (EU) No 910/2014
In Regulation (EU) No 910/2014, Article 5a is amended as follows:
(1) paragraph 1 is replaced by the following:
‘1. For the purpose of ensuring that all natural persons in the Union have secure, trusted and seamless cross-border access to public and private services, while having full control over their data, each Member State shall provide at least one European Digital Identity Wallet within 24 months of the date of entry into force of the implementing acts referred to in paragraph 23 of this Article and in Article 5c(6).’
(2) in paragraph 5 point (f) is replaced by the following:
‘(f) ensure that the person identification data, which is available from the electronic identification scheme under which the European Digital Identity Wallet is provided, uniquely represents the natural person or the natural person representing the natural or legal person, and is associated with that European Digital Identity Wallet;’;
(3) in paragraph 9 point c) is replaced by the following:
‘(c) upon the death of the user.’;
(4) Paragraph 15 is replaced by the following:
’15. The use of European Digital Identity Wallets shall be voluntary. Access to public and private services, access to the labour market and freedom to conduct business shall not in any way be restricted or made disadvantageous to natural persons that do not use European Digital Identity Wallets. It shall remain possible to access public and private services by other existing identification and authentication means.’.
Article 21
Evaluation and review
1. The Commission shall review the application of this Regulation and shall, by [Publications Office, insert the date – 3 years after entry into force], submit a report to the European Parliament and to the Council. The report shall evaluate the effectiveness of the provisions of this Regulation with regard to facilitating the submission of electronic documents and electronic attestations to public sector bodies, the overall uptake and usage of the European Business Wallets within B2G and B2B interactions, as well as technological, market, and legal developments. The report shall assess whether this Regulation has generated direct savings, in particular for small and medium-sized enterprises and smaller public sector bodies, as well as indirect benefits for the wider Union economy and society. The report shall also assess whether it is necessary to modify the scope of this Regulation or its specific provisions to set out an obligation for the use of the European Business Wallets to address the risks of legal fragmentation. In particular, the Commission shall assess whether new core functionalities should be added to the Business Wallets, such as enabling payments.
2. The report referred to in paragraph 1 shall include at least the following aspects:
(a) the minimum core functionalities of European Business Wallets;
(b) the level of compliance of providers of European Business Wallets and the notification procedure and criteria established in Article 11;
(c) the application and functioning of the rules on penalties laid down by the Member States pursuant to Article 13;
(d) the detailed requirements and technical specifications for the qualified electronic registered delivery service referred to in Article 5(1) point I;
(da) the adoption rate of European Business Wallets by economic operators and public sector bodies, disaggregated by size category and sector where relevant, and relevant metrics on the use of European Business Wallets;
(db) the financial or administrative impacts on economic operators, specifically small and medium-sized enterprises, including micro enterprises and start-ups, sole traders and self-employed persons;
(dc) the financial or administrative impacts on smaller public sector bodies;
(dd) the assessment of indirect benefits for the wider Union economy and society, including, fraud reduction and environmental sustainability;
(de) the evaluation of the cross-border interoperability of the Business Wallets and interoperability with existing digital solutions at both Union and Member State level, including identifying any duplication or parallel systems;
(df) the effectiveness of cooperation between supervisory bodies in the Member States and with the Commission in the implementation and supervision of this Regulation.
No later than one year before the report referred to in paragraph 1 is due, Member States shall provide the Commission with the information necessary for the preparation of the reports.
Article 22
Entry into force and application
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
It shall apply from [Publications Office, insert the date – 1 year after entry into force].
However, Article 20 shall apply from … [the day of entry into force of this Regulation].
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels,
For the European Parliament For the Council
The President The President
ANNEX
Requirements for minimum functionalities and technical requirements of European Business Wallets
1. European Business Wallets Unit Authentication
Access to the European Business Wallets Unit shall be granted only after the European Business Wallets user has been successfully authenticated by means of either:
(1) a notified electronic identification (eID) means in accordance with Article 6 of Regulation (EU) No 910/2014, fulfilling at least the requirements for a substantial level of assurance as defined in Article 8 of that Regulation and further specified in Commission Implementing Regulation (EU) 2015/1502; or
(2) an alternative authentication mechanism recognised as equivalent and fulfilling at least the requirements for a substantial level of assurance as defined in Article 8 of Regulation (EU) No 910/2014 and further specified in Commission Implementing Regulation (EU) 2015/1502.
Until such authentication has been completed, no functionality of the European Business Wallets Unit or of any other functionalities shall be made accessible to the Wallets user.
2. European Business Wallets Unit integrity
Providers of European Business Wallets shall, for each European Business Wallet unit, generate and sign a European Business Wallet unit attestation in accordance with the requirements laid down in point 5. The certificate used to sign or seal the Business Wallet unit attestation shall be issued under a certificate listed in the trusted list referred to in Commission Implementing Regulation (EU) 2024/2980.
3. European Business Wallets secure communication and critical asset management
(1) European Business Wallet back-end shall use at least one Wallet secure cryptographic application and Wallets secure cryptographic device to manage critical assets.
(2) Providers of the European Business Wallets shall ensure integrity, authenticity and confidentiality of the communication within and among all Business Wallet’s back-end, front-end and secure cryptographic applications and device.
(3) Where critical assets relate to performing electronic identification at assurance level substantial, the European Business Wallets cryptographic operations or other operations processing critical assets shall be performed in accordance with the requirements for the characteristics and design of electronic identification means at assurance level substantial, as set out in Commission Implementing Regulation (EU) 2015/1502.
4. Wallets secure cryptographic applications
(1) Providers of European Business Wallets shall ensure that European Business Wallets secure cryptographic applications and devices:
(a) perform the wallet’s cryptographic operations involving critical assets other than those needed for the Wallets unit to authenticate the Wallets owner only in cases where those applications have successfully authenticated Wallets users;
(b) where they authenticate the European Business Wallet owner in the context of performing electronic identification at assurance level substantial as set out in Implementing Regulation (EU) 2015/1502;
(c) are able to securely generate new cryptographic keys;
(d) are able to perform secure erasure of critical assets;
(e) are able to generate a proof of possession of private keys;
(f) protect the private keys generated by these Wallets secure cryptographic applications and devices during the existence of the keys;
(g) comply with the requirements for the characteristics and design of electronic identification means at assurance level substantial, as set out in Implementing Regulation (EU) 2015/1502.
5. Wallets unit authenticity and validity
(1) Providers of European Business Wallets shall ensure that the European Business Wallets unit attestations referred to in point 1 contain public keys and that the corresponding private keys are protected by a Wallets secure cryptographic device.
(2) Providers of European Business Wallets shall provide mechanisms, independent of Wallets units, for the secure identification and authentication of Wallets users.
6. Revocation of Wallets unit attestations
(1) Providers of European Business Wallets shall establish a publicly available policy specifying the conditions and the timeframe for the revocation of Wallets unit attestations.
(2) In line with Article 6, where the providers of European Business Wallets revoke European Business Wallets unit attestations, they shall inform the affected European Business Wallets users without undue delay and no later than 24 hours from the revocation of their European Business Wallets units, including the reason for the revocation and the consequences for the European Business Wallets user. This information shall be provided in a manner that is concise, easily accessible and using clear and plain language.
(3) Where European Business Wallets providers have revoked a European Business Wallet’s unit attestation, they shall make publicly available the validity status of the European Business Wallet unit attestation and describe the location of that information in the Business Wallet’s unit attestation.
7. Transaction logs
(1) The providers of European Business Wallets shall implement and document an appropriate logging policy that shall include, at a minimum, electronic signing, electronic sealing, and notifications of all transactions with Business-Wallet-relying parties, other European Business Wallets units, and European Digital Identity Wallets units, irrespective of whether the transaction is successfully completed.
(2) The logged information shall at least contain:
(a) the time and date of the transaction;
(b) the name, contact details, and unique identifier of the corresponding Business-Wallet-relying party and the Member State in which that Business-Wallet-relying party is established, or in case of other Wallets units, relevant information from the Wallets unit attestation;
(c) the type or types of data requested and presented in the transaction;
(d) in the case of non-completed transactions, the reason for such non-completion.
(3) Providers of European Business Wallets shall ensure integrity, authenticity and confidentiality of the logged information.
(4) European Business Wallets back-end shall log reports sent by the Wallets user to the competent authorities via the Wallets unit, including interactions related to notifications, regulatory compliance, data sharing, or audit requests.
(5) The logs referred to in subpoints 1 and 2 shall be accessible to the European Business Wallets provider, where it is necessary for the provision of Wallets services.
(6) The logs referred to in subpoints 1 and 2 shall remain accessible for as long as required to be accessible by Union law or national law.
8. Qualified electronic signatures and seals
(1) In line with Article 6, providers of European Business Wallets shall ensure that Wallets users are able to receive qualified certificates for qualified electronic signatures or seals which are linked to qualified signature or seal creation devices that are either local, external, or remote in relation to the Wallet’s unit.
(2) Providers of European Business Wallets shall ensure that European Business Wallets solutions can securely interface with one of the following types of qualified signature or seal creation devices: local, external, or remotely managed qualified signature or seal creation devices for the purposes of using the qualified certificates referred to in subpoint 1.
9. Signature creation applications
(1) The signature creation applications used by European Business Wallets units may be provided either by European Business Wallets providers, by providers of trust services or by Business-Wallet-relying parties.
(2) Signature creation applications shall have the following functions:
(a) signing or sealing data provided by European Business Wallets users;
(b) signing or sealing data provided by relying parties;
(c) creating signatures or seals in accordance with at least the mandatory format;
creating signatures or seals in accordance with the optional format;
– informing Wallets users about the result of the signature or seal creation process.
To ensure uniform conditions for the implementation of this Regulation, the Commission is empowered to adopt implementing acts in accordance with Article 6 that specify the technical standards referred to in subpoint 2, letters (c) and (c)(ii).
(3) The signature creation applications may either be integrated into or be external to European Business Wallets back-end. Where signature creation applications rely on remote qualified signature creation devices and where they are integrated into European Business Wallets back-end, they shall support the application programming interface set out in the implementing acts, which the Commission is empowered to adopt in accordance with Article 5 in order to ensure uniform conditions for the implementation of this Regulation.
10. Data export and portability
Business Wallets shall support the secure export, import and portability of an owner’s European Business Wallet data in at least an open format. This shall enable the owner to migrate their data to another Business Wallets solution while ensuring a level of assurance of at least "substantial", as defined in Implementing Regulation (EU) 2015/1502.
11. Secure Legal Communication Channel for the Business Wallet
(1) In line with Article 5 of this Regulation, Business Wallets shall integrate and support the use of ▌ qualified electronic registered delivery services, which comply with the technical and interoperability requirements established pursuant to subpoint 2, in accordance with Articles 43 and 44 of Regulation (EU) No 910/2014.
(2) The Commission shall, by means of implementing acts:
(a) establish a common set of technical and operational requirements, including a standardised interface, for qualified electronic registered delivery services to be used as asecure legal communication channel for European Business Wallets;
(b) define the minimum technical and interoperability requirements that such qualified electronic registered delivery services must fulfil, including alignment with the reference standards, specifications and procedures established under Articles 43 and 44 of Regulation (EU) No 910/2014;
(c) ensure that the ▌qualified electronic registered delivery services referred to in subpoint 1 are based on open, publicly available and royalty-free standards to guarantee interoperability and prevent vendor lock-in;
(d) ensure that the ▌ qualified electronic registered delivery servicesreferred to in subpoint 1 are end-to-end encryption to guarantee confidentiality;
(e) ensure that the designated qualified electronic registered delivery services shall establish adequate procedures for ensuring continuous availability, redundancy and fallback mechanisms in case of service failure.
(3) Interoperability between Business Wallets and the ▌ qualified electronic registered delivery services referred to in subpoint 1 shall be mandatory. Providers of Business Wallets shall ensure technical integration in accordance with the implementing acts referred to in subpoint 2.
12. European Business Wallets Access Control Mechanism
(1) Providers of European Business Wallets shall ensure that authorisation decisions under the access control mechanism are based on one or more of the following criteria, as appropriate to the specific access request:
(a) the electronic attestation of attributes of the acting subject;
(b) the formal role of the acting subjects within a recognised organisational structure or economic operator;
(c) the scope, validity and constraints of any mandate, delegation, or power of attorney;
(d) contextual information or policies and rules adopted at Union or national level for sector-specific compliance.
(2) Providers of European Business Wallets shall ensure the access control mechanism enables fine-grained and auditable authorisation outcomes, ensuring that:
(a) visibility of credentials and attestations is selective and conditioned on access rights;
(b) access to business processes, digital procedures or submission interfaces is controlled by real-time validation of roles and mandates;
(c) all access and execution events are logged, timestamped, and bound to cryptographically verifiable proofs of authorisation, suitable for audit and legal proceedings.
(3) Providers of the European Business Wallets shall ensure that:
(a) mappings between roles and attributes are verifiable, auditable, revocable and traceable to their legitimate issuers;
(b) conflicts of roles, over-delegation, or expired authorisations are automatically detected and prevented in real time;
(c) all authorisation logic is interoperable between European Business Wallets across Member States.
(4) The list of reference standards, technical specifications and procedures to be applied for the implementation of the access control mechanism shall be defined in the implementing acts, which the Commission is empowered to adopt in accordance with Article 5 in order to ensure uniform conditions for the implementation of this Regulation. These shall cover in particular:
(a) the formats for the representation of roles and attributes;
(b) interoperability mechanisms for mandates and delegations across wallets;
(c) protocols, policy language and constraint enforcement;
(d) requirements for secure logging, timestamping and auditability of authorisation events.
(5) Compliance with the requirements laid down in this Article shall be presumed where the standards, specifications and procedures referred to in subpoint 1 are met.
13. General provisions for protocols and interfaces
In line with Article 6 of this Regulation, providers of European Business Wallets shall ensure that European Business Wallets units:
(1) authorise requests and, where applicable, authenticate those made through relying-party access certificates or Wallet unit attestations. Authentication of the relying party shall be required where attestations are intended for a restricted audience; in all other cases, attestations may be presented by any requesting party;
(2) display to Wallet users’ information contained in the Business-Wallet-relying party access certificates or in the Wallets unit attestations where applicable;
(3) display to Wallets users, where applicable, the attributes that Wallets users are requested to present;
(4) present Wallet unit attestations of the Wallet unit to Business-Wallet-relying parties or Wallets units that request it.
14. Issuance of electronic attestations of attributes to Wallets units
(1) In line with Article 5 of this Regulation, providers of European Business Wallets shall ensure that Business Wallet units requesting issuance of, electronic attestations of attributes are able to authenticate relying parties.
(2) In relation to the issuance of electronic attestations of attributes to a Wallet unit, Wallet providers shall ensure that the following requirements are complied with:
(a) where European Business Wallets owners, through their Business Wallet unit, request from the provider of the European Business Wallet the issuance of Business Wallets owner identification data or of electronic attestations of attributes from providers of Business Wallets owner identification data or providers of electronic attestations of attributes that enable issuance of Business Wallets owner identification data or electronic attestations in more than one format, the Wallets unit shall request it in all formats referred to in Article 8 to this Regulation laying down rules for the application of the Business Wallets Regulation as regards the integrity and core functionalities of Business Wallets;
(b) where Business Wallet owners use their Business Wallets unit to interact with competent national authorities and providers of electronic attestations of attributes, Wallet units shall enable authentication and validation of the Wallet unit components by presenting the Wallet unit attestations to those competent national authorities and providers upon their request;
(c) Wallet solutions shall support mechanisms that enable providers of Business Wallets Owner Identification Data to verify issuance, delivery and activation in compliance with assurance level high requirements set out in Commission Implementing Regulation (EU) 2015/1502 (2.2);
(d) Wallet units shall verify the authenticity and validity of Business Wallets owner identification data and electronic attestations of attributes.
15. Presentation of attributes to European Business Wallet relying parties
In line with point (d) and (k) of paragraph 1 of Article 5, European Business Wallet providers shall ensure that:
(1) European Business Wallet solutions support protocols and interfaces for the presentation of attributes to Business-Wallet-relying parties in accordance with the standards defined in the implementing acts;
(2) At the request of users, European Business Wallet units respond to successfully authenticated and validated requests from Business-Wallet-relying parties in accordance with the standards defined in the implementing acts;
(3) European Business Wallet units support proving the possession of private keys corresponding to public keys used in cryptographic bindings.
16. Issuance of European Business Wallet Owner Identification Data to Wallets units
(1) Competent authorities shall ensure that Business Wallets owner identification data issued to Business Wallets units comply with the technical specifications set out in the implementing acts, in line with Article 8 of this Regulation.
(2) Competent national authorities shall ensure that Business Wallets owner identification data that they issue is cryptographically bound to the Wallets unit to which it is issued.
17. Issuance of electronic attestations of attributes to Wallets units
(1) Electronic attestations of attributes issued to European Business Wallets units shall comply with at least one of the standards in the list set out in the implementing acts, in line with Article 5 of this Regulation.
(2) Providers of electronic attestations of attributes shall identify themselves to European Business Wallets units using their wallet-relying party access certificate.
(3) Providers of electronic attestations of attributes shall ensure that electronic attestations of attributes issued to European Business Wallets units contain the information necessary for authentication and validation of those electronic attestations of attributes.
Annex: declaration of input 5 paragraphs
Pursuant to Article 8 of Annex I to the Rules of Procedure, the rapporteur declares that he included in his report input on matters pertaining to the subject of the file that he received, in the preparation of the report, prior to the adoption thereof in committee, from the following interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from the following representatives of public authorities of third countries, including their diplomatic missions and embassies:
| 1. Interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register |
| Bundesnotarkammer K.d.ö.R. - Transparency register: 74591581960-65 |
| DATEV eG. - Transparency register: 5027241291-41 |
| DIGITALEUROPE - Transparency register: 64270747023-20 64270747023-20 64270747023-20 |
| Docusign INC - Transparency register: 114101993563-51 114101993563-51 |
| EDPIA - Transparency register: 704370938610-77 |
| Confederation of Finnish Industries EK - Transparency register: 1274604847-34 |
| Consejo General de Colegios de Gestores Administrativos de España - Transp. Reg 678366044152-83 |
| Federation of German Industries (BDI) - Transparency register number 1771817758-48 |
| GLEIF - Transparency register: 660337819709-62 |
| MEDEF - Transparency register: 43763731235-75 |
| Namirial S.p.A. - Transparency register: 634705549512-92 |
| Service Sector Employers Palta - Transparency register: 412537550377-31 |
| Sage Group - Transparency register: 086894649381-50 |
| SMEunited aisbl - Transparency register: 55820581197-35 |
| Federation of Finnish Enterprises - Transparency register: 032592932156-20 - Transparency register: |
| Bundesverband Kooperierender Mittelstand - Transparency register: 196997510883-76 |
| Uria Menendez Abogados - 3516467105640-79 |
| Tinexta InfoCert - 686002336313-34 |
| European Startup Network - 568027349084-26 |
| Allied For Startups - 634665118544-37 |
| 2. Representatives of public authorities of third countries, including their diplomatic missions and embassies |
The list above is drawn up under the exclusive responsibility of the rapporteur.
Where natural persons are identified in the list by their name, by their function or by both, the rapporteur declares that he has submitted to the natural persons concerned the European Parliament’s Data Protection Notice No 484 (https://www.europarl.europa.eu/data-protect/index.do), which sets out the conditions applicable to the processing of their personal data and the rights linked to that processing.
4.6.2026
Opinion of the committee on the internal market and consumer protection 347 paragraphs
for the Committee on Industry, Research and Energy
on the proposal for a regulation of the European Parliament and of the Council on the establishment of European Business Wallets
(COM(2025)0838 – C100305/2025 – 2025/0358(COD))
Rapporteur for opinion: Veronika Cifrová Ostrihoňová
AMENDMENT
The Committee on the Internal Market and Consumer Protection submits the following to the Committee on Industry, Research and Energy, as the committee responsible:
Amendment 1
Proposal for a regulation
Recital 3
| Text proposed by the Commission | Amendment |
|---|---|
| (3) In order to foster a competitive and digital European economy, and to facilitate cross-border business, it is necessary to establish a seamless and secure environment for digital interaction between economic operators and public sector bodies in different configurations. | (3) In order to foster a competitive, resilient and digital European economy, reduce administrative burden, in particular for small and medium sized economic operators, and to facilitate cross-border business, it is necessary to establish a seamless and secure environment for digital interaction between economic operators and between those and public sector bodies in different configurations. |
Amendment 2
Proposal for a regulation
Recital 4
| Text proposed by the Commission | Amendment |
|---|---|
| (4) In order to ensure the interoperability and security of European Business Wallets, the technical specifications established in Regulation (EU) No 910/2014 and subsequent implementing regulations established pursuant to that Regulation as well as the technology and standards developments and the work carried out on the basis of Recommendation (EU) 2021/946, and in particular the Architecture and Reference Framework, should apply, with the specifications laid down in this Regulation taking precedence in the event of any inconsistency. | (4) In order to ensure a high degree of interoperability, security and technological neutrality of European Business Wallets, the technical specifications established in Regulation (EU) No 910/2014 and subsequent implementing regulations established pursuant to that Regulation as well as relevant technological developments, open standards, where appropriate, and the work carried out on the basis of Recommendation (EU) 2021/946, and in particular the Architecture and Reference Framework, should apply. The development of European Business Wallets should be based on interoperable and, where appropriate, open standards, ensuring compatibility across systems and Member States. A common European architecture and strong governance at Union level should be ensured, including alignment with the European Digital Identity Framework, in order to guarantee consistency, avoid fragmentation and support the effective functioning of the internal market. The specifications laid down in this Regulation taking precedence in the event of any inconsistency. |
Amendment 3
Proposal for a regulation
Recital 5
| Text proposed by the Commission | Amendment |
|---|---|
| (5) In order to enhance the functioning of the digital single market, ensure interoperability and reduce administrative burdens, it is essential to ensure compatibility between and European Business Wallets and existing systems and solutions at both Union and national level. As prescribed by the Interoperable Europe Act and to enhance secure and efficient data exchanges across the Union, the implementation of the European Business Wallets should, to the extent possible, where appropriate and following technical analysis, make use of existing EU digital infrastructures and building blocks, including those developed under the Once Only Technical System, the Business Registers Interconnection System and the European Digital Identity Wallet, thereby ensuring complementarity, interoperability, and efficient use of public resources. | (5) In order to enhance the functioning of the digital single market, facilitate innovation, ensure interoperability and reduce unnecessary administrative burdens for businesses and public bodies, it is essential to ensure compatibility between the various European Business Wallets as well as between the European Business Wallets and existing systems and solutions at both Union and national level. As prescribed by the Interoperable Europe Act and to enhance secure and efficient data exchanges across the Union, the implementation of the European Business Wallets should, to the extent possible, where appropriate and following technical analysis, make use of existing EU digital infrastructures and building blocks, including those developed under the Once Only Technical System, the Business Registers Interconnection System and the European Digital Identity Wallet, thereby ensuring complementarity, interoperability, and efficient use of public resources. |
Amendment 4
Proposal for a regulation
Recital 5 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (5a) In order to ensure digital sovereignty, operational autonomy of European Business Wallets and a high level of security and protection of data, Business Wallets should be hosted, to the extent technically feasible and where appropriate, on cloud infrastructure that is established and operated in the Union in line with applicable Union law on cloud services. This should enable providers to offer secure and trustworthy services and should protect data of European Business Wallet owners in accordance with EU standards and regulations. To that end, providers should, where appropriate, ensure that data is stored and processed within the Union, in particular where this is necessary to safeguard the security, confidentiality and integrity of the system. In all cases, data processing should comply with Union law and should not undermine effective jurisdiction, supervision and enforcement within the Union's internal market. |
Amendment 5
Proposal for a regulation
Recital 6
| Text proposed by the Commission | Amendment |
|---|---|
| (6) The European Business Wallets are a digital tool for economic operators to interact with public sector bodies in the context of meeting reporting obligations and fulfilling administrative procedures. The use of the core functionalities of the European Business Wallets to identify and authenticate, sign or seal, submit documents and send or receive notifications should be without prejudice to procedural requirements that might be part of an administrative procedure and that cannot be fulfilled by the core functionalities of the European Business Wallets. These procedural requirements may include any additional safeguards or verifications, such as checks to ensure the awareness or understanding of the contents of a document or the implications of the signature of a contract, or specific actions that are required as part of an administrative procedure and are not supported by the core functionalities of the European Business Wallets. Public sector bodies should therefore ensure that all relevant procedural requirements are met, including any specific actions or processes which need to be fulfilled as part of an administrative procedure and which cannot be performed through the European Business Wallets. | (6) The European Business Wallets are a digital tool for economic operators to interact securely with public sector bodies and other businesses in the context of meeting reporting obligations and fulfilling administrative procedures as well as promoting the reuse of robust and trusted functionalities in business-to-business operations. At the same time, it should be assured that the core functionalities of the European Business Wallets cannot be used to circumvent Union or Member State law that aims to protect the public interest. The use of the core functionalities of the European Business Wallets to identify and authenticate, sign or seal, request or share electronic attestations of attributes, submit documents and send or receive notifications should be without prejudice to procedural requirements that might be part of an administrative procedure and that cannot be fulfilled by the core functionalities of the European Business Wallets. These procedural requirements may include any additional safeguards or verifications, such as checks to ensure the awareness or understanding of the contents of a document or the implications of the signature of a contract, or specific actions that are required as part of an administrative procedure and are not supported by the core functionalities of the European Business Wallets. Public sector bodies should therefore ensure that all relevant procedural requirements are met, including any specific actions or processes which need to be fulfilled as part of an administrative procedure and which cannot be performed through the European Business Wallets. |
Amendment 6
Proposal for a regulation
Recital 7
| Text proposed by the Commission | Amendment |
|---|---|
| (7) Public sector bodies have the flexibility to decide how to ensure that they can accept European Business Wallets considering the diversity of their IT infrastructure and their needs for interoperability. This approach allows public sector bodies to maintain their existing operational frameworks, while benefiting from the advantages of the European Business Wallets. | (7) Public sector bodies have the flexibility to decide how to ensure that they can accept European Business Wallets considering the diversity of their IT infrastructure and their needs for interoperability. This approach allows public sector bodies to maintain their existing operational frameworks, while benefiting from the advantages of the European Business Wallets. The exercise of that flexibility should respect the principle of proportionality and should not create unnecessary technical or administrative burden, notably on micro-enterprises and small and medium-sized enterprises. |
Amendment 7
Proposal for a regulation
Recital 7 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (7a) The European Digital Identity Cooperation Group should support the implementation of the European Business Wallets, facilitate cross-border interoperability of digital wallets, and facilitate the progressive alignment of existing solutions with the European Business Wallets framework, while avoiding unnecessary transition costs or duplication of infrastructures. |
Amendment 8
Proposal for a regulation
Recital 9 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (9a) In order to support consistent implementation and prevent misuse, the Commission should provide Member States and economic operators, especially SMEs, with clear guidance, technical assistance and user education resources. The Commission, in cooperation with Member States, should promote a common understanding of key concepts and ensure the consistent use of terminology across the Union, thereby facilitating the proper functioning of the internal market, including with regard to the identification of legal entities and the attributes associated with them. |
Amendment 9
Proposal for a regulation
Recital 10 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (10a) The early and effective use of European Business Wallets by public authorities can encourage economic operators, including SMEs, sole traders and self-employed persons, to adopt and use those wallets in their interactions with public authorities and with other economic operators, thereby contributing to the effective functioning of the internal market and reducing administrative burden. |
Amendment 10
Proposal for a regulation
Recital 11
| Text proposed by the Commission | Amendment |
|---|---|
| (11) In order to reduce administrative burden and improve competitiveness, all entities conducting economic activities, including companies, organisations, self-employed persons, sole traders and any other type of business, regardless of size, sector or legal form, should be able to use European Business Wallets. To ensure that legally valid notifications, and documents can be exchanged, and reporting obligations fulfilled by means of European Business Wallets, it is necessary to establish a reliable and secure communication channel that can be used by European Business Wallet owners across the Union. A qualified electronic registered delivery service (‘QERDS’) should therefore be integrated as a secure communication channel in the European Business Wallets, and should enable the secure and legally valid exchange of information between parties, as provided for in Article 43 of Regulation (EU) No 910/2014. | (11) In order to reduce unnecessary administrative burden and improve competitiveness, all entities conducting economic activities, including companies, organisations, self-employed persons, sole traders and any other type of business, regardless of size, sector or legal form, should be able to use European Business Wallets. To ensure that legally valid notifications, and documents can be exchanged, and reporting obligations fulfilled by means of European Business Wallets, it is necessary to establish a reliable and secure communication channel that can be used by European Business Wallet owners across the Union. A qualified electronic registered delivery service (‘QERDS’) should therefore be integrated as a secure communication channel in the European Business Wallets, and should enable the secure and legally valid exchange of information between parties, as provided for in Article 43 of Regulation (EU) No 910/2014. |
Amendment 11
Proposal for a regulation
Recital 11 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (11a) In light of the role of European Business Wallets as part of the Union’s digital infrastructure, and in order to safeguard integrity, accountability and a high level of trust, while contributing to a competitive and resilient internal market, providers of qualified electronic registered delivery services (QERDS) that are integrated into European Business Wallets should be established within the Union and have their principal place of business and core operations therein. Such providers should ensure a high level of security of data stored or exchanged within the European Business Wallet ecosystem and should not present a risk to the security of the Union. In particular, they should not be directly or indirectly controlled by a third country or by a third-country entity. |
Amendment 12
Proposal for a regulation
Recital 12
| Text proposed by the Commission | Amendment |
|---|---|
| (12) In order to provide a tailored solution for self-employed persons and sole traders, it is essential to ensure the seamless integration of European Digital Identity Wallets with European Business Wallets. That integration should enable those persons to authenticate using their European Digital Identity Wallet and access trust services offered for the European Business Wallets, including the QERDS established as a secure communication channel in this Regulation, using those Wallets, without the need to create a separate business identity. Providers of European Business Wallets should therefore be allowed to offer the secure communication channel as a standalone service to self-employed persons and sole traders that use European Digital Identity Wallets in a business capacity, with ensured interoperability to facilitate app switching, as well as trust services such as electronic signatures and qualified and non-qualified time stamping services. Such access to the secure communication channel for self-employed persons and sole traders, should be promoted by ensuring an offer, at reasonable and affordable prices, that reflects the usage needs and is accompanied by terms of use that do not impose an undue burden on those persons. | (12) In order to provide a common solution specifically tailored to the needs of self-employed persons and sole traders, it is essential to ensure a common technical framework for European Digital Identity Wallets and European Business Wallets. That integration should enable those persons to authenticate using their European Digital Identity Wallet and access trust services offered for the European Business Wallets, allowing wallet providers to issue specialised or common solutions supported on European Digital Identity Wallets or European Business Wallets, including the QERDS established as a secure communication channel in this Regulation, using those Wallets, without the need to create a separate business identity. Providers of European Business Wallets should therefore be allowed to offer the secure communication channel as a standalone service to self-employed persons and sole traders that use European Digital Identity Wallets in a business capacity, with ensured interoperability to facilitate app switching, as well as trust services such as electronic signatures and qualified and non-qualified time stamping services. In order to ensure accessibility and uptake, such access to the secure communication channel for self-employed persons and sole traders, should be promoted by ensuring an offer, at reasonable and affordable prices, that reflects the usage needs and is accompanied by terms of use that do not impose unnecessary burden on those persons |
Amendment 13
Proposal for a regulation
Recital 13
| Text proposed by the Commission | Amendment |
|---|---|
| (13) The European Business Wallets, in combination with Regulation (EU) 2018/1724, should support the forthcoming 28th Regime(5 ) by providing the digital infrastructure for fully digital procedures, enabling start-ups and scale-ups to conduct EU-wide operations in a rapid and efficient manner. The Business Wallets should provide the digital infrastructure for the 28th Regime's digital-first strategy, streamlining cross-border interactions and reducing administrative burden, such as facilitating the secure storing and signature of contracts and certificates or submitting, receiving and sharing electronic applications and documents. By providing this infrastructure, the Business Wallets should help make the "digital by default" principle a reality, facilitating the growth and development of EU companies and enhancing their competitiveness. | (13) The European Business Wallets, in combination with Regulation (EU) 2018/1724, should support the forthcoming 28th Regime(5) by providing the digital infrastructure for fully digital procedures, enabling SMEs, start-ups and scale-ups to conduct EU-wide operations in a rapid and efficient manner. The Business Wallets should provide the digital infrastructure for the 28th Regime's digital-first strategy, streamlining cross-border interactions and reducing unnecessary administrative burden, such as facilitating the secure storing and signature of contracts and certificates or submitting, receiving and sharing electronic applications and documents. By providing this infrastructure, the Business Wallets should help make the "digital by default" principle a reality, facilitating the growth and development of EU companies and enhancing their competitiveness. . |
| 5 European Commission, Call for Evidence: 28th regime – a single harmonized set of rules for innovative companies throughout the EU, 8th of July, available at https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14674-28th-regime-a-single-harmonized-set-of-rules-for-innovative-companies-throughout-the-EU_en | 5 European Commission, Call for Evidence: 28th regime – a single harmonized set of rules for innovative companies throughout the EU, 8th of July, available at https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14674-28th-regime-a-single-harmonized-set-of-rules-for-innovative-companies-throughout-the-EU_en |
Amendment 14
Proposal for a regulation
Recital 13 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (13a) In order to maximise the benefits of administrative simplification and promote the uptake of European Business Wallets across the Union, particular attention should be given to the needs of SMEs, sole traders and self-employed persons. The use of European Business Wallets should not create unnecessary financial, administrative or other burdens for such economic operators compared to larger companies. European Business Wallets should therefore be accessible, affordable and easy to use. |
Amendment 15
Proposal for a regulation
Recital 13 b (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (13b) While promoting digital-by-default interactions, the transition towards a fully digital ecosystem should not create barriers to participation in the internal market, in particular for SMEs, start-ups, self-employed persons and other actors with limited resources or digital skills. Particular attention should be paid to accessibility requirements, including for persons with disabilities, in accordance with Union law. Measures should therefore ensure affordability, ease of use and proportionality, thereby supporting uptake and innovation. |
Amendment 16
Proposal for a regulation
Recital 13 c (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (13c) In order to ensure coherence with Union company law and reduce administrative burden in cross-border activities, European Business Wallets should facilitate interoperability with digital company-law tools established under Union law, in particular the EU Company Certificate and the digital EU power of attorney. |
Amendment 17
Proposal for a regulation
Recital 15
| Text proposed by the Commission | Amendment |
|---|---|
| (15) In order to ensure the proper issuance and integration of European Business Wallets throughout the operations and systems of Union entities, this Regulation should have due regard to the specific nature and structure of such institutions, bodies, offices and agencies. To ensure the respect of administrative autonomy and security of Union entities. They should be allowed to acquire European Business Wallets from already established providers of European Business Wallets, or develop their own European Business Wallets or act themselves as provider for Union entities. Where Union entities act as providers of European Business Wallets, they should also be subject to a supervisory framework. In such cases, the Commission should be tasked to the supervise the provision of European Business Wallets by Union entities. | (15) In order to ensure the proper issuance and integration of European Business Wallets throughout the operations and systems of Union entities, this Regulation should have due regard to the specific nature and structure of such institutions, bodies, offices and agencies. To ensure the respect of administrative autonomy and security of Union entities, they should be allowed to acquire European Business Wallets from already established providers of European Business Wallets, or develop their own European Business Wallets or act themselves as provider for Union entities. Where Union entities act as providers of European Business Wallets, they should also be subject to a supervisory framework. In such cases, the Commission should be tasked to supervise the provision of European Business Wallets by Union entities and ensure that there is no distortion of competition as regards commercial providers. |
Amendment 18
Proposal for a regulation
Recital 17
| Text proposed by the Commission | Amendment |
|---|---|
| (17) The European Business Wallets should allow individuals granted the power to act on behalf of an entity in legal, financial, and administrative matters to exercise their functions by signing any attestations, declarations, or documents executed through a legally valid electronic signature within the meaning of Regulation (EU) 910/2014, which establishes that electronic signatures shall have the equivalent legal effect of a handwritten signature. | (17) The European Business Wallets should allow individuals granted the power to act on behalf of an entity in legal, financial, and administrative matters to exercise their functions by signing any attestations, declarations, or documents executed through a legally valid electronic signature within the meaning of Regulation (EU) 910/2014, which establishes that qualified electronic signatures shall have the equivalent legal effect of a handwritten signature. |
Amendment 19
Proposal for a regulation
Recital 18
| Text proposed by the Commission | Amendment |
|---|---|
| (18) To support the delegation of powers and mandates within a professional context, the European Business Wallets should incorporate a mandate and role-based authorisation system that governs access to services and transactions within the European Business Wallet in such a way as to preserve the integrity of the identity of the owner of that Wallet. That system should enable economic operators and public sector bodies to assign rights to authorised representatives through clearly defined technical mandates allowing the owner of a specific European Business Wallet to grant full rights to generally use the solution and act on its behalf, and an administrative mandate, allowing the owner of a Business Wallet to assign roles and responsibilities to various users of the solution within their organisation. This authorisation system should ensure compatibility with the EU digital power of attorney, as established by Directive (EU) 2025/25 of the European Parliament and of the Council6 . This authorisation system should be robust and scalable, to ensure that economic operators and public sector bodies, as the owners of European Business Wallets, can delegate authority to multiple users, including employees or other authorised natural or legal persons, thereby facilitating the efficient and secure management of internal activities and ensuring that access to European Business Wallets and their functions is controlled and auditable. This system should govern access to services and transactions within the European Business Wallet, preserving the integrity of the owners' identities. | (18) To support the delegation of powers and mandates within a professional context, the European Business Wallets should incorporate a mandate, role-based and secure authorisation system that governs access to services and transactions within the European Business Wallet in such a way as to preserve the integrity and confidentiality of the identity of the owner of that Wallet. That system should enable economic operators and public sector bodies to assign rights to authorised representatives through clearly defined technical mandates allowing the owner of a specific European Business Wallet to grant full rights to generally use the solution and act on its behalf, and an administrative mandate, allowing the owner of a Business Wallet to assign roles and responsibilities to various users of the solution within their organisation. This authorisation system should allow the use of European Digital Identity Wallets, but should not require users to have them, as the use of European Digital Wallets remains voluntary. This authorisation system should ensure compatibility with the EU digital power of attorney, as established by Directive (EU) 2025/25 of the European Parliament and of the Council. This authorisation system should be robust, scalable and with seamless application, to ensure that economic operators and public sector bodies, as the owners of European Business Wallets, can delegate authority to multiple users, including employees or other authorised natural or legal persons, thereby facilitating the efficient and secure management of internal activities and ensuring that access to European Business Wallets and their functions is controlled and auditable. This Regulation should not prevent a natural or legal person from managing or operating multiple European Business Wallets on behalf of economic operators, public sector bodies, subsidiaries, affiliates, or other entities, where duly authorised to do so under applicable mandates or arrangements. This may include, for example, a business group structure in which a parent undertaking centrally manages or operates European Business Wallets on behalf of several subsidiary companies within the same corporate group. This system should govern access to services and transactions within the European Business Wallet, preserving the integrity of the owners' identities, while ensuring that only data which is strictly necessary for each specific transaction is processed and shared, in accordance with the principle of data minimisation, and that such systems remain simple and proportionate in their use. |
| 6 Directive (EU) 2025/25 of the European Parliament and of the Council of 19 December 2024 amending Directives 2009/102/EC and (EU) 2017/1132 as regards further expanding and upgrading the use of digital tools and processes in company law (OJ L, 2025/25, 10.1.2025, ELI: http://data.europa.eu/eli/dir/2025/25/oj). | 6 Directive (EU) 2025/25 of the European Parliament and of the Council of 19 December 2024 amending Directives 2009/102/EC and (EU) 2017/1132 as regards further expanding and upgrading the use of digital tools and processes in company law (OJ L, 2025/25, 10.1.2025, ELI: http://data.europa.eu/eli/dir/2025/25/oj). |
Amendment 20
Proposal for a regulation
Recital 19
| Text proposed by the Commission | Amendment |
|---|---|
| (19) In order to facilitate the conduct of cross-border business transactions, reduce administrative burdens, and promote economic growth, it is necessary to establish a clear and predictable legal framework that recognises the legal equivalence between the use of the European Business Wallets, or their core functionalities and the secure communication channel where the latter is used by self-employed persons and sole traders, and other accepted methods for economic operators to identify, authenticate, submit documents and receive notifications when interacting with public sector bodies in the Union. To that end, the use of the core functionalities of a European Business Wallet, or the secure communication channel where the latter is used by self-employed persons and sole traders, should have the same legal effect as if lawfully carried out in person, in paper form, or via any other means or process that would otherwise be deemed compliant with applicable legal, administrative, or procedural requirements. | (19) In order to facilitate the conduct of cross-border business transactions, reduce unnecessary administrative burdens, and promote sustainable economic growth, it is necessary to establish a clear and predictable legal framework that recognises the legal equivalence between the use of the European Business Wallets, or their core functionalities and the secure communication channel where the latter is used by self-employed persons and sole traders, and other accepted methods for economic operators to identify, authenticate, submit documents and receive notifications when interacting with public sector bodies in the Union. To that end, the use of the core functionalities of a European Business Wallet, or the secure communication channel where the latter is used by self-employed persons and sole traders, should have the same legal effect as if lawfully carried out in person, in paper form, or via any other means or process that would otherwise be deemed compliant with applicable legal, administrative, or procedural requirements. This should not prevent economic operators from continuing to use other legally valid means of carrying out such actions, where permitted under applicable law. |
Amendment 21
Proposal for a regulation
Recital 20
| Text proposed by the Commission | Amendment |
|---|---|
| (20) To ensure a consistent user experience and to guarantee the utility, reliability, and interoperability of European Business Wallets across the Union, providers of European Business Wallets should implement a core set of functionalities. They should retain the freedom to offer additional features as part of their commercial offering, fostering innovation and responding to market needs. In order to ensure uniform conditions for the development and use of the core functionalities, implementing powers should be conferred on the Commission to set out requirements and technical specifications necessary to ensure interoperability and seamless functioning across the Union. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council(7 ) and should include the powers to define the necessary standards and protocols for the secure communication channel, taking into account the latest technological developments. | (20) To ensure a consistent user experience and to guarantee the utility, reliability, and interoperability of European Business Wallets across the Union, providers of European Business Wallets should implement a core set of functionalities. As part of their commercial offering, fostering innovation and responding to market needs, those providers should retain the freedom to offer additional features which are compliant with the security requirements laid down in this Regulation. In order to ensure uniform conditions for the development and use of the core functionalities, implementing powers should be conferred on the Commission to set out requirements and technical specifications necessary to ensure security interoperability and seamless functioning across the Union. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council7 and should include the powers to define the necessary standards and protocols for the secure communication channel. When defining those requirements and technical specifications, the Commission should ensure that they remain technologically neutral, proportionate and adaptable to technological developments, including emerging technologies, and take relevant international standards and best practices into account. Those requirements and technical specifications should moreover not create unnecessary regulatory burdens or barriers to market entry, in particular for SMEs and smaller providers. |
| 7 Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by the Member States of the Commission's exercise of implementing powers (OJ L 55, 28.2.2011, p. 13, ELI: http://data.europa.eu/eli/reg/2011/182/oj). | 7 Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by the Member States of the Commission's exercise of implementing powers (OJ L 55, 28.2.2011, p. 13, ELI: http://data.europa.eu/eli/reg/2011/182/oj). |
Amendment 22
Proposal for a regulation
Recital 21
| Text proposed by the Commission | Amendment |
|---|---|
| (21) European Business Wallets should simplify the complex interactions between economic operators and public sector bodies, and could also facilitate interactions among economic operators themselves, reducing administrative burden on economic operators in a broad range of economic sectors. In order to foster innovation and competitiveness, the European Business Wallets should enable sector-specific use cases and enhance operational efficiencies, while ensuring flexibility and adaptability to support the unique requirements of different sectors, including, but not limited to, agriculture, energy, environment, social security coordination. | (21) European Business Wallets should simplify the complex interactions between economic operators and public sector bodies, and should also facilitate interactions among economic operators themselves, reducing administrative burden on economic operators in a broad range of economic sectors. In order to foster innovation and competitiveness, the European Business Wallets should enable sector-specific use cases and enhance operational efficiencies, while ensuring flexibility and adaptability to support the unique requirements of different sectors, including, but not limited to, agriculture, energy, environment, healthcare and social security coordination, with particular attention to sectors characterised by a high number of cross-border activities. |
Amendment 23
Proposal for a regulation
Recital 22
| Text proposed by the Commission | Amendment |
|---|---|
| (22) The use of the European Business Wallets in such contexts can aid in the reduction of costs and promote a wide range of applications and use cases across the Union, such as the submission of declarations, applications for public funding, access to public services and facilitating secure data sharing and access within data spaces, such as the submission of A1 certificates concerning posted workers provided for under Regulation (EU) 883/2004. | (22) The use of the European Business Wallets in such contexts can aid in the reduction of costs and promote a wide range of applications and use cases across the Union, such as Know Your Customer (KYC) and Know Your Business Partner (KYB) processes, public procurement, business permits, the submission of declarations, applications for public funding, access to public services and facilitating secure cross-border data sharing and access within data spaces, such as the submission of A1 certificates concerning posted workers provided for under Regulation (EU) 883/2004. |
Amendment 24
Proposal for a regulation
Recital 24
| Text proposed by the Commission | Amendment |
|---|---|
| (24) In order to ensure coordination between the Union’s ongoing digitalisation of judicial cooperation, the modernisation of secure cross-border information exchange, and the need to provide economic operators with efficient digital tools to interact with authorities, it is necessary to establish a coherent framework that enables smooth interaction between such relevant systems. Enhancing such coordination will reduce administrative burden, improve legal certainty, and strengthen the effectiveness of cross-border cooperation, by ensuring that communication channels used by economic operators function seamlessly within the European digital market. In that context, European Business Wallets should complement the systems set out in Regulation (EU) 2023/2844 and Regulation (EU) 2023/969, where a seamless interaction between these systems and the Business Wallets should be maintained through the Business Wallets gateway, enabling relevant authorities to maintain these systems whilst promoting simplification for European companies. | (24) In order to ensure coordination between the Union’s ongoing digitalisation of judicial cooperation, the modernisation of secure cross-border information exchange, and the need to provide economic operators with efficient digital tools to interact with authorities, it is necessary to establish a coherent framework that enables smooth interaction between such relevant systems. Enhancing such coordination will reduce administrative burden, improve legal certainty, and strengthen the effectiveness of cross-border cooperation, by ensuring that communication channels used by economic operators function seamlessly within the European digital market. In that context, European Business Wallets should complement the systems set out in Regulation (EU) 2023/2844 and Regulation (EU) 2023/969, where a seamless interaction between these systems and the Business Wallets should be maintained through the Business Wallets gateway, enabling relevant authorities to maintain these systems whilst promoting simplification for European companies, especially SMEs. |
Amendment 25
Proposal for a regulation
Recital 26
| Text proposed by the Commission | Amendment |
|---|---|
| (26) In order to ensure the secure and trustworthy operation of European Business Wallets, providers of European Business Wallets should ensure that each European Business Wallet they provide is pre-configured to interact with certain trust services, which are required to enable the core functionalities of European Business Wallets, including the creation of qualified electronic signatures, the creation of qualified electronic seals, and the issuance and validation of qualified and non-qualified electronic attestations of attributes. To support these functionalities, European Business Wallets should allow for the sharing and storage of specific information and documents relating to the owner, such as messages and documents for the secure communication channel, signed and sealed documents, and sets of attributes for attestation-related services. | (26) In order to ensure the secure and trustworthy operation of European Business Wallets, providers of European Business Wallets should ensure that each European Business Wallet they provide is pre-configured to interact with certain trust services that are optimised for the use by legal entities and are required to enable the core functionalities of European Business Wallets, including the creation of qualified electronic signatures, the creation of qualified electronic seals, and the issuance and validation of qualified and non-qualified electronic attestations of attributes. To support these functionalities, European Business Wallets should allow for the sharing, storage and verification of specific information and documents relating to the owner, such as messages and documents for the secure communication channel, signed and sealed documents, and sets of attributes for attestation-related services. |
Amendment 26
Proposal for a regulation
Recital 27 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (27a) In order to ensure a competitive market for European Business Wallet providers, enhance user choice and prevent vendor lock-in, European Business Wallet owners should be able to export their data, including identification data, electronic attestations of attributes, communication logs and interaction records, in a structured, commonly used and machine-readable format to another European Business Wallet. |
Amendment 27
Proposal for a regulation
Recital 28
| Text proposed by the Commission | Amendment |
|---|---|
| (28) In order to ensure that the standards and technical specifications for European Business Wallets ensure harmonisation across various solutions, it is necessary to define the standards and protocols for the core functionalities and technical requirements for European Business Wallets in an Annex to this Regulation. The Annex should set out the requirements for the implementation of European Business Wallets. To ensure the long-term viability and effectiveness of the European Business Wallets, implementing powers should be conferred on the Commission to establish and update the procedures and technical specifications on the implementation of core functionalities, thereby allowing for the integration of additional features and new technologies that would enable new use cases, such as agentic AI or the provision of a digital identity to an owner’s asset, and enabling the European Business Wallets to continue to support the evolving needs of economic operators in a secure and trustworthy manner. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council. To the extent possible, the standards and technical specifications of the European Business Wallet should take into account relevant technical solutions and standards used by existing ICT systems by economic operators, facilitating the alignment of these systems to be aligned to and made interoperable with the European Business Wallet. | (28) In order to ensure that the standards and technical specifications for European Business Wallets ensure interoperability across various solutions, it is necessary to define the standards and protocols for the core functionalities and technical requirements for European Business Wallets in an Annex to this Regulation. The Annex should set out the requirements for the implementation of European Business Wallets. To ensure the long-term viability and effectiveness of the European Business Wallets, implementing powers should be conferred on the Commission to establish and update the procedures and technical specifications on the implementation of core functionalities, thereby allowing for the integration of additional features and new technologies that would enable new use cases, such as agentic AI or the provision of a digital identity to an owner’s asset, and enabling the European Business Wallets to continue to support the evolving needs of economic operators in a secure and trustworthy manner. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council. To the extent possible, the standards and technical specifications of the European Business Wallet should take into account relevant technical solutions and standards used by existing ICT systems by economic operators, provided that those technical solutions and standards comply with the Union law and are compatible with the security requirements laid down in this Regulation, facilitating the alignment of these systems to be aligned to and made interoperable with the European Business Wallet. |
Amendment 28
Proposal for a regulation
Recital 31 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (31a) In order to safeguard the security and trustworthiness of the European Business Wallets ecosystem, and in light of its role in the Union’s digital infrastructure, providers of Qualified Electronic Registered Delivery Services (QERDS) and, to the extent technically feasible and where appropriate, their cloud service providers, should be established in the Union. Given that European Business Wallet services rely on cloud environments for the storage, processing and exchange of data, such requirements should help reducing exposure to the extraterritorial application of third-country laws that could undermine the confidentiality, integrity and availability of data, as well as control over data processed within the ecosystem. Cloud providers should therefore ensure that European Business Wallet data is exclusively stored and processed using standards equivalent to those required under Union law. |
Amendment 29
Proposal for a regulation
Recital 32
| Text proposed by the Commission | Amendment |
|---|---|
| (32) The Union must protect its security interest against providers which could represent a persistent security risk due to the potential interference from third countries. To that end, it is necessary to reduce the risk of persisting dependency on high-risk suppliers in the internal market, including in the ICT supply chain, as they could have potentially serious negative impacts on the security of economic operators and public sector bodies across the Union and the Union’s critical infrastructure, especially with regards to the integrity, confidentiality and availability of data and services. Any restrictions should be based on a proportionate risk assessment and corresponding mitigation measures as defined in Union policies and laws. Such limitations may apply, for example, to high-risk suppliers, as identified under Union law. | (32) The Union must protect its security interest against providers and suppliers which could represent a security risk due to the potential interference from third countries. To that end, it is necessary to reduce the persisting dependencies on high-risk suppliers in the internal market, including in the ICT supply chain, as they could have potentially serious negative impacts on the security of economic operators and public sector bodies across the Union and the Union’s critical infrastructure, especially with regards to the integrity, confidentiality and availability of data and services. Any restrictions must be based on a proportionate risk assessment and corresponding mitigation measures as defined in Union policies and laws. Such limitations may apply, for example, to high-risk suppliers, as identified under Union law. |
Amendment 30
Proposal for a regulation
Recital 32 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (32a) Cybersecurity is a key element for trust in the European Business Wallet ecosystem. The design and implementation of the system should ensure a high level of security by design and by default, including appropriate safeguards for data access, storage and transfer, while taking into account the risks associated with centralised components and dependencies. Where appropriate, governance and implementation models should avoid excessive concentration of critical functions and ensure resilience through secure and reliable architectures, thereby supporting trust and the proper functioning of the internal market. |
Amendment 31
Proposal for a regulation
Recital 33 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (33a) In order to foster innovation, competition and user choice in the market for European Business Wallet providers, the technical standards and protocols underpinning the European Business Wallet ecosystem should rely on standards that are interoperable and, where appropriate, open. Such standards should ensure that economic operators can easily switch between different providers of European Business Wallets without undue technical or administrative barriers, while ensuring that their data, credentials and electronic attestations of attributes remain usable and interoperable across the ecosystem. |
Amendment 32
Proposal for a regulation
Recital 40
| Text proposed by the Commission | Amendment |
|---|---|
| (40) To avoid excessive regulatory burdens, ex post supervision of providers of European Business Wallets and monitoring of their activities should be provided for, rather than requiring prior compliance verification for every aspect of their operations. This approach should allow for a more flexible and efficient regulatory environment, while maintaining the necessary safeguards to protect users and ensure compliance with the requirements of the European Business Wallets framework. The notification process for providers of European Business Wallets should be streamlined and efficient, with clear requirements and timelines for applicants. Qualified trust service providers, which are already subject to a robust regulatory framework under Regulation (EU) No 910/2014, should benefit from a particularly light process to be able to provide European Business Wallets. | (40) To avoid unnecessary regulatory burdens, ex post supervision of providers of European Business Wallets and monitoring of their activities should be provided for, rather than requiring prior compliance verification for every aspect of their operations. This approach should allow for a more flexible, risk-based and efficient regulatory environment, while maintaining the necessary safeguards to protect users and ensure compliance with the requirements of the European Business Wallets framework. The notification process for providers of European Business Wallets should be clear, transparent and efficient, with well-defined requirements and timelines for applicants, ensuring legal certainty and a high level of trust. Qualified trust service providers, which are already subject to a robust regulatory framework under Regulation (EU) No 910/2014, should benefit from a particularly light process to be able to provide European Business Wallets. |
Amendment 33
Proposal for a regulation
Recital 41
| Text proposed by the Commission | Amendment |
|---|---|
| (41) In order to ensure transparency and accountability in the European Business Wallet ecosystem, a publicly available list of notified providers of European Business Wallets should be established and maintained by the Commission. That list should include information transmitted by the national supervisory bodies concerning providers, including qualified trust service providers, that have completed the notification process. Making that information publicly available should enable users to verify the authenticity and trustworthiness of providers, thereby promoting a high level of security and trust in the European Business Wallet ecosystem. | (41) In order to ensure transparency and accountability in the European Business Wallet ecosystem, a publicly available list of notified providers of European Business Wallets should be established and maintained by the Commission. That list should include information transmitted by the national supervisory bodies concerning providers, including qualified trust service providers, that have completed the notification process. Making that information publicly available should enable users to verify the authenticity and trustworthiness of providers, thereby promoting a high level of security and trust in the European Business Wallet ecosystem. That list should be updated without undue delay following the completion of the notification process in order to ensure legal certainty for entities intending to provide European Business Wallets and for users of such services. In order to avoid unnecessary delays and ensure legal certainty for market participants, where the competent supervisory body does not provide a substantive response within the prescribed period, the notification should be deemed complete, and the description of the core functionalities should be considered to correspond to the requirements laid down in this Regulation. In such cases, the notifying entity should be added to the list of providers of European Business Wallets maintained by the Commission. |
Amendment 34
Proposal for a regulation
Recital 44
| Text proposed by the Commission | Amendment |
|---|---|
| (44) To harmonise the enforcement of this Regulation, national supervisory bodies should be empowered to impose administrative fines. It is necessary to specify the upper limit of administrative fines and the criteria for their determination in order to promote equal treatment of providers of European Business Wallets across the Union regardless of their Member State of establishment. The competent supervisory authority should assess each case individually, taking into account all relevant circumstances, including the nature, gravity and duration of the infringement, its consequences and any measures taken to ensure compliance and mitigate harm. In this regard, Member States should notify the Commission of the rules laid down in national law allowing the supervisory body to impose penalties by [Publications Office, insert the date 12 months after the entry into force of this Regulation] and should notify the Commission without delay of any subsequent amendments to those rules. | (44) To harmonise the enforcement of this Regulation, national supervisory bodies should be empowered to impose administrative sanctions, including fines. It is necessary to specify the upper limit of administrative fines and the criteria for their determination in order to promote equal treatment of providers of European Business Wallets across the Union regardless of their Member State of establishment. The competent supervisory authority should assess each case individually, taking into account all relevant circumstances, including the nature, gravity, duration and recurrence of the infringement, its consequences and any measures taken to ensure compliance and mitigate harm. In this regard, Member States should notify the Commission of the rules laid down in national law allowing the supervisory body to impose penalties by [Publications Office, insert the date 12 months after the entry into force of this Regulation] and should notify the Commission without delay of any subsequent amendments to those rules. |
Amendment 35
Proposal for a regulation
Recital 48
| Text proposed by the Commission | Amendment |
|---|---|
| (48) In order to avoid disrupting existing interactions between economic operators and public sector bodies, it is necessary to enable a transition period until [Publications Office, please insert the date 36 months after the entry into force of this Regulation]. During such period public sector bodies may choose not to offer the European Business Wallets' secure communication channel and instead support alternative solutions already in place which enable economic operators to communicate with public sector bodies prior to offering the European Business Wallets’ secure communication channel. In order to ensure an adequate level of security and interoperability, any alternative solution used during this transition period should comply with the requirements for Qualified Electronic Registered Delivery Services set out in Regulation (EU) No 910/2014 and offer a gateway to European Business Wallets. The gateway should enable users of European Business Wallets to access the alternative solutions used during the transition period. After this period, public sector bodies should support the secure communication channel of the European Business Wallets to ensure a harmonised and efficient means of communication across the Union, to the benefits of European businesses. | (48) In order to avoid disrupting existing interactions between economic operators and public sector bodies, it is necessary to enable a transition period until [Publications Office, please insert the date 36 months after the entry into force of this Regulation]. During such period public sector bodies may choose not to offer the European Business Wallets' secure communication channel and instead support alternative solutions already in place which enable economic operators to communicate with public sector bodies prior to offering the European Business Wallets’ secure communication channel. In order to ensure an adequate level of security and interoperability, any alternative solution used during this transition period should comply with the requirements for Qualified Electronic Registered Delivery Services set out in Regulation (EU) No 910/2014 and offer a gateway to European Business Wallets. The gateway should enable users of European Business Wallets to access the alternative solutions used during the transition period. After this period, public sector bodies should support the secure communication channel of the European Business Wallets to ensure a harmonised and efficient means of communication across the Union, to the benefits of European businesses and the proper functioning of the internal market. |
Amendment 36
Proposal for a regulation
Recital 54
| Text proposed by the Commission | Amendment |
|---|---|
| (54) In order to ensure uniform conditions for the implementation of the recognition and interoperability of business wallets or similar systems and framework from third countries to support and promote partnerships and cooperation, implementing powers should be conferred on the Commission to set the conditions under which such similar systems or framework benefit from the provisions of this Regulation. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council. | (54) In order to ensure legal certainty, preserve a high level of trust and guarantee uniform conditions for the recognition and interoperability of business wallets or similar systems and framework from third countries to support and promote partnerships and cooperation, implementing powers should be conferred on the Commission to set the conditions under which such similar systems or framework may benefit from the provisions of this Regulation. The recognition of such systems or frameworks should be subject to a thorough assessment of whether the functions offered are clearly defined and equivalent in substance to those provided under this Regulation, taking into account, in particular, the scope of functionalities, the level of security and reliability, data protection, as well as interoperability with the trust framework laid down in Regulation (EU) No 910/2014. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council. The Commission may, where appropriate, take into account the development of reciprocal arrangements with the relevant third countries when assessing the frameworks, in order to reduce administrative burden and facilitate cross-border economic activity, while ensuring compliance with Union requirements. Particular attention should be paid to economic operators from third countries in order to avoid potential threats to the Union's strategic interests. |
Amendment 37
Proposal for a regulation
Recital 54 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (54a) All implementing acts adopted pursuant to this Regulation should be proportionate, technologically neutral and should not create unnecessary administrative burden, taking account of the specific needs and limited resources of SMEs, sole traders and self-employed persons. |
Amendment 38
Proposal for a regulation
Recital 58 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (58a) E-invoicing is a core digital business process that supports automation, reduces administrative burden and improves cash-flow management, in particular for SMEs. Its development is closely linked to Union initiatives such as the VAT in the Digital Age (ViDA) package and the future framework for the 28th regime, which rely on interoperable and secure digital data exchanges. The European Business Wallet may therefore facilitate the secure use and storage of electronic invoices in cross-border transactions, in compliance with existing Union law. |
Amendment 39
Proposal for a regulation
Recital 58 b (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (58b) In order to ensure that European Business Wallets can be effectively used in real business environments, the framework for unique identifiers should support hierarchical and operational identifiers reflecting the structure and activities of economic operators. This includes, where relevant, identifiers for subsidiaries, branches, establishments or operational units, as well as identifiers enabling the correct routing of transactions within and between organisations. Such flexibility is necessary to ensure interoperability with existing business systems and to support compliance processes, including electronic invoicing and reporting obligations. |
Amendment 40
Proposal for a regulation
Recital 58 c (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (58c) In order to support the efficient and coherent implementation of European Business Wallets across the Union, the Commission should, in close cooperation with the Member States and relevant stakeholders, develop and regularly update a comprehensive and forward-looking implementation roadmap. That roadmap should extend beyond the initial deployment phase and identify key milestones, priority use cases and practical applications in business-to-government (B2G), government-to-business (G2B) and business-to-business (B2B) interactions. It should also take into account the need to ensure cross-border interoperability and seamless integration with existing digital solutions at Union and national level, with a view to facilitating uptake by economic operators and supporting public sector bodies at all levels, including those with limited administrative or technical capacity. |
Amendment 41
Proposal for a regulation
Article 1 – paragraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| This Regulation enables secure digital identification and authentication, data sharing and legally valid notifications, reduces administrative burdens and compliance costs, and supports cross-border business and competitiveness. In particular, it: | This Regulation enables secure digital identification and authentication, data sharing and legally valid notifications, reduces unnecessary administrative requirements and compliance costs, and supports cross-border business and competitiveness. In particular, it: |
Amendment 42
Proposal for a regulation
Article 1 – paragraph 1 – point 6
| Text proposed by the Commission | Amendment |
|---|---|
| (6) lays down the notification mechanism under which providers of European Business Wallets shall be established; | (6) lays down the notification mechanism under which providers of European Business Wallets shall be authorised to provide European Business Wallets; |
Amendment 43
Proposal for a regulation
Article 1 – paragraph 1 – point 9
| Text proposed by the Commission | Amendment |
|---|---|
| (9) provides a framework for the recognition of third-country systems similar to the European Business Wallets and the issuance of European Business Wallets to third country economic operators. | (9) provides a framework for the recognition of third-country systems similar to the European Business Wallets, which offer the same level of security, trust and digital standards as the European Business Wallets, and the issuance of European Business Wallets to third country economic operators. |
Amendment 44
Proposal for a regulation
Article 2 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. This Regulation is without prejudice to the existing systems and procedures mandated by Union law governing the exchange of documents and data between competent authorities. | 2. This Regulation is without prejudice to the existing systems and procedures mandated by Union and national law governing the exchange of documents and data between competent authorities. |
Amendment 45
Proposal for a regulation
Article 3 – paragraph 1 – point 43 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (43a) ‘incident’ means an incident as defined in Article 6, point (6) of Directive (EU) 2022/2555. |
Amendment 46
Proposal for a regulation
Article 5 – paragraph 1 – point l
| Text proposed by the Commission | Amendment |
|---|---|
| (l) export their data, including issued European Business Wallet owner identification data, electronic attestations of attributes, communication logs, and interaction records, in a structured, commonly used and machine-readable format, at the request of the owner or in the event of termination of service or revocation of the notification of the provider of the European Business Wallet; | (l) export their data, including issued European Business Wallet owner identification data, electronic attestations of attributes, communication logs, and interaction records, in a structured, commonly used and machine-readable format, at the request of the owner or in the event of termination of service or revocation of the notification of the provider of the European Business Wallet, to enable data portability across providers of European Business Wallets; |
Amendment 47
Proposal for a regulation
Article 5 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Providers of European Business Wallets may offer additional functionalities beyond those listed in paragraph 1 provided that such functionalities do not interfere with or compromise the confidentiality, availability, or integrity of the minimum core functionalities, and the reliability and interoperability of the European Business Wallets they provide. | 2. Providers of European Business Wallets may offer additional functionalities beyond those listed in paragraph 1 provided that the full and consistent implementation of the minimum core functionalities is ensured and that such functionalities do not interfere with or compromise the confidentiality, availability, or integrity of the minimum core functionalities, and the reliability and interoperability of the European Business Wallets they provide. |
Amendment 48
Proposal for a regulation
Article 5 – paragraph 5
| Text proposed by the Commission | Amendment |
|---|---|
| 5. The Commission shall, by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the core functionalities of European Business Wallets referred to in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 5. The Commission shall, by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures the core functionalities of European Business Wallets referred to in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 5 of Regulation (EU) No 182/2011. |
Amendment 49
Proposal for a regulation
Article 6 – paragraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Providers of European Business Wallets shall ensure that the European Business Wallets they provide support common protocols and interfaces: | 1. Providers of European Business Wallets shall ensure that the European Business Wallets they provide support common protocols and interfaces, while ensuring that those wallets remain user-friendly and do not create disproportionate administrative or technical requirements for economic operators: |
Amendment 50
Proposal for a regulation
Article 6 – paragraph 2 – point e
| Text proposed by the Commission | Amendment |
|---|---|
| (e) provide a mechanism enabling European Business Wallet owners to easily request technical support and report technical problems or any other incidents having a negative impact on the use of European Business Wallets; | (e) provide a mechanism enabling European Business Wallet owners to easily request technical support and report technical problems or any other incidents having a negative impact on the use of European Business Wallets in a timely and effective manner; |
Amendment 51
Proposal for a regulation
Article 6 – paragraph 2 – point f – indent 4
| Text proposed by the Commission | Amendment |
|---|---|
| – where the provider of the European Business Wallet is not included in the list referred to in Article 12(5). | – where the provider of the European Business Wallet is not included in the list referred to in Article 12(3). |
Amendment 52
Proposal for a regulation
Article 6 – paragraph 2 – point g – indent 2 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| – any security breach or hazard affecting European Business Wallets, in particular where the breach originates from, or involves actors or systems located in, a third country. |
Amendment 53
Proposal for a regulation
Article 7 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. European Business Wallets shall be provided by providers of European Business Wallets that are included in the list established pursuant to Article 12(5). | 1. European Business Wallets shall be provided by European Business Wallets providers that are included in the list established pursuant to Article 12(3). |
Amendment 54
Proposal for a regulation
Article 7 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Given the role of European Business Wallets in the Unions digital infrastructure, providers of European Business Wallets shall be established in the Union, have their principal place of business and main operations in the Union and not present a risk to the security of the Union. In particular they shall not be subject to control by a third country or by a third-country entity. | 2. Given the role of European Business Wallets in the Unions digital infrastructure, providers of European Business Wallets shall be established in the Union, have their principal place of business and main operations in the Union and not present a risk to the security of the Union. In particular they shall not be directly or indirectly controlled by a third country or by a third-country entity, while ensuring a level playing field and fair competition within the internal market. Providers of European Business Wallets shall, to the extent technically feasible and where appropriate, make use of cloud service providers which are established in the Union, and have their principal place of business and main operations in the Union. Providers of European Business Wallets shall also ensure that their suppliers, including cloud service providers, do not present a risk to the security of the Union. European Business Wallets data shall be exclusively stored and processed using standards equivalent to those required under Union law. |
Amendment 55
Proposal for a regulation
Article 7 – paragraph 5
| Text proposed by the Commission | Amendment |
|---|---|
| 5. Providers of European Business Wallets shall comply with applicable cybersecurity requirements laid down in Union and national law, including those relating to the identification of high-risk suppliers. Providers shall also ensure that their suppliers of software and security solutions comply with these requirements and conform to the relevant security standards and requirements. | 5. Providers of European Business Wallets shall comply with applicable cybersecurity requirements laid down in Union and national law, including those relating to the identification of high-risk suppliers. Providers shall also ensure that their suppliers of software and security solutions, as well as their cloud service providers that host European Business Wallets data, comply with these requirements and conform to the relevant security standards and requirements. |
Amendment 56
Proposal for a regulation
Article 7 – paragraph 6 – point e
| Text proposed by the Commission | Amendment |
|---|---|
| (e) notify the relevant national supervisory bodies, or the Commission in the cases referred to in Article 14(1), of any substantive changes to their services or overall structure which may impact the compliance of the provider with this Regulation; | (e) notify, without undue delay, the relevant national supervisory bodies, or the Commission in the cases referred to in Article 15(1), of any substantive changes to their services or overall structure which may impact the compliance of the provider with this Regulation; |
Amendment 57
Proposal for a regulation
Article 7 – paragraph 6 – point f
| Text proposed by the Commission | Amendment |
|---|---|
| (f) notify European Business Wallet owners in the event of suspension, revocation or voluntary termination of the providers of European Business Wallet`s services and of the removal of the provider of European Business Wallet from the list established pursuant to Article 12(5) and ensure the transfer or deletion of the European Business Wallet owner data in accordance with the European Business Wallet owners instructions, including European Business Wallet owner identification data; | (f) notify, without undue delay, European Business Wallet owners in the event of suspension, revocation or voluntary termination of the providers of European Business Wallet`s services and of the removal of the provider of European Business Wallet from the list established pursuant to Article 12(3) and ensure the transfer or deletion of the European Business Wallet owner data in accordance with the European Business Wallet owners instructions, including European Business Wallet owner identification data; |
Amendment 58
Proposal for a regulation
Article 7 – paragraph 6 – point g a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (ga) ensure that their services are user friendly and accessible, taking into account the diverse needs, including those of persons with disabilities, in accordance with Union law. |
Amendment 59
Proposal for a regulation
Article 8 – paragraph 7
| Text proposed by the Commission | Amendment |
|---|---|
| 7. The Commission may, by means of implementing acts, set out requirements for European Business Wallet owner identification data issued pursuant to this Article, including procedures for Member States to notify to the Commission the relevant authentic sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 7. The Commission may, by means of implementing acts, set out harmonised requirements for European Business Wallet owner identification data issued pursuant to this Article, including procedures for Member States to notify to the Commission the relevant authentic sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Amendment 60
Proposal for a regulation
Article 9 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Where an economic operator or public sector body has not been attributed a European Unique Identifier, a unique identifier shall be created in accordance with the implementing act referred to in paragraph 4. | 2. Where an economic operator or public sector body has not been attributed a European Unique Identifier, a unique identifier shall be created without undue delay in accordance with the implementing act referred to in paragraph 4. |
Amendment 61
Proposal for a regulation
Article 9 – paragraph 4 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 4a. The Commission shall, when establishing technical specifications for the European Business Wallet, ensure that the identifier framework supports hierarchical and operational identifiers reflecting the organisational structure and operational needs of economic operators. |
Amendment 62
Proposal for a regulation
Article 10 – paragraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The Commission shall establish, operate and maintain a European Digital Directory which shall act as the trusted source of information for European Business Wallet owners and shall take the form of a web application comprising of two interfaces: | 1. The Commission shall establish, operate and maintain a European Digital Directory which shall act as the trusted source of information for European Business Wallet owners and shall take the form of a web application comprising of two easily accessible interfaces: |
Amendment 63
Proposal for a regulation
Article 10 – paragraph 3
| Text proposed by the Commission | Amendment |
|---|---|
| 3. The Commission shall ensure that the relevant information shall be included in the European Digital Directory. | 3. The Commission shall ensure that the relevant information is included in the European Digital Directory in a secure manner and in accordance with the relevant data protection principles. |
Amendment 64
Proposal for a regulation
Article 10 – paragraph 4
| Text proposed by the Commission | Amendment |
|---|---|
| 4. The Commission shall make the European Digital Directory only accessible to European Business Wallet owners and their authorised representatives and providers of European Business Wallets. | 4. The Commission shall make the web-based interface of the European Digital Directory only accessible to European Business Wallet owners and their authorised representatives and providers of European Business Wallets. |
Amendment 65
Proposal for a regulation
Article 10 – paragraph 5
| Text proposed by the Commission | Amendment |
|---|---|
| 5. Any modification or revocation concerning the information referred to in paragraph 2 shall, without undue delay and in any event within one working day, be communicated by the providers of European Business Wallet directly to the Commission for the purpose of maintaining the European Digital Directory. | 5. Any modification or revocation concerning the information referred to in paragraph 2 shall, without undue delay and in any event within three working days, be communicated by the providers of European Business Wallet directly to the Commission for the purpose of maintaining the European Digital Directory. |
Amendment 66
Proposal for a regulation
Article 11 – paragraph 2 – point e a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) safety policies to address security risks related to the protection of data of the European Business Wallet owner. |
Amendment 67
Proposal for a regulation
Article 12 – paragraph 3
| Text proposed by the Commission | Amendment |
|---|---|
| 3. On the basis of the information received pursuant to this Article, the Commission shall establish and maintain on the Commission’s website, in a machine-readable format, a list of providers of European Business Wallets. | 3. On the basis of the information received pursuant to this Article, the Commission shall establish and maintain on the Commission’s website, in an easily accessible and machine-readable format, a list of providers of European Business Wallets and update that list without undue delay following the receipt of such information. |
Amendment 68
Proposal for a regulation
Article 13 – paragraph 3
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Member States shall ensure that the supervisory bodies referred to in paragraph 1 have the necessary powers and adequate resources for the exercise of their tasks in an effective, efficient and independent manner. | 3. Member States shall ensure that the supervisory bodies referred to in paragraph 1 are entrusted with the necessary powers, responsibilities and sufficient resources for the exercise of their tasks and enforcement of the obligations under this Regulation in an effective, efficient and independent manner. |
Amendment 69
Proposal for a regulation
Article 13 – paragraph 5 – point b
| Text proposed by the Commission | Amendment |
|---|---|
| (b) investigate substantiated claims, particularly those made by European Business Wallets owners, that a provider of European Business Wallets fails to comply with any of its obligations under this Regulation and to take action if necessary; | (b) set up a complaint mechanism whereby substantiated complaints can be filed, particularly by European Business Wallets owners, that a provider of European Business Wallets fails to comply with any of its obligations under this Regulation, investigate such complaints and take action, including enforcement measures, if necessary, in a transparent manner and within a reasonable timeframe; |
Amendment 70
Proposal for a regulation
Article 13 – paragraph 5 – point f
| Text proposed by the Commission | Amendment |
|---|---|
| (f) inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant security breach or loss of integrity of which it becomes aware in the performance of its tasks and, in the case of a significant security breach or loss of integrity which concerns other Member States, to inform the single point of contact designated or established pursuant to Article 8(3) Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of Regulation (EU) No 910/2014 in the other Member States concerned, and to inform the public or require the provider of European Business Wallets to do so where the supervisory body determines that disclosure of the breach of security or loss of integrity would be in the public interest; | (f) inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant incident of which it becomes aware in the performance of its tasks and, in the case of a significant incident which concerns other Member States, to inform the single point of contact designated or established pursuant to Article 8(3) Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of Regulation (EU) No 910/2014 in the other Member States concerned, and to inform the public or require the provider of European Business Wallets to do so where the supervisory body determines that disclosure of the breach of security or loss of integrity would be in the public interest; |
Amendment 71
Proposal for a regulation
Article 13 – paragraph 5 – point j
| Text proposed by the Commission | Amendment |
|---|---|
| (j) report to the Commission on its main activities; | (j) report regularly to the Commission on its main activities; |
Amendment 72
Proposal for a regulation
Article 13 – paragraph 11
| Text proposed by the Commission | Amendment |
|---|---|
| 11. Based on the evaluation, the Commission may decide that a corrective or restrictive measure is necessary, and after consulting the Member States concerned and the provider, the Commission may determine the appropriate course of action. The Commission shall take into account the nature and severity of the non-compliance, as well as the potential impact on the internal market and the rights of economic operators. | 11. Based on the evaluation, the Commission may decide that a corrective or restrictive measure is necessary, and after consulting the Member States concerned and the provider, the Commission may determine the appropriate course of action and provide appropriate justifications to the Member State and provider concerned. The Commission shall take into account the nature and severity of the non-compliance, as well as the potential impact on the internal market and the rights of economic operators. |
Amendment 73
Proposal for a regulation
Article 14 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| The European Digital Identity Cooperation Group established pursuant to Article 46e of Regulation (EU) No 910/2014 shall be responsible for facilitating cooperation and information sharing among Member States and the Commission on matters related to the European Business Wallets. This shall include sharing best practices, discussing technical and operational issues, and coordinating efforts to ensure the proper implementation and functioning of the European Business Wallets. | The European Digital Identity Cooperation Group established pursuant to Article 46e of Regulation (EU) No 910/2014 shall be responsible for supporting the national supervisory bodies, facilitating cooperation and information sharing among the Member States and the Commission on matters related to the European Business Wallets. This shall include sharing best practices, discussing technical and operational issues, and coordinating efforts to ensure the proper implementation and functioning of the European Business Wallets. |
Amendment 74
Proposal for a regulation
Article 15 – paragraph 3 – subparagraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| The Commission shall prepare a report on its main activities in this respect. | The Commission shall prepare an annual report on its main activities in this respect and submit it to the European Parliament and to the Council. |
Amendment 75
Proposal for a regulation
Article 16 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. For the purposes of paragraph 1, points (c) and (d), public sector bodies shall have European Business Wallets, including the qualified electronic registered delivery service referred to in Article 5(1), point (i). | 2. For the purposes of paragraph 1, points (c) and (d) of this Article, public sector bodies shall have European Business Wallets, including the qualified electronic registered delivery service referred to in Article 5(1), point (i). Public sector bodies may also make use of European Business Wallets for the purposes referred to in paragraph 1, points (a) and (b) of this Article. |
Amendment 76
Proposal for a regulation
Article 17 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The Commission may adopt implementing acts establishing that business wallets or systems offering similar functions that are issued by providers established in third countries are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that such business wallets or systems are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 1. The Commission may adopt implementing acts establishing that business wallets or systems offering similar functions that are issued by providers established in third countries and which guarantee the same level of trust, security and interoperability to those of European Business Wallets, may be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that such business wallets or systems are interoperable with the trust framework laid down in Regulation (EU) 910/2014, that they ensure security, data protection, and reliability standards equivalent to those required under Union law, and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Amendment 77
Proposal for a regulation
Article 17 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The Commission may adopt implementing acts establishing that third country frameworks for systems offering similar functions as the European Business Wallets are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that the systems provided under that framework are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 2. The Commission may adopt implementing acts establishing that third country frameworks for systems offering similar functions that guarantee the same level of trust, security and interoperability to those of European Business Wallets, may be considered as offering assurances equivalent to those provided under this Regulation, provided that the systems provided under that framework are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Amendment 78
Proposal for a regulation
Article 17 – paragraph 3
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Prior to the adoption of the implementing acts referred to in paragraphs 1 and 2, the Commission shall assess whether the assurances can be considered as equivalent to the requirements under this Regulation. | 3. Prior to the adoption of the implementing acts referred to in paragraphs 1 and 2, the Commission shall assess whether the assurances can be considered as equivalent to the requirements under this Regulation. That assessment shall evaluate the functionalities, security, independence of providers, reliability and interoperability with the trust framework laid down in Regulation (EU) No 910/2014, and evaluate risks to the internal market, in particular from third-country providers, including compliance with Union data protection and cybersecurity rules as well as impact on competition and Union economic operators. |
Amendment 79
Proposal for a regulation
Article 17 – paragraph 4
| Text proposed by the Commission | Amendment |
|---|---|
| 4. The Commission shall, where available information reveals that those assurances can no longer be considered as equivalent to the requirements under this Regulation, to the extent necessary, repeal, amend or suspend the act referred to in paragraphs 1 and 2 by means of an implementing act. | 4. The Commission shall review, on an annual basis, whether those assurances can be considered as equivalent to the requirements under this Regulation. Where the results of that review or other available information reveal that this is no longer the case, the Commission shall without undue delay and to the extent necessary, repeal, amend or suspend the act referred to in paragraphs 1 and 2 by means of an implementing act. |
Amendment 80
Proposal for a regulation
Article 18 – paragraph 5 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| 5. Providers of European Business Wallet owner identification data may issue European Business Wallet owner identification data and unique identifiers pursuant to Articles 8 and 9 to economic operators established outside the Union, provided that: | 5. Providers of European Business Wallet owner identification data may issue European Business Wallet owner identification data and unique identifiers, without undue delay, following successful identity verification pursuant to Articles 8 and 9 to economic operators established outside the Union, provided that: |
Amendment 81
Proposal for a regulation
Article 18 – paragraph 6
| Text proposed by the Commission | Amendment |
|---|---|
| 6. Member States shall cooperate to ensure that providers of European Business Wallet owner identification data can verify that an economic operator established outside the Union has not yet been issued European Business Wallet owner identification data. | 6. Member States shall cooperate, including through the exchange of relevant information and through the use of Union-level systems established under this Regulation, to ensure that providers of European Business Wallet owner identification data can verify that an economic operator established outside the Union has not yet been issued European Business Wallet owner identification data. |
Amendment 82
Proposal for a regulation
Article 21 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The Commission shall review the application of this Regulation and shall, by [Publications Office, insert the date – 3 years after entry into force], submit a report to the European Parliament and to the Council. The report shall evaluate the effectiveness of the provisions of this Regulation with regard to facilitating the submission of electronic documents and electronic attestations to public sector bodies, by the usage of the European Business Wallets, as well as technological, market, and legal developments. The report shall also assess whether it is necessary to modify the scope of this Regulation or its specific provisions to set out an obligation for the use of the European Business Wallets to address the risks of legal fragmentation. | 1. The Commission shall review the application of this Regulation and shall, by [Publications Office, insert the date – 3 years after entry into force], submit a report to the European Parliament and to the Council. The report shall evaluate the effectiveness of the provisions of this Regulation with regard to facilitating the submission of electronic documents and electronic attestations to public sector bodies, by the usage of the European Business Wallets, as well as technological, market, and legal developments. |
| The report shall assess the impact of the Regulation on the reduction of administrative requirements and compliance costs, particularly for SMEs and smaller public sector bodies, as well as its contribution to cross-border activities and competitiveness, and shall examine the administrative and financial costs of implementation, including those arising from the coexistence with existing systems. | |
| It shall also evaluate cross-border interoperability, including with existing Union and national digital solutions, and identify any duplication or parallel systems. | |
| Based on the results, the Commission shall evaluate whether it is necessary to modify the scope of this Regulation or its specific provisions. Any such modification shall be accompanied by an impact assessment. |
Amendment 83
Proposal for a regulation
Article 21 – paragraph 2 – subparagraph 1 – point d a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (da) the effectiveness of cooperation between supervisory bodies in the Member States and with the Commission in the implementation and supervision of this Regulation; |
Amendment 84
Proposal for a regulation
Article 21 – paragraph 2 – subparagraph 1 – point d b (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (db) a review of financial, administrative or other possible impact on SMEs, sole traders and self-employed persons. |
Amendment 85
Proposal for a regulation
Article 21 – paragraph 2 – subparagraph 2 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| The Commission shall issue guidelines, including common definitions and technical guidance, to facilitate the consistent implementation of this Regulation across Member States. |
8.6.2026
Opinion of the committee on legal affairs 346 paragraphs
for the Committee on Industry, Research and Energy
on the proposal for a regulation of the European Parliament and of the Council on the establishment of European Business Wallets
(COM(2025)0838 – C100305/2025 – 2025/0358(COD))
Rapporteur for opinion: Axel Voss
AMENDMENTS
The Committee on Legal Affairs submits the following to the Committee on Industry, Research and Energy, as the committee responsible:
Amendment 1
Proposal for a regulation
Recital 3
| Text proposed by the Commission | Amendment |
|---|---|
| (3) In order to foster a competitive and digital European economy, and to facilitate cross-border business, it is necessary to establish a seamless and secure environment for digital interaction between economic operators and public sector bodies in different configurations. | (3) In order to foster a competitive and digital European economy, to reduce economic disparities within the Union and to facilitate cross-border business, it is necessary to establish a seamless, efficient and secure environment for digital interaction among economic operators and between economic operators and public sector bodies in different configurations, without creating additional administrative and financial burdens for economic operators. |
Amendment 2
Proposal for a regulation
Recital 5
| Text proposed by the Commission | Amendment |
|---|---|
| (5) In order to enhance the functioning of the digital single market, ensure interoperability and reduce administrative burdens, it is essential to ensure compatibility between and European Business Wallets and existing systems and solutions at both Union and national level. As prescribed by the Interoperable Europe Act and to enhance secure and efficient data exchanges across the Union, the implementation of the European Business Wallets should, to the extent possible, where appropriate and following technical analysis, make use of existing EU digital infrastructures and building blocks, including those developed under the Once Only Technical System, the Business Registers Interconnection System and the European Digital Identity Wallet, thereby ensuring complementarity, interoperability, and efficient use of public resources. | (5) In order to enhance the functioning of the digital single market, ensure interoperability and reduce administrative burdens, it is essential to ensure compatibility between and European Business Wallets and existing systems and solutions at both Union and national level. In this regard, the implementation of this Regulation should take into account such systems and solutions. As prescribed by the Interoperable Europe Act and to enhance secure and efficient data exchanges across the Union, the implementation of the European Business Wallets should, to the extent possible, where appropriate and following technical analysis, make use of existing EU digital infrastructures and building blocks, including those developed under the Once Only Technical System, the Business Registers Interconnection System and the European Digital Identity Wallet, thereby ensuring complementarity, interoperability, and efficient use of public resources. Those efforts should be supported by the European Digital Identity Cooperation Group. |
Amendment 3
Proposal for a regulation
Recital 6
| Text proposed by the Commission | Amendment |
|---|---|
| (6) The European Business Wallets are a digital tool for economic operators to interact with public sector bodies in the context of meeting reporting obligations and fulfilling administrative procedures. The use of the core functionalities of the European Business Wallets to identify and authenticate, sign or seal, submit documents and send or receive notifications should be without prejudice to procedural requirements that might be part of an administrative procedure and that cannot be fulfilled by the core functionalities of the European Business Wallets. These procedural requirements may include any additional safeguards or verifications, such as checks to ensure the awareness or understanding of the contents of a document or the implications of the signature of a contract, or specific actions that are required as part of an administrative procedure and are not supported by the core functionalities of the European Business Wallets. Public sector bodies should therefore ensure that all relevant procedural requirements are met, including any specific actions or processes which need to be fulfilled as part of an administrative procedure and which cannot be performed through the European Business Wallets. | (6) The European Business Wallets are a digital tool for economic operators to interact with public sector bodies in the context of meeting reporting obligations and fulfilling administrative procedures, and a digital tool for interactions in business-to-business settings. The use of the core functionalities of the European Business Wallets to identify and authenticate, sign or seal, submit documents, send or receive notifications, and request or share electronic attestations of attributes, communication logs and interaction records in a structured, commonly used and machine-readable format which will facilitate machine translation of such data, should be without prejudice to procedural requirements or requirements relating to form that might be part of an administrative procedure and that cannot be fulfilled by the core functionalities of the European Business Wallets. These procedural requirements may include any additional safeguards or verifications, such as checks to ensure the awareness or understanding of the contents of a document or the implications of the signature of a contract, or specific actions that are required as part of an administrative procedure and are not supported by the core functionalities of the European Business Wallets. Public sector bodies should therefore ensure that all relevant procedural requirements are met, including any specific actions or processes which need to be fulfilled as part of an administrative procedure and which cannot be performed through the European Business Wallets. |
Amendment 4
Proposal for a regulation
Recital 7
| Text proposed by the Commission | Amendment |
|---|---|
| (7) Public sector bodies have the flexibility to decide how to ensure that they can accept European Business Wallets considering the diversity of their IT infrastructure and their needs for interoperability. This approach allows public sector bodies to maintain their existing operational frameworks, while benefiting from the advantages of the European Business Wallets. | (7) Public sector bodies have the flexibility to decide how to ensure that they can accept European Business Wallets considering the diversity of their IT infrastructure and their needs for interoperability. This approach allows public sector bodies to maintain their existing operational frameworks and avoid additional costs, while benefiting from the advantages of the European Business Wallets. To the extent public sector bodies have already developed effective and secure solutions for core functionalities, those solutions should be duly taken into account and could be maintained, provided that they are interoperable, in order to ensure a cost-effective implementation of this Regulation by ensuring compatibility with European Business Wallets rather than replacing or duplicating those solutions. |
Amendment 5
Proposal for a regulation
Recital 7 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (7a) The implementation of this Regulation should respect the principle of proportionality and contribute to reducing administrative burden and compliance costs for economic operators, especially micro-undertakings and small and medium-sized undertakings. The design and deployment of European Business Wallets should therefore take into account the limited administrative capacities and resources of smaller businesses, should be offered under fair, transparent and non-discriminatory conditions and should avoid creating additional reporting or compliance obligations. |
Amendment 6
Proposal for a regulation
Recital 7 b (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (7b) In order to promote the effective and widespread uptake of European Business Wallets across the Union, their deployment and use should take into account differences in digital infrastructure, administrative capacity and levels of digitalisation across Member States and regions, including rural, remote and less developed areas. European Business Wallets should therefore be designed and implemented in an inclusive, accessible and user-friendly manner, including through intuitive interfaces and appropriate accessibility functionalities, so as to ensure effective and equal access for all economic operators, including for users with limited digital skills, and should support multilingual access in accordance with the linguistic diversity of the Union. It should be possible for Union funding instruments to support the effective deployment and uptake of European Business Wallet solutions, especially in less developed regions. |
Amendment 7
Proposal for a regulation
Recital 11
| Text proposed by the Commission | Amendment |
|---|---|
| (11) In order to reduce administrative burden and improve competitiveness, all entities conducting economic activities, including companies, organisations, self-employed persons, sole traders and any other type of business, regardless of size, sector or legal form, should be able to use European Business Wallets. To ensure that legally valid notifications, and documents can be exchanged, and reporting obligations fulfilled by means of European Business Wallets, it is necessary to establish a reliable and secure communication channel that can be used by European Business Wallet owners across the Union. A qualified electronic registered delivery service (‘QERDS’) should therefore be integrated as a secure communication channel in the European Business Wallets, and should enable the secure and legally valid exchange of information between parties, as provided for in Article 43 of Regulation (EU) No 910/2014. | (11) In order to reduce administrative burden and improve competitiveness, all entities conducting economic activities, including companies, organisations, self-employed persons, sole traders and any other type of business, regardless of size, sector or legal form, should be able to use European Business Wallets. Those entities should be able to become European Business Wallet owners in various ways, including through ownership, license, subscription or any other agreement granting a right of use of a European Business Wallet, without restrictions to fair, transparent, non-discriminatory and interoperable access to European Business Wallets, including cross border. To ensure that legally valid notifications, and documents can be exchanged, and reporting obligations fulfilled by means of European Business Wallets, it is necessary to establish a reliable and secure communication channel that can be used by European Business Wallet owners across the Union. A qualified electronic registered delivery service (‘QERDS’) should therefore be integrated as a secure communication channel in the European Business Wallets, and should enable the secure and legally valid exchange of information between parties, as provided for in Article 43 of Regulation (EU) No 910/2014. |
Amendment 8
Proposal for a regulation
Recital 12
| Text proposed by the Commission | Amendment |
|---|---|
| (12) In order to provide a tailored solution for self-employed persons and sole traders, it is essential to ensure the seamless integration of European Digital Identity Wallets with European Business Wallets. That integration should enable those persons to authenticate using their European Digital Identity Wallet and access trust services offered for the European Business Wallets, including the QERDS established as a secure communication channel in this Regulation, using those Wallets, without the need to create a separate business identity. Providers of European Business Wallets should therefore be allowed to offer the secure communication channel as a standalone service to self-employed persons and sole traders that use European Digital Identity Wallets in a business capacity, with ensured interoperability to facilitate app switching, as well as trust services such as electronic signatures and qualified and non-qualified time stamping services. Such access to the secure communication channel for self-employed persons and sole traders, should be promoted by ensuring an offer, at reasonable and affordable prices, that reflects the usage needs and is accompanied by terms of use that do not impose an undue burden on those persons. | (12) In order to provide a tailored solution for self-employed persons and sole traders, it is essential to ensure the seamless integration of European Digital Identity Wallets with European Business Wallets. That integration should enable those persons to authenticate using their European Digital Identity Wallet and access trust services offered for the European Business Wallets, including the QERDS established as a secure communication channel in this Regulation, using those Wallets, without the need to create a separate business identity. Providers of European Business Wallets should therefore be allowed to offer the secure communication channel as a standalone service to self-employed persons and sole traders that use European Digital Identity Wallets in a business capacity, with ensured interoperability to facilitate app switching, as well as trust services such as electronic signatures and qualified and non-qualified time stamping services. Such access to the secure communication channel for self-employed persons and sole traders, should be promoted by ensuring an offer, at reasonable and affordable prices, that reflects the usage needs and is accompanied by terms of use that do not impose an undue burden on those persons. The implementation of this Regulation should ensure that solutions for self-employed persons and sole traders are sufficient to perform the core functionalities of the European Business Wallets. It is also essential to ensure that self-employed persons or sole traders that perform multiple distinct activities, such as tax advice and legal services, are allowed to use separate solutions for each economic activity in such a way as to facilitate the performance of each distinct activity. |
Amendment 9
Proposal for a regulation
Recital 13
| Text proposed by the Commission | Amendment |
|---|---|
| (13) The European Business Wallets, in combination with Regulation (EU) 2018/1724, should support the forthcoming 28th Regime(5 ) by providing the digital infrastructure for fully digital procedures, enabling start-ups and scale-ups to conduct EU-wide operations in a rapid and efficient manner. The Business Wallets should provide the digital infrastructure for the 28th Regime's digital-first strategy, streamlining cross-border interactions and reducing administrative burden, such as facilitating the secure storing and signature of contracts and certificates or submitting, receiving and sharing electronic applications and documents. By providing this infrastructure, the Business Wallets should help make the "digital by default" principle a reality, facilitating the growth and development of EU companies and enhancing their competitiveness. | (13) The European Business Wallets, in combination with Regulation (EU) 2018/1724, should support the newly proposed EU Inc., a new harmonised corporate legal regime and a starting point for the Union's 28th Regime(5) by providing the digital infrastructure to perform any procedures established under that framework in a fully digital manner, enabling start-ups and scale-ups to conduct EU-wide operations in a rapid and efficient manner. In particular, European Business Wallets should be interoperable with, and enable the execution of, procedures and legal acts established under that framework, including the digital incorporation, registration, representation, governance and cross-border operation of companies. The Business Wallets should provide the digital infrastructure for the EU Inc.’s digital-first strategy, streamlining cross-border interactions and reducing administrative burden, such as facilitating the secure storing and signature of contracts and certificates or submitting, receiving and sharing electronic applications and documents. By providing this infrastructure, the Business Wallets should help make the "digital by default" principle and the once-only principle a reality, facilitating the growth and development of EU companies and enhancing their competitiveness. |
| 5 European Commission, Call for Evidence: 28th regime – a single harmonized set of rules for innovative companies throughout the EU, 8th of July, available at https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14674-28th-regime-a-single-harmonized-set-of-rules-for-innovative-companies-throughout-the-EU_en | 5 European Commission, Call for Evidence: 28th regime – a single harmonized set of rules for innovative companies throughout the EU, 8th of July, available at https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14674-28th-regime-a-single-harmonized-set-of-rules-for-innovative-companies-throughout-the-EU_en |
Amendment 10
Proposal for a regulation
Recital 14
| Text proposed by the Commission | Amendment |
|---|---|
| (14) Given the objective of creating a unified digital ecosystem for electronic identification, authentication, and the exchange of electronic documents, notifications, and attestations of attributes, the inclusion of Union entities among public sector bodies covered this Regulation, is necessary. Such an inclusion should create a coherent framework for owners of European Business Wallets to engage with all levels of public administration thereby reducing administrative complexities and driving uptake of the European Business Wallets. | (14) Given the objective of creating a unified and secure digital ecosystem for electronic identification, authentication, and the exchange of electronic documents, notifications, and attestations of attributes, the inclusion of Union entities among public sector bodies covered by this Regulation, is necessary. Such an inclusion should create a coherent framework for owners of European Business Wallets to engage with all levels of public administration thereby reducing administrative complexities and driving uptake of the European Business Wallets. |
Amendment 11
Proposal for a regulation
Recital 15
| Text proposed by the Commission | Amendment |
|---|---|
| (15) In order to ensure the proper issuance and integration of European Business Wallets throughout the operations and systems of Union entities, this Regulation should have due regard to the specific nature and structure of such institutions, bodies, offices and agencies. To ensure the respect of administrative autonomy and security of Union entities. They should be allowed to acquire European Business Wallets from already established providers of European Business Wallets, or develop their own European Business Wallets or act themselves as provider for Union entities. Where Union entities act as providers of European Business Wallets, they should also be subject to a supervisory framework. In such cases, the Commission should be tasked to the supervise the provision of European Business Wallets by Union entities. | (15) In order to ensure the proper issuance and integration of European Business Wallets throughout the operations and systems of Union entities, this Regulation should have due regard to the specific nature and structure of such institutions, bodies, offices and agencies. To ensure the respect of administrative autonomy and security of Union entities, they should be allowed to acquire European Business Wallets from already established providers of European Business Wallets, or develop their own European Business Wallets or act themselves as provider for Union entities. Where Union entities act as providers of European Business Wallets, they should also be subject to a supervisory framework. In such cases, the Commission should be tasked to the supervise the provision of European Business Wallets by Union entities. |
Amendment 12
Proposal for a regulation
Recital 15 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (15a) In order to ensure a high level of security, trust and resilience in the European Business Wallet ecosystem and safeguard the Union’s digital sovereignty, the storage and processing of data associated with European Business Wallets should take place on infrastructure located within the Union and subject to Union law. Ensuring that such infrastructure is located within the Union enables effective supervision by competent authorities and contributes to protecting sensitive business information while strengthening the Union’s capacity to provide secure and trustworthy digital services for economic operators and public sector bodies. |
Amendment 13
Proposal for a regulation
Recital 16
| Text proposed by the Commission | Amendment |
|---|---|
| (16) Regulation (EU) No 910/2014 established a framework for electronic identification and trust services in the internal market. Building on the ecosystem established by Regulation (EU) No 910/2014, the European Business Wallets should offer economic operators and public sector bodies a secure and reliable solution for digital identification and authentication, data sharing, and the delivery of legally valid notifications. The trust framework for European Business Wallets, including the use of trusted lists, should build upon the structures established under Regulation (EU) No 910/2014. | (16) Regulation (EU) No 910/2014 established a framework for electronic identification and trust services in the internal market. Building on the ecosystem established by Regulation (EU) No 910/2014, the European Business Wallets should offer economic operators and public sector bodies a secure and reliable solution for digital identification and authentication, data sharing, and the delivery of legally valid notifications. The trust framework for European Business Wallets, including the use of trusted lists, should build upon the structures established under Regulation (EU) No 910/2014. The identification and authentication within the European Business Wallets framework should rely on electronic attestations, issued by trusted entities, which attest to the identity, attributes or specific roles of a natural or legal person using those solutions and enable their verification in accordance with the requirements of this Regulation. |
Amendment 14
Proposal for a regulation
Recital 19
| Text proposed by the Commission | Amendment |
|---|---|
| (19) In order to facilitate the conduct of cross-border business transactions, reduce administrative burdens, and promote economic growth, it is necessary to establish a clear and predictable legal framework that recognises the legal equivalence between the use of the European Business Wallets, or their core functionalities and the secure communication channel where the latter is used by self-employed persons and sole traders, and other accepted methods for economic operators to identify, authenticate, submit documents and receive notifications when interacting with public sector bodies in the Union. To that end, the use of the core functionalities of a European Business Wallet, or the secure communication channel where the latter is used by self-employed persons and sole traders, should have the same legal effect as if lawfully carried out in person, in paper form, or via any other means or process that would otherwise be deemed compliant with applicable legal, administrative, or procedural requirements. | (19) In order to facilitate the conduct of cross-border business transactions, reduce administrative burdens, and promote economic growth, it is necessary to establish a clear and predictable legal framework that recognises the legal equivalence between the use of the European Business Wallets, or their core functionalities and the secure communication channel where the latter is used by self-employed persons and sole traders, and other accepted methods for economic operators to identify, authenticate, submit documents and receive notifications when interacting with public sector bodies in the Union. To that end, the use of the core functionalities of a European Business Wallet, or the secure communication channel where the latter is used by self-employed persons and sole traders, should have the same legal effect as if lawfully carried out in person, in paper form, or via any other means or process that would otherwise be deemed compliant with applicable legal, administrative, or procedural requirements. That legal equivalence should not be interpreted as requiring Member States or public sector bodies that have already transitioned to fully digital procedures to reintroduce or maintain paper-based or in-person alternatives, in line with the ‘digital-by-default’ principle and the objective of administrative simplification. |
Amendment 15
Proposal for a regulation
Recital 20
| Text proposed by the Commission | Amendment |
|---|---|
| (20) To ensure a consistent user experience and to guarantee the utility, reliability, and interoperability of European Business Wallets across the Union, providers of European Business Wallets should implement a core set of functionalities. They should retain the freedom to offer additional features as part of their commercial offering, fostering innovation and responding to market needs. In order to ensure uniform conditions for the development and use of the core functionalities, implementing powers should be conferred on the Commission to set out requirements and technical specifications necessary to ensure interoperability and seamless functioning across the Union. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council(7 ) and should include the powers to define the necessary standards and protocols for the secure communication channel, taking into account the latest technological developments. | (20) To ensure a consistent user experience and to guarantee the utility, reliability, and interoperability of European Business Wallets across the Union, providers of European Business Wallets should implement a core set of functionalities. They should retain the freedom to offer additional features as part of their commercial offering, fostering innovation and responding to market needs. In order to ensure uniform conditions for the development and use of the core functionalities, implementing powers should be conferred on the Commission to set out requirements and technical specifications necessary to ensure interoperability and seamless functioning across the Union. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council([1]) and should include the powers to define the necessary standards and protocols for the secure communication channel, taking into account the latest technological developments. Where European Business Wallets facilitate automated processes which do not require manual intervention or direct user action, those processes should be verifiable and auditable, and should ensure a level of assurance and accountability equivalent to actions performed by a user. |
| 7 Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by the Member States of the Commission's exercise of implementing powers (OJ L 55, 28.2.2011, p. 13, ELI: http://data.europa.eu/eli/reg/2011/182/oj). | 7 Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by the Member States of the Commission's exercise of implementing powers (OJ L 55, 28.2.2011, p. 13, ELI: http://data.europa.eu/eli/reg/2011/182/oj). |
Amendment 16
Proposal for a regulation
Recital 21
| Text proposed by the Commission | Amendment |
|---|---|
| (21) European Business Wallets should simplify the complex interactions between economic operators and public sector bodies, and could also facilitate interactions among economic operators themselves, reducing administrative burden on economic operators in a broad range of economic sectors. In order to foster innovation and competitiveness, the European Business Wallets should enable sector-specific use cases and enhance operational efficiencies, while ensuring flexibility and adaptability to support the unique requirements of different sectors, including, but not limited to, agriculture, energy, environment, social security coordination. | (21) European Business Wallets should simplify the complex interactions between economic operators and public sector bodies, and could also facilitate interactions among economic operators themselves, reducing administrative burden on economic operators in a broad range of economic sectors. In order to foster innovation and competitiveness, the European Business Wallets should enable sector-specific use cases and enhance operational efficiencies, while ensuring flexibility and adaptability to support the unique requirements of different sectors, including, but not limited to, agriculture, industry, energy, environment, social security coordination. |
Amendment 17
Proposal for a regulation
Recital 22
| Text proposed by the Commission | Amendment |
|---|---|
| (22) The use of the European Business Wallets in such contexts can aid in the reduction of costs and promote a wide range of applications and use cases across the Union, such as the submission of declarations, applications for public funding, access to public services and facilitating secure data sharing and access within data spaces, such as the submission of A1 certificates concerning posted workers provided for under Regulation (EU) 883/2004. | (22) The use of the European Business Wallets in such contexts can aid in the reduction of costs and promote a wide range of applications and use cases across the Union, such as the submission of declarations, applications for public funding, participation in public procurement procedures, access to public services and facilitating secure data sharing and access within data spaces, such as the submission of A1 certificates concerning posted workers provided for under Regulation (EU) 883/2004. European Business Wallets should also support interactions between economic operators and public authorities in the context of regulatory compliance and administrative procedures, including the secure submission, sharing and reuse of verified information required in particular for public procurement, tax and VAT-related procedures, electronic declarations and reporting obligations, in line with the once-only principle. |
Amendment 18
Proposal for a regulation
Recital 26
| Text proposed by the Commission | Amendment |
|---|---|
| (26) In order to ensure the secure and trustworthy operation of European Business Wallets, providers of European Business Wallets should ensure that each European Business Wallet they provide is pre-configured to interact with certain trust services, which are required to enable the core functionalities of European Business Wallets, including the creation of qualified electronic signatures, the creation of qualified electronic seals, and the issuance and validation of qualified and non-qualified electronic attestations of attributes. To support these functionalities, European Business Wallets should allow for the sharing and storage of specific information and documents relating to the owner, such as messages and documents for the secure communication channel, signed and sealed documents, and sets of attributes for attestation-related services. | (26) In order to ensure the secure and trustworthy operation of European Business Wallets, providers of European Business Wallets should ensure that each European Business Wallet they provide is pre-configured to interact with certain trust services, which are required to enable the core functionalities of European Business Wallets, including the creation of qualified electronic signatures, the creation of qualified electronic seals, and the issuance and validation of qualified and non-qualified electronic attestations of attributes. To support these functionalities, European Business Wallets should allow for the sharing, storage and verification of specific information and documents relating to the owner, such as messages and documents for the secure communication channel, signed and sealed documents, and sets of attributes for attestation-related services. |
Amendment 19
Proposal for a regulation
Recital 28
| Text proposed by the Commission | Amendment |
|---|---|
| (28) In order to ensure that the standards and technical specifications for European Business Wallets ensure harmonisation across various solutions, it is necessary to define the standards and protocols for the core functionalities and technical requirements for European Business Wallets in an Annex to this Regulation. The Annex should set out the requirements for the implementation of European Business Wallets. To ensure the long-term viability and effectiveness of the European Business Wallets, implementing powers should be conferred on the Commission to establish and update the procedures and technical specifications on the implementation of core functionalities, thereby allowing for the integration of additional features and new technologies that would enable new use cases, such as agentic AI or the provision of a digital identity to an owner’s asset, and enabling the European Business Wallets to continue to support the evolving needs of economic operators in a secure and trustworthy manner. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council. To the extent possible, the standards and technical specifications of the European Business Wallet should take into account relevant technical solutions and standards used by existing ICT systems by economic operators, facilitating the alignment of these systems to be aligned to and made interoperable with the European Business Wallet. | (28) In order to ensure that the standards and technical specifications for European Business Wallets ensure interoperability across various solutions, it is necessary to define the standards and protocols for the core functionalities and technical requirements for European Business Wallets in an Annex to this Regulation. The Annex should set out the requirements for the implementation of European Business Wallets. To ensure the long-term viability and effectiveness of the European Business Wallets, implementing powers should be conferred on the Commission to establish and update the procedures and technical specifications on the implementation of core functionalities, thereby allowing for the integration of additional features and new technologies that would enable new use cases, such as agentic AI or the provision of a digital identity to an owner’s asset, and enabling the European Business Wallets to continue to support the evolving needs of economic operators in a secure and trustworthy manner. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council. To the extent possible, the standards and technical specifications of the European Business Wallet should take into account relevant technical solutions and standards used by existing ICT systems by economic operators, facilitating the alignment of these systems to be aligned to and made interoperable with the European Business Wallet. For that purpose, the Commission should consult relevant stakeholders, including economic operators and industry representatives, to ensure that the standards and technical specifications are practical, reflect real-world use and support innovation. In order to ensure the timely development and deployment of European Business Wallets across the Union, those implementing acts should be adopted within a short period following the entry into force of this Regulation. |
Amendment 20
Proposal for a regulation
Recital 28 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (28a) The technical solutions and standards for European Business Wallets should make use of existing commonly used open source software and openly standardised formats and protocols, and should ensure interoperability and opportunities for European businesses by publishing open source reference implementations. Providers are encouraged to release the source code of the application software of European Business Wallets under an open source license. |
Amendment 21
Proposal for a regulation
Recital 29
| Text proposed by the Commission | Amendment |
|---|---|
| (29) To support the timely development of the market for European Business Wallets, the adoption of the implementing acts on core functionalities and the accompanying technical specifications should be prioritised. Where appropriate, these should build on the existing standards including those out in the Architecture and Reference Framework provided for in the context of Regulation (EU) No 910/2014, to support the re-use of familiar technical standards and uptake of the European Business Wallets. | (29) To support the timely development of the market for European Business Wallets, the adoption of the implementing acts on core functionalities and the accompanying technical specifications should be prioritised and completed within a short period following the entry into force of this Regulation in order to enable providers to develop compliant European Business Wallet solutions without undue delay. Where appropriate, these should build on the existing standards including those out in the Architecture and Reference Framework provided for in the context of Regulation (EU) No 910/2014, to support the re-use of familiar technical standards and uptake of the European Business Wallets. The adoption of those implementing acts should precede the large-scale deployment of European Business Wallets in order to ensure that providers and public sector bodies can rely on a stable and harmonised technical framework. |
Amendment 22
Proposal for a regulation
Recital 31
| Text proposed by the Commission | Amendment |
|---|---|
| (31) To ensure proper supervision in line with this Regulation, entities that would like to become providers of European Business Wallets should be required to notify their intention to provide such European Business Wallets to the supervisory bodies prior to offering their services. In order to safeguard the integrity and accountability of European Business Wallet providers and to ensure the security of data stored or exchanged in the European Business Wallets ecosystem, providers should be established within the Union. This should ensure that such providers fall under the jurisdiction and supervision of a competent body in a Member State, allowing for effective enforcement of this Regulation and the protection of users' rights and data. Furthermore, providers of European Business Wallets should not present a risk to the security of the Union, namely by not being subject to control by a third country or by a third-country entity, to ensure that the Union's critical digital infrastructure remains secure and resilient. In line with the requirements set out in this Regulation, the Commission may adopt implementing acts to ensure cooperation and interoperability with solutions established or endorsed by like-minded partners of the Union. | (31) To ensure proper supervision in line with this Regulation, entities that would like to become providers of European Business Wallets should be required to notify their intention to provide such European Business Wallets to the supervisory bodies prior to offering their services. In order to safeguard the integrity and accountability of European Business Wallet providers and to ensure the security of data stored or exchanged in the European Business Wallets ecosystem, providers should be established within the Union. This should ensure that such providers fall under the jurisdiction and supervision of a competent body in a Member State, allowing for effective enforcement of this Regulation and the protection of users' rights and data. Furthermore, providers of European Business Wallets should not present a risk to the security of the Union, namely by not being subject to control by a third country or by a third-country entity, to ensure that the Union's critical digital infrastructure remains secure and resilient. The concept of control should be understood in line with Regulation (EU) 2019/452, in particular having due regard to a company´s ownership structure and significant funding and the applicability of third country law that impact the jurisdiction over thecompany or its data. Ownership and governance of a provider of European Business Wallets should continue to be monitored by supervisory bodies for the entire duration that that provider provides a European Business Wallet. In line with the requirements set out in this Regulation, the Commission may adopt implementing acts to ensure cooperation and interoperability with solutions established or endorsed by like-minded partners of the Union. |
Amendment 23
Proposal for a regulation
Recital 34
| Text proposed by the Commission | Amendment |
|---|---|
| (34) This Regulation should not affect the functioning or the role of business registers as authentic sources and should not alter the way they operate or the data filed therein but rather build upon and complement the existing infrastructure. In this regard, where electronic attestations of attributes are issued by or on behalf of an authentic source, such as a business register, the register could directly issue the relevant data, further enhancing the security and reliability of the identification process. | (34) This Regulation should not affect the functioning or the role of business registers as authentic sources and should not alter the way they operate, including requirements with respect to form or the data filed therein but rather build upon and complement the existing infrastructure. In this regard, where electronic attestations of attributes are issued by or on behalf of an authentic source, such as a business register, the register could directly issue the relevant data, further enhancing the security and reliability of the identification process |
Amendment 24
Proposal for a regulation
Recital 36 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (36a) In order to ensure the effective functioning and widespread use of European Business Wallets, Member States should ensure that all companies and other legal entities, excluding natural persons acting in a business capacity, as well as public sector bodies established in their territory are attributed a European Unique Identifier within a short period following the entry into force of this Regulation. Such identifiers should, in particular, be assigned automatically at the time of registration of a company or other legal entity in a national register, and, where applicable, without delay for entities already registered. Where possible, such identifiers should be derived from or linked to identifiers already used in national registers, including company registers or other official registers, in order to ensure interoperability and avoid duplication. Member States should also ensure that companies or other legal entities that are not registered in national company registers can be attributed such identifiers through a competent national authority so that all economic operators are able to make effective use of European Business Wallets. The attribution of a European Unique Identifier should be done automatically, free of charge and without imposing additional administrative or procedural burdens on the companies and other legal entities concerned. |
Amendment 25
Proposal for a regulation
Recital 37
| Text proposed by the Commission | Amendment |
|---|---|
| (37) To ensure that all European Business Wallet owners can be reliably identified and their electronic attestation of attributes are associated with a unique entity, it is also necessary to assign a unique identifier to other economic operators and public sector bodies. To ensure uniform conditions for the implementation of unique identifiers, in particular their effectiveness and consistency, implementing powers should be conferred on the Commission to specify the detailed requirements for the unique identifiers. Those powers should be exercised in accordance with Regulation (EU) No 182/2011. Given the diverse approaches among Member States regarding the registration of some economic operators and public sector bodies, it is important to ensure transparency and accessibility for providers of European Business Wallet owner identification data. To this end, Member States should notify to the Commission the authentic sources that are relevant for the issuance of European Business Wallet owner identification data. | (37) To ensure that all European Business Wallet owners can be reliably identified and their electronic attestation of attributes are associated with a unique entity, it is also necessary to assign a European Unique Identifier to other economic operators and public sector bodies that do not yet have such an identifier under Union law. To ensure uniform conditions for the implementation of unique identifiers, in particular their effectiveness and consistency, implementing powers should be conferred on the Commission to specify the detailed requirements for the unique identifiers. Those powers should be exercised in accordance with Regulation (EU) No 182/2011. Given the diverse approaches among Member States regarding the registration of some economic operators and public sector bodies, it is important to ensure transparency and accessibility for providers of European Business Wallet owner identification data. To this end, Member States should notify to the Commission the authentic sources that are relevant for the issuance of European Business Wallet owner identification data. |
Amendment 26
Proposal for a regulation
Recital 37 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (37a) In order to reflect the organisational realities of economic operators operating in the internal market, the European Unique Identifier framework should be capable of accommodating complex business structures. Economic operators may operate through subsidiaries, branches, establishments or operational units that require distinct identification with respect to administrative procedures or digital transactions. The identifier framework should therefore allow for the association of identifiers with such entities while maintaining a clear link to the economic operator to which they belong. In addition, natural persons may act in different economic capacities, including as self-employed persons, entrepreneurs or representatives of legal entities; the framework should allow for the attribution of identifiers reflecting such different roles where that is necessary for the purposes of European Business Wallets. |
Amendment 27
Proposal for a regulation
Recital 38
| Text proposed by the Commission | Amendment |
|---|---|
| (38) In order to ensure the efficient, secure, and transparent functioning of the European Business Wallet framework, it is necessary to establish a European Digital Directory, that includes personal data of economic operators. The Commission should be empowered to set up and maintain this Directory, as a trusted source of information on economic operators and public sector bodies using European Business Wallets. The Directory should enable European Business Wallet owners to be easily contacted to promote legal certainty in relation to dealings between businesses and in relation to interactions with public sector bodies, particularly in the view of promoting trade between Member States. European Business Wallet Providers, liaising with the Commission, should submit the necessary information to support the functioning of the European Digital Directory and collaborate with the relevant qqualified trust service providers to ensure that the data submitted remains accurate. Such actions shall not indirectly create a requirement for economic operators to update such information. In this regard the Digital Directory will rely on the information made available by business registers also through BRIS while ensuring that such information will not be duplicated. | (38) In order to ensure the efficient, secure, and transparent functioning of the European Business Wallet framework, it is necessary to establish a European Digital Directory, that includes personal data of economic operators. The Commission should be empowered to set up and maintain this Directory, as a trusted source of information on economic operators and public sector bodies using European Business Wallets. The Directory should enable European Business Wallet owners to be easily contacted to promote legal certainty in relation to dealings between businesses and in relation to interactions with public sector bodies, particularly in the view of promoting trade between Member States. European Business Wallet Providers, liaising with the Commission, should submit the necessary information to support the functioning of the European Digital Directory and collaborate with the relevant qualified trust service providers to ensure that the data submitted remains accurate. Such actions shall not indirectly create a requirement for economic operators to update such information. In this regard the Digital Directory will rely on the information made available by business registers, including BRIS, while ensuring that such information will not be duplicated. |
Amendment 28
Proposal for a regulation
Recital 39
| Text proposed by the Commission | Amendment |
|---|---|
| (39) Regulation (EU) 2016/679 of the European Parliament and of the Council applies to all personal data processing activities under this Regulation. Where the European Digital Directory includes the processing of personal data this will be carried out in accordance with the relevant data protection principles, such as the data minimisation and purpose limitation principle, obligations, such as data protection by design and by default, and include, where appropriate, features of pseudonymisation. | (39) Regulations (EU) 2016/679 and (EU) 2018/1725 of the European Parliament and of the Council applies to all personal data processing activities under this Regulation. Where the European Digital Directory includes the processing of personal data this will be carried out through verifiable processing methods in accordance with the relevant data protection principles, such as the data minimisation and purpose limitation principle, obligations, such as data protection by design and by default, and include, where appropriate, features of pseudonymisation and anonymisation of data. |
Amendment 29
Proposal for a regulation
Recital 40
| Text proposed by the Commission | Amendment |
|---|---|
| (40) To avoid excessive regulatory burdens, ex post supervision of providers of European Business Wallets and monitoring of their activities should be provided for, rather than requiring prior compliance verification for every aspect of their operations. This approach should allow for a more flexible and efficient regulatory environment, while maintaining the necessary safeguards to protect users and ensure compliance with the requirements of the European Business Wallets framework. The notification process for providers of European Business Wallets should be streamlined and efficient, with clear requirements and timelines for applicants. Qualified trust service providers, which are already subject to a robust regulatory framework under Regulation (EU) No 910/2014, should benefit from a particularly light process to be able to provide European Business Wallets. | (40) To avoid regulatory burdens, ex post supervision of providers of European Business Wallets and monitoring of their activities should be provided for, rather than requiring prior compliance verification for every aspect of their operations. This approach should allow for a more flexible and efficient regulatory environment, while maintaining the necessary safeguards to protect users and ensure compliance with the requirements of the European Business Wallets framework. The notification process for providers of European Business Wallets should be streamlined and efficient, with clear requirements and timelines for applicants. Qualified trust service providers, which are already subject to a robust regulatory framework under Regulation (EU) No 910/2014, should benefit from a particularly light process to be able to provide European Business Wallets. |
Amendment 30
Proposal for a regulation
Recital 47
| Text proposed by the Commission | Amendment |
|---|---|
| (47) In order to support effective take-up and interoperability, all public sector bodies should be required to enable the use of the European Business Wallet in all relevant administrative procedures for the purposes of identification and authentication, signing or sealing documents, submitting documents and sending or receiving notifications. In this regard, public sector bodies should by [Publications Office, please insert the date 24 months after the entry into force of this Regulation] ensure that the use of European Business Wallets by economic operators is possible and that, where the receipt or communication of documents or notifications is concerned, they are able to access the Business Wallets’ secure communication channel. To ensure seamless and interoperable application of this Regulation in this regard, public sector bodies should own a European Business Wallet for the purposes of receiving or sending documents and notifications. The obligation for public sector bodies to accept European Business Wallets by economic operators should not affect systems used for the exchange or submission of documents or data between competent authorities. | (47) In order to support effective take-up and interoperability, all public sector bodies should be required to enable the use of the European Business Wallet in all relevant administrative procedures for the purposes of identification and authentication, signing or sealing documents, submitting documents and sending or receiving notifications. In this regard, public sector bodies should by [Publications Office, please insert the date 18 months after the entry into force of this Regulation] ensure that the use of European Business Wallets by economic operators is possible and that, where the receipt or communication of documents or notifications is concerned, they are able to access the Business Wallets’ secure communication channel. To ensure seamless and interoperable application of this Regulation in this regard, public sector bodies should own a European Business Wallet for the purposes of receiving or sending documents and notifications. However, while it is necessary for all public sector bodies to accept the usage of European Business Wallets, attention should be paid to the capacity of smaller public sector bodies to comply with that obligation. To ensure acceptability, Member States should ensure that there is adequate and appropriate support to smaller public sector bodies, including, where possible, that affordable European Business Wallets are available for use by such entities. The obligation for public sector bodies to accept European Business Wallets by economic operators should not affect systems used for the exchange or submission of documents or data between competent authorities. |
Amendment 31
Proposal for a regulation
Recital 48
| Text proposed by the Commission | Amendment |
|---|---|
| (48) In order to avoid disrupting existing interactions between economic operators and public sector bodies, it is necessary to enable a transition period until [Publications Office, please insert the date 36 months after the entry into force of this Regulation]. During such period public sector bodies may choose not to offer the European Business Wallets' secure communication channel and instead support alternative solutions already in place which enable economic operators to communicate with public sector bodies prior to offering the European Business Wallets’ secure communication channel. In order to ensure an adequate level of security and interoperability, any alternative solution used during this transition period should comply with the requirements for Qualified Electronic Registered Delivery Services set out in Regulation (EU) No 910/2014 and offer a gateway to European Business Wallets. The gateway should enable users of European Business Wallets to access the alternative solutions used during the transition period. After this period, public sector bodies should support the secure communication channel of the European Business Wallets to ensure a harmonised and efficient means of communication across the Union, to the benefits of European businesses. | (48) In order to avoid disrupting existing interactions between economic operators and public sector bodies, it is necessary to enable a transition period until [Publications Office, please insert the date 24 months after the entry into force of this Regulation]. During such period public sector bodies may choose not to offer the European Business Wallets' secure communication channel and instead support alternative solutions already in place which enable economic operators to communicate with public sector bodies prior to offering the European Business Wallets’ secure communication channel. In order to ensure an adequate level of security and interoperability, any alternative solution used during this transition period should comply with the requirements for Qualified Electronic Registered Delivery Services set out in Regulation (EU) No 910/2014 and offer a gateway to European Business Wallets. The gateway should enable users of European Business Wallets to access the alternative solutions used during the transition period. After this period, public sector bodies should support the secure communication channel of the European Business Wallets to ensure a harmonised and efficient means of communication across the Union, to the benefits of European businesses. |
Amendment 32
Proposal for a regulation
Recital 50
| Text proposed by the Commission | Amendment |
|---|---|
| (50) To ensure that the European Business Wallets ecosystem continues to meet the needs of economic operators and public sector bodies, it is necessary to assess its implementation and impact in light of the purpose of this Regulation. The evaluation should, in particular, take into account the risk of legal fragmentation within the internal market regarding the electronic submission of documents and attestations of attributes as well as the technological developments and progression of the market for European Business Wallets and associated trust services. | (50) To ensure that the European Business Wallets ecosystem continues to meet the needs of economic operators and public sector bodies, it is necessary to assess its implementation and impact in light of the purpose of this Regulation. The evaluation should, in particular, take into account the risk of legal fragmentation within the internal market regarding the electronic submission of documents and attestations of attributes as well as the technological developments and progression of the market for European Business Wallets and associated trust services. It should also assess the uptake of European Business Wallets by economic operators and public sector bodies, including the extent to which micro-undertakings and small and medium-sized undertakings make use of European Business Wallets, as well as the administrative and financial costs associated with their implementation and use. |
Amendment 33
Proposal for a regulation
Article 1 – paragraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| This Regulation enables secure digital identification and authentication, data sharing and legally valid notifications, reduces administrative burdens and compliance costs, and supports cross-border business and competitiveness. In particular, it: | This Regulation establishes harmonised rules on secure digital identification and authentication, data sharing and legally valid notifications in order to ensure effective and inclusive access to digital tools, facilitate the smooth functioning of the internal market and enhance the competitiveness of businesses across the Union, in particular micro-undertakings and small and medium-sized undertakings, self-employed persons and cross-border economic operators, by reducing, administrative burdens and compliance costs. In particular, it: |
Amendment 34
Proposal for a regulation
Article 1 – paragraph 1 – point 1
| Text proposed by the Commission | Amendment |
|---|---|
| (1) establishes a framework for the provision of European Business Wallets; | establishes a secure framework for the provision of European Business Wallets; |
Amendment 35
Proposal for a regulation
Article 1 – paragraph 1 – point 9
| Text proposed by the Commission | Amendment |
|---|---|
| (9) provides a framework for the recognition of third-country systems similar to the European Business Wallets and the issuance of European Business Wallets to third country economic operators. | (9) provides a framework for the recognition of third-country systems which offer a level of security and trustworthiness equivalent to the European Business Wallets and the issuance of European Business Wallets to third country economic operators |
Amendment 36
Proposal for a regulation
Article 3 – paragraph 1 – point 1 – paragraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| ‘European Business Wallet’ means a digital solution that allows European Business Wallet owners to securely store, manage, and present European Business Wallet owner identification data and electronic attestations of attributes to Business Wallet-relying parties and other entities using European Business Wallets and European Digital Identity Wallets for the following purposes: | ‘European Business Wallet’ means a digital solution that allows European Business Wallet owners to securely receive, store, manage, combine and present European Business Wallet owner identification data and electronic attestations of attributes to Business Wallet-relying parties and other entities using European Business Wallets and European Digital Identity Wallets for the following purposes: |
Amendment 37
Proposal for a regulation
Article 3 – paragraph 1 – point 4
| Text proposed by the Commission | Amendment |
|---|---|
| (4) ‘economic operator’ means any natural or legal person, or a group of such persons, including temporary associations of undertakings, acting in a commercial or professional capacity for purposes related to their trade, business, craft or profession; | (4) ‘economic operator’ means any natural or legal person, or a group of such persons, including temporary associations of undertakings, acting in a commercial, non-commercial or professional capacity for purposes related to their trade, business, craft or profession; |
Amendment 38
Proposal for a regulation
Article 3 – paragraph 1 – point 5
| Text proposed by the Commission | Amendment |
|---|---|
| (5) ‘public sector body’ means a Union entity, a national, state, regional or local authority, a body governed by public law or an association formed by one or several such entities or bodies , or a private entity mandated by at least one such entities, authorities, bodies or associations to provide public services, when acting under such a mandate; | (5) ‘public sector body’ means a Union entity, a national, state, regional or local authority, a body governed by public law or an association formed by one or several such entities or bodies , or a private entity mandated by such entities, authorities, bodies or associations to provide public services, when acting under such a mandate; |
Amendment 39
Proposal for a regulation
Article 3 – paragraph 1 – point 17
| Text proposed by the Commission | Amendment |
|---|---|
| (17) ‘qualified electronic stamp’ means a qualified electronic stamp as defined in Article 3, point (34) of Regulation (EU) No 910/2014; | (17) ‘qualified electronic time stamp’ means a qualified electronic time stamp as defined in Article 3, point (34) of Regulation (EU) No 910/2014; |
Amendment 40
Proposal for a regulation
Article 5 – paragraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Providers of European Business Wallets shall ensure that the European Business Wallets they provide enable European Business Wallet owners to make use of the following core functionalities: | 1. Providers of European Business Wallets shall ensure that the European Business Wallets they provide enable European Business Wallet owners to make use of the following core functionalities, allowing users to utilise any combination of those features at their own discretion: |
Amendment 41
Proposal for a regulation
Article 5 – paragraph 1 – point j
| Text proposed by the Commission | Amendment |
|---|---|
| (j) authorise multiple users to access and operate the European Business Wallet of the owner, and for the European Business Wallet owner to manage and revoke such authorisations; | (j) authorise multiple users to access and operate the European Business Wallet of the owner, including by creating transparent and clearly defined delegations of powers, mandates and roles, and for the European Business Wallet owner to manage and revoke such authorisations; |
Amendment 42
Proposal for a regulation
Article 5 – paragraph 1 – point j a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (ja) enable the European Business Wallet owner, carrying out multiple economic activities and their authorised representatives, to act in different roles or mandates within the same European Business Wallet while ensuring a clear attribution of actions and appropriate logical separation between such roles, mandates or activities; |
Amendment 43
Proposal for a regulation
Article 5 – paragraph 1 – point l
| Text proposed by the Commission | Amendment |
|---|---|
| (l) export their data, including issued European Business Wallet owner identification data, electronic attestations of attributes, communication logs, and interaction records, in a structured, commonly used and machine-readable format, at the request of the owner or in the event of termination of service or revocation of the notification of the provider of the European Business Wallet; | (l) export their data, including issued European Business Wallet owner identification data, electronic attestations of attributes, communication logs, and interaction records, in a structured, commonly used and machine-readable format which shall facilitate machine translation of that data, at the request of the owner or in the event of termination of service or revocation of the notification of the provider of the European Business Wallet; |
Amendment 44
Proposal for a regulation
Article 5 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Providers of European Business Wallets may offer additional functionalities beyond those listed in paragraph 1 provided that such functionalities do not interfere with or compromise the confidentiality, availability, or integrity of the minimum core functionalities, and the reliability and interoperability of the European Business Wallets they provide. | 2. Providers of European Business Wallets may offer additional functionalities beyond those listed in paragraph 1 provided that such functionalities do not interfere with or compromise the confidentiality, availability, security or integrity of the minimum core functionalities, and the reliability and interoperability of the European Business Wallets they provide. |
Amendment 45
Proposal for a regulation
Article 5 – paragraph 4
| Text proposed by the Commission | Amendment |
|---|---|
| 4. Providers of European Business Wallets shall implement the functionalities referred to in paragraph 1 in accordance with requirements set out in the Annex. | 4. Providers of European Business Wallets shall implement the functionalities referred to in paragraph 1 in accordance with the requirements set out in the Annex. |
Amendment 46
Proposal for a regulation
Article 5 – paragraph 5
| Text proposed by the Commission | Amendment |
|---|---|
| 5. The Commission shall, by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the core functionalities of European Business Wallets referred to in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 5. The Commission shall no later than ... [OJ, please insert the date six months after the date of the entry into force of this Regulation], by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the core functionalities of European Business Wallets, including those critical for interoperability and security, referred to in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Amendment 47
Proposal for a regulation
Article 6 – paragraph 2 – point a
| Text proposed by the Commission | Amendment |
|---|---|
| (a) ensure that the European Business Wallet owner identification data is digitally associated with the European Business Wallet of the owner; | (a) ensure that the European Business Wallet owner identification data is securely and reliably attributed to the European Business Wallet of the owner; |
Amendment 48
Proposal for a regulation
Article 6 – paragraph 2 – point c a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (ca) ensure that, for the purposes of the functionality referred to in Article 5(1), point (l), European Business Wallet owners are able to exercise data portability through appropriate and secure mechanisms; |
Amendment 49
Proposal for a regulation
Article 6 – paragraph 2 – point e a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) provide a mechanism ensuring that the access to European Business Wallets and their functionalities is controlled and auditable; |
Amendment 50
Proposal for a regulation
Article 6 – paragraph 2 – point f
| Text proposed by the Commission | Amendment |
|---|---|
| (f) where the provider of the European Business Wallet is not included in the list referred to in Article 12(5). | (f) where the provider of the European Business Wallet is not included in the list referred to in Article 12(3). |
Amendment 51
Proposal for a regulation
Article 6 – paragraph 5
| Text proposed by the Commission | Amendment |
|---|---|
| 5. The Commission shall, by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the technical features of European Business Wallets provided for in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 5. The Commission shall no later than ... [OJ, please insert the date six months after the date of the entry into force of this Regulation], by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the technical features of European Business Wallets, including those critical for interoperability and security, provided for in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Amendment 52
Proposal for a regulation
Article 6 – paragraph 5 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 5a. Providers of European Business Wallets shall ensure that the storage and processing of data associated with European Business Wallets takes place on infrastructure located within the Union and subject to Union law. Such infrastructure shall be established and structured in a way that ensures that competent supervisory authorities within the Union are able to exercise effective oversight and enforcement in accordance with this Regulation. |
Amendment 53
Proposal for a regulation
Article 7 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. European Business Wallets shall be provided by providers of European Business Wallets that are included in the list established pursuant to Article 12(5). | 1. European Business Wallets shall be provided by providers of European Business Wallets that are included in the list established pursuant to Article 12(3). |
Amendment 54
Proposal for a regulation
Article 7 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Given the role of European Business Wallets in the Unions digital infrastructure, providers of European Business Wallets shall be established in the Union, have their principal place of business and main operations in the Union and not present a risk to the security of the Union. In particular they shall not be subject to control by a third country or by a third-country entity. | 2. Given the role of European Business Wallets in the Unions digital infrastructure, providers of European Business Wallets shall be established in the Union, have their principal place of business and main operations in the Union and not present a risk to the security of the Union. In particular they shall not be subject to control by a third country or by a third-country entity. Providers established in the Union and granted status as qualified trust service providers under Regulation (EU) No 910/2014 shall be eligible to provide European Business Wallet services. |
Amendment 55
Proposal for a regulation
Article 7 – paragraph 6 – point a
| Text proposed by the Commission | Amendment |
|---|---|
| (a) implement appropriate technical and organisational measures to ensure the confidentiality, integrity, authenticity, interoperability, and availability of the European Business Wallets they provide with other European Business Wallets and European Digital Identity Wallets; | (a) implement appropriate technical and organisational measures to ensure the confidentiality, integrity, authenticity, interoperability, security and availability of the European Business Wallets they provide with other European Business Wallets and European Digital Identity Wallets; |
Amendment 56
Proposal for a regulation
Article 7 – paragraph 6 – point b
| Text proposed by the Commission | Amendment |
|---|---|
| (b) ensure that European Business Wallet owners are clearly informed, in a user-friendly, concise and accessible manner, about the terms and conditions of use of the European Business Wallet, including the scope and limitations of core and additional functionalities, cybersecurity standards, and the European Business Wallet owner’s rights with regard to data portability, redress, and termination of service; | (b) ensure that European Business Wallet owners are clearly informed, in a user-friendly, concise and accessible manner, about the terms and conditions of use of the European Business Wallet and about any changes to those terms and conditions, including the scope and limitations of core and additional functionalities, cybersecurity standards, and the European Business Wallet owner’s rights with regard to data portability, redress, and termination of service; |
Amendment 57
Proposal for a regulation
Article 8 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Providers of European Business Wallet owner identification data shall issue European Business Wallet owner identification data to European Business Wallets of European Business Wallet owners. Where European Business Wallet owners are Union entities, the Commission shall issue European Business Wallet owner identification data to the European Business Wallets of those Union entities. | 1. Providers of European Business Wallet owner identification data shall issue European Business Wallet owner identification data to European Business Wallets of European Business Wallet owners. Where European Business Wallet owners are Union entities, the Commission shall issue European Business Wallet owner identification data to the European Business Wallets of those Union entities. Where European Business Wallet owners are natural persons carrying out more than one economic activity, it shall be possible for such natural persons to request the issuance of separate European Business Wallet owner identification data for each economic activity. |
Amendment 58
Proposal for a regulation
Article 8 – paragraph 7
| Text proposed by the Commission | Amendment |
|---|---|
| 7. The Commission may, by means of implementing acts, set out requirements for European Business Wallet owner identification data issued pursuant to this Article, including procedures for Member States to notify to the Commission the relevant authentic sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 7. The Commission shall no later than ... [OJ, please insert the date six months after the date of the entry into force of this Regulation], by means of implementing acts, set out requirements for European Business Wallet owner identification data issued pursuant to this Article, including procedures for Member States to notify to the Commission the relevant authentic sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Amendment 59
Proposal for a regulation
Article 9 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Where an economic operator has been attributed a European Unique Identifier, that identifier shall be used as the unique identifier referred to in Article 8(4), point (b) of this Regulation. | 1. Member States shall ensure that all companies and other legal entities, as well as public sector bodies, established in their territory are attributed a European Unique Identifier no later than ... [OJ, please insert the date six months after the date of the entry into force of this Regulation]. Natural persons acting in a business capacity, including self-employed persons and sole traders, shall not be required to obtain a European Unique Identifier under this Regulation. Where an economic operator has been attributed a European Unique Identifier, including under Directive (EU) 2017/1132, that identifier shall be used as the unique identifier referred to in Article 8(4), point (b) of this Regulation. |
Amendment 60
Proposal for a regulation
Article 9 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Where an economic operator or public sector body has not been attributed a European Unique Identifier, a unique identifier shall be created in accordance with the implementing act referred to in paragraph 4. | 2. The European Unique Identifier shall be assigned automatically and simultaneously with the registration of a company or other legal entity in a national register. Where possible, the European Unique Identifier shall be derived from or linked to identifiers used in national registers, including company registers, tax registers or other official registers. Member States shall ensure that economic operators that are not registered in a national company register are attributed a European Unique Identifier through a competent national authority designated for that purpose. The attribution of a European Unique Identifier shall be done free of charge and without requiring any additional application, registration or administrative procedure on the part of the company or other legal entity concerned. |
Amendment 61
Proposal for a regulation
Article 9 – paragraph 4
| Text proposed by the Commission | Amendment |
|---|---|
| 4. The Commission shall, by means of implementing acts, establish specifications, requirements and procedures relating to the unique identifier referred to in paragraph 2 of this Article, including measures to ensure that European Business Wallet owners are not attributed more than one unique identifier. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 4. The Commission shall, by means of implementing acts, establish specifications, requirements and procedures relating to the unique identifier referred to in paragraph 2 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Amendment 62
Proposal for a regulation
Article 9 – paragraph 4 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 4a. The identifier framework established under this Article shall support the identification of subsidiaries, branches, establishments or other operational units of economic operators where that is required for administrative procedures or digital transactions. It shall also allow natural persons engaged in more than one economic activity to have different identifiers reflecting their distinct economic roles. |
Amendment 63
Proposal for a regulation
Article 10 – paragraph 1 – point b
| Text proposed by the Commission | Amendment |
|---|---|
| (b) a secure, web-based platform that provides access to authenticated and authorised users and system online portal for European Business Wallet users. | (b) a secure, web-based platform that provides access to authenticated and authorised users through an online portal for European Business Wallet users. |
Amendment 64
Proposal for a regulation
Article 10 – paragraph 6
| Text proposed by the Commission | Amendment |
|---|---|
| 6. The Commission shall, by means of implementing acts, establish standards and technical specifications for the unique digital addresses and the categories of information to be communicated to the Commission for the purpose of the European Digital Directory. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 6. The Commission shall no later than ... [OJ, please insert the date six months after the date of the entry into force of this Regulation], by means of implementing acts, establish standards and technical specifications for the unique digital addresses and the categories of information to be communicated to the Commission for the purpose of the European Digital Directory. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Amendment 65
Proposal for a regulation
Article 11 – paragraph 4 – subparagraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| When that review leads the supervisory body to conclude that the information is complete and the description referred to in paragraph 2 point (c) appears to correspond to the requirements laid down in Article 5(1), it shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(5). | When that review leads the supervisory body to conclude that the information is complete and the description referred to in paragraph 2 point (c) corresponds to the requirements laid down in Article 5(1), it shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12( 3 ). |
Amendment 66
Proposal for a regulation
Article 11 – paragraph 5
| Text proposed by the Commission | Amendment |
|---|---|
| 5. When that review leads the supervisory body to conclude that the information is not complete or the description referred to in paragraph 2 point (c) appears not to correspond to the requirements laid down in Article 5(1), it shall request additional information or explanations from the notifying entity and set a reasonable deadline, not exceeding 15 calendar days, for response. If that information or those explanations allow the supervisory body to conclude that the information is complete and the description referred to in paragraph 2 point (c) appears to correspond to the requirements laid down in Article 5(1), it shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(5). If not, or no response is received, the supervisory body shall inform the notifying entity that it will not be added to the list referred to in Article 12(5). | 5. When that review leads the supervisory body to conclude that the information is not complete or the description referred to in paragraph 2 point (c) does not correspond to the requirements laid down in Article 5(1), it shall request additional information or explanations from the notifying entity and set a reasonable deadline, not exceeding 15 calendar days, for response. If that information or those explanations allow the supervisory body to conclude that the information is complete and the description referred to in paragraph 2 point (c) corresponds to the requirements laid down in Article 5(1), it shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(3 ). If not, or no response is received, the supervisory body shall inform the notifying entity that it will not be added to the list referred to in Article 12(3 ). |
Amendment 67
Proposal for a regulation
Article 11 – paragraph 6
| Text proposed by the Commission | Amendment |
|---|---|
| 6. Where the supervisory body has not provided the notifying entity with a substantive response on the outcome of the review referred to in paragraph 4 within 30 calendar days of receiving the notification, the information shall be considered as complete and the description referred to in paragraph 2 point (c) shall be considered as appearing to correspond to the requirements laid down in Article 5(1), and the supervisory body shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(5) | 6. Where the supervisory body has not provided the notifying entity with a substantive response on the outcome of the review referred to in paragraph 4 within 30 calendar days of receiving the notification, the information shall be considered as complete and the description referred to in paragraph 2 point (c) shall be considered to correspond to the requirements laid down in Article 5(1), and the supervisory body shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(3 ). |
Amendment 68
Proposal for a regulation
Article 12 – paragraph 2 – point a – indent 1
| Text proposed by the Commission | Amendment |
|---|---|
| – the registration of a notified provider of European Business Wallets not previously present on the list referred to in paragraph 5; | – the registration of a notified provider of European Business Wallets not previously present on the list referred to in paragraph 3; |
Amendment 69
Proposal for a regulation
Article 12 – paragraph 2 – point a – indent 2
| Text proposed by the Commission | Amendment |
|---|---|
| – a change to previously submitted information regarding providers of European Business Wallets currently present on the list referred to in paragraph 5; | – a change to previously submitted information regarding providers of European Business Wallets currently present on the list referred to in paragraph 3; |
Amendment 70
Proposal for a regulation
Article 12 – paragraph 2 – point a – indent 3
| Text proposed by the Commission | Amendment |
|---|---|
| – a request to remove a provider of European Business Wallets from the list referred to in paragraph 5; | – a request to remove a provider of European Business Wallets from the list referred to in paragraph 3; |
Amendment 71
Proposal for a regulation
Article 13 – paragraph 5 – point f
| Text proposed by the Commission | Amendment |
|---|---|
| (f) inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant security breach or loss of integrity of which it becomes aware in the performance of its tasks and, in the case of a significant security breach or loss of integrity which concerns other Member States, to inform the single point of contact designated or established pursuant to Article 8(3) Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of Regulation (EU) No 910/2014 in the other Member States concerned, and to inform the public or require the provider of European Business Wallets to do so where the supervisory body determines that disclosure of the breach of security or loss of integrity would be in the public interest; | (f) without undue delay inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant security breach or loss of integrity of which it becomes aware in the performance of its tasks and, in the case of a significant security incident, breach or loss of integrity which concerns other Member States, to without undue delay inform the single point of contact designated or established pursuant to Article 8(3) Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of Regulation (EU) No 910/2014 in the other Member States concerned, and to inform the public or require the provider of European Business Wallets to do so where the supervisory body determines that disclosure of the breach of security or loss of integrity would be in the public interest; |
Amendment 72
Proposal for a regulation
Article 13 – paragraph 5 – point k
| Text proposed by the Commission | Amendment |
|---|---|
| (k) revoke the inclusion in the list established pursuant to Article 12(5) of a provider of European Business Wallets if the supervisory body determines that the provider no longer meets the requirements laid down in this Regulation or that the provider has failed to comply with the obligations imposed by this Regulation; | (k) revoke the inclusion in the list established pursuant to Article 12(3) of a provider of European Business Wallets if the supervisory body determines that the provider no longer meets the requirements laid down in this Regulation or that the provider has failed to comply with the obligations imposed by this Regulation; |
Amendment 73
Proposal for a regulation
Article 13 – paragraph 7
| Text proposed by the Commission | Amendment |
|---|---|
| 7. By [Publications Office, insert the date 12 months after the entry into force of this Regulation] Member States shall notify the Commission of the rules laid down by Member States in accordance with paragraph 6 and shall notify the Commission without delay of any subsequent amendments to the rules. The Commission shall regularly update and maintain an easily accessible public register of those rules. | 7. By [Publications Office, insert the date 12 months after the entry into force of this Regulation] Member States shall notify the Commission of the rules laid down by Member States in accordance with paragraph 6 and shall notify the Commission without undue delay of any subsequent amendments to the rules. The Commission shall regularly update and maintain an easily accessible public register of those rules. |
Amendment 74
Proposal for a regulation
Article 13 – paragraph 9
| Text proposed by the Commission | Amendment |
|---|---|
| 9. Where the legal system of a Member State does not provide for administrative fines being imposed by administrative authorities, fines initiated by the supervisory body and imposed by competent national courts, which have an equivalent effect to the administrative fines imposed by supervisory bodies, shall be considered to comply with the requirements laid down in paragraph 6. In any event, the fines imposed shall be effective, proportionate and dissuasive. That Member State shall notify to the Commission the provisions of the laws which it adopts pursuant to this paragraph by [Publications Office, insert the date 12 months after the entry into force of this Regulation] and, without delay, any subsequent amendment law or amendment affecting them. | 9. Where the legal system of a Member State does not provide for administrative fines being imposed by administrative authorities, fines initiated by the supervisory body and imposed by competent national courts, which have an equivalent effect to the administrative fines imposed by supervisory bodies, shall be considered to comply with the requirements laid down in paragraph 6. In any event, the fines imposed shall be effective, proportionate and dissuasive. That Member State shall notify to the Commission the provisions of the laws which it adopts pursuant to this paragraph by [Publications Office, insert the date 12 months after the entry into force of this Regulation] and, without undue delay, any subsequent amendment law or amendment affecting them. |
Amendment 75
Proposal for a regulation
Article 15 – paragraph 3 – subparagraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| When acting as a supervisory body in accordance with paragraph 1, the Commission shall perform the tasks referred to in Article 13(5) points a, b, c, d, h and k. | When acting as a supervisory body in accordance with paragraph 1, the Commission shall perform the tasks referred to in Article 13(5) points a, b, c, d, g, h and k. |
Amendment 76
Proposal for a regulation
Article 16 – paragraph 1 – subparagraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| By [Publications Office, please insert the date 24 months after the entry into force of this Regulation] public sector bodies shall enable economic operators to take the following actions by using the core functionalities of European Business Wallets as set out in Article 5(1): | By [Publications Office, please insert the date 18 months after the entry into force of this Regulation] public sector bodies shall enable economic operators to take the following actions by using the core functionalities of European Business Wallets as set out in Article 5(1): |
Amendment 77
Proposal for a regulation
Article 16 – paragraph 1a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (1a) Member States shall provide support to smaller public sector bodies to ensure that they have the capacity to enable economic operators to take the actions listed in paragraph 1 and, where possible, shall ensure the availability of European Business Wallets for use by smaller public sector bodies at an affordable cost. |
Amendment 78
Proposal for a regulation
Article 16 – paragraph 3 – subparagraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| By way of derogation from paragraph 2 and until [Publications Office, insert the date 36 months after entry into force of this Regulation], public sector bodies may choose not to offer the qualified electronic registered delivery service referred to in Article 5(1), point (i), and support instead other existing alternative solutions which enable economic operators to take the actions listed in paragraph 1, points (c) and (d), provided those solutions: | By way of derogation from paragraph 2 and until [Publications Office, insert the date 24 months after entry into force of this Regulation], public sector bodies may choose not to offer the qualified electronic registered delivery service referred to in Article 5(1), point (i), and support instead other existing alternative solutions which enable economic operators to take the actions listed in paragraph 1, points (c) and (d), provided those solutions: |
Amendment 79
Proposal for a regulation
Article 16 – paragraph 3 (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (3a) Member States shall ensure that micro-undertakings and small and medium-sized undertakings and self-employed persons receive adequate support in the uptake and use of European Business Wallets. Such support shall include access to appropriate technical assistance, guidance and, where relevant, financial support mechanisms. Member states shall also ensure that the conditions for access to and use of European Business Wallets are proportionate and do not impose disproportionate costs or administrative burden on micro-undertakings and small and medium-sized undertakings and self-employed persons. |
Amendment 80
Proposal for a regulation
Article 17 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The Commission may adopt implementing acts establishing that business wallets or systems offering similar functions that are issued by providers established in third countries are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that such business wallets or systems are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 1. The Commission may adopt implementing acts establishing that business wallets or systems offering similar functions that are issued by providers established in third countries are to be considered as equivalent to European Business Wallets issued in accordance with this Regulation, provided that such business wallets or systems are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Amendment 81
Proposal for a regulation
Article 17 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The Commission may adopt implementing acts establishing that third country frameworks for systems offering similar functions as the European Business Wallets are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that the systems provided under that framework are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 2. The Commission may adopt implementing acts establishing that third country frameworks for systems offering similar functions as the European Business Wallets are to be considered as equivalent to European Business Wallets issued in accordance with this Regulation, provided that the systems provided under that framework are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Amendment 82
Proposal for a regulation
Article 17 – paragraph 3
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Prior to the adoption of the implementing acts referred to in paragraphs 1 and 2, the Commission shall assess whether the assurances can be considered as equivalent to the requirements under this Regulation. | 3. Prior to the adoption of the implementing acts referred to in paragraphs 1 and 2, the Commission shall carry out a thorough assessment of the business wallets or systems offering similar functions that are issued by providers established in third countries, assessing especially the equivalence of cybersecurity and data protection standards, and the independence of the providers or systems from the control of high-risk entities or third countries. |
Amendment 83
Proposal for a regulation
Article 17 – paragraph 4
| Text proposed by the Commission | Amendment |
|---|---|
| 4. The Commission shall, where available information reveals that those assurances can no longer be considered as equivalent to the requirements under this Regulation, to the extent necessary, repeal, amend or suspend the act referred to in paragraphs 1 and 2 by means of an implementing act. | 4. The Commission shall, where available information reveals that those business wallets or systems can no longer be considered as equivalent to the requirements under this Regulation, without undue delay and to the extent necessary, repeal, amend or suspend the act referred to in paragraphs 1 and 2 by means of an implementing act. |
Amendment 84
Proposal for a regulation
Article 18 – paragraph 6 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 6a. As part of the implementing acts referred to in Articles 8(7) and 9(4), the Commission shall establish standards and technical specifications for issuing European Business Wallet owner identification data, including unique identifiers, to economic operators established outside the Union. |
Amendment 85
Proposal for a regulation
Article 21 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The Commission shall review the application of this Regulation and shall, by [Publications Office, insert the date – 3 years after entry into force], submit a report to the European Parliament and to the Council. The report shall evaluate the effectiveness of the provisions of this Regulation with regard to facilitating the submission of electronic documents and electronic attestations to public sector bodies, by the usage of the European Business Wallets, as well as technological, market, and legal developments. The report shall also assess whether it is necessary to modify the scope of this Regulation or its specific provisions to set out an obligation for the use of the European Business Wallets to address the risks of legal fragmentation. | 1. The Commission shall review the application of this Regulation and shall, by [Publications Office, insert the date – 3 years after entry into force], submit a report to the European Parliament and to the Council. The report shall evaluate the effectiveness of the provisions of this Regulation with regard to facilitating the submission of electronic documents and electronic attestations to public sector bodies, by the usage of the European Business Wallets, as well as technological, market, and legal developments and shall, where available, include information on time and cost savings, as well as the level of uptake of European Business Wallets by all economic operators, in particular micro-undertakings and small and medium-sized undertakings, and the administrative and financial costs associated with their implementation and use. The report shall also assess whether it is necessary to modify the scope of this Regulation or its specific provisions to set out an obligation for the use of the European Business Wallets to address the risks of legal fragmentation. |
Annex: declaration of input 4 paragraphs
Pursuant to Article 8 of Annex I to the Rules of Procedure, the rapporteur for opinion declares that he included in his opinion input on matters pertaining to the subject of the file that he received, in the preparation of the opinion, prior to the adoption thereof in committee, from the following interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from the following representatives of public authorities of third countries, including their diplomatic missions and embassies:
| 1. Interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register |
| Bitkom e.V. - Transparency Register: 5351830264-31 |
| Bundesnotarkammer - Transparency Register: 74591581960-65 |
| Cigref - Transparency Register: 252197741755-66 |
| DATEV eG - Transparency Register: 5027241291-41 |
| DIGITALEUROPE - Transparency Register: 64270747023-20 |
| European Banking Federation - Transparency Register: 4722660838-23 |
| Hanbury Strategy and Communications Limited - Transparency Register: 884060637263-03 |
| Kamer van Koophandel Nederland - Transparency Register: 254902496827-41 |
| LA POSTE - Transparency Register: 01890906437-84 |
| Namirial S.p.A. - Transparency Register: 634705549512-92 |
| NOVE - Transparency Register: 522122412613-18 |
| SAGE Group - Transparency Register: 086894649381-50 |
| SMEunited aisbl - Transparency Register: 55820581197-35 |
| Wolt - Transparency Register: 987241938472-54 |
| 2. Representatives of public authorities of third countries, including their diplomatic missions and embassies |
The list above is drawn up under the exclusive responsibility of the rapporteur for opinion.
Where natural persons are identified in the list by their name, by their function or by both, the rapporteur for opinion declares that he has submitted to the natural persons concerned the European Parliament's Data Protection Notice No 484 (https://www.europarl.europa.eu/data-protect/index.do), which sets out the conditions applicable to the processing of their personal data and the rights linked to that processing.
Annex: declaration of input 4 paragraphs
Pursuant to Article 8 of Annex I to the Rules of Procedure, the rapporteur for opinion declares that she included in her opinion input on matters pertaining to the subject of the file that she received, in the preparation of the opinion, from the following interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from the following representatives of public authorities of third countries, including their diplomatic missions and embassies:
| 1. Interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register |
| Digital Europe |
| Sage Group |
| Association of Finnish Local and Regional Authorities |
| 2. Representatives of public authorities of third countries, including their diplomatic missions and embassies |
| Permanent representation of the Slovak Republic to the EU |
| Permanent representation of the Czech Republic to the EU |
The list above is drawn up under the exclusive responsibility of the rapporteur for opinion.
Where natural persons are identified in the list by their name, by their function or by both, the rapporteur for opinion declares that she has submitted to the natural persons concerned the European Parliament's Data Protection Notice No 484 (https://www.europarl.europa.eu/data-protect/index.do), which sets out the conditions applicable to the processing of their personal data and the rights linked to that processing.
Procedure pages
How the committees handled the text, and how their members voted on it.
Procedure – committee asked for opinion 1 paragraph
| Title | Establishment of European Business Wallets | ||
| References | COM(2025)0838 – C10-0305/2025 – 2025/0358(COD) | ||
| Committee(s) responsible Date announced in plenary | ITRE 19.1.2026 | ||
| Opinion by Date announced in plenary | JURI 19.1.2026 | ||
| Rapporteur for opinion Date appointed | Axel Voss 12.1.2026 | ||
| Discussed in committee | 24.2.2026 | 15.4.2026 | 4.5.2026 |
| Date adopted | 3.6.2026 | ||
| Result of final vote | +: –: 0: | 19 3 0 |
Final vote by roll call by the committee asked for opinion 3 paragraphs
19 · For
- ESN
- Mary Khan
- EPP
- Maravillas Abadía Jover, Daniel Buda, Emil Radev, Axel Voss, Adrián Vázquez Lázara, Marion Walsmann, Michał Wawrykiewicz
- Renew
- Ilhan Kyuchyuk, Lukas Sieper, Dainius Žalimas
- S&D
- Delara Burkhardt, Marit Maij, René Repasi, Krzysztof Śmiszek, Tiemo Wölken
- The Left
- Arash Saeidi
- Greens
- David Cormand, Sergey Lagodinsky
3 · Against
- Patriots
- Jorge Buxadé Villalba, Ton Diepeveen, Elisabeth Dieringer
0 · Abstained
Procedure – committee asked for opinion 1 paragraph
| Title | Establishment of European Business Wallets | |
| References | COM(2025)0838 – C10-0305/2025 – 2025/0358(COD) | |
| Committee(s) responsible Date announced in plenary | ITRE 19.1.2026 | |
| Opinion by Date announced in plenary | IMCO 19.1.2026 | |
| Rapporteur for opinion Date appointed | Veronika Cifrová Ostrihoňová 16.2.2026 | |
| Discussed in committee | 15.4.2026 | 7.5.2026 |
| Date adopted | 2.6.2026 | |
| Result of final vote | +: –: 0: | 41 4 0 |
Final vote by roll call by the committee asked for opinion 3 paragraphs
41 · For
- ECR
- Stefano Cavedagna, Piotr Müller, Denis Nesci, Gheorghe Piperea, Reinis Pozņaks, Ivaylo Valchev
- EPP
- Peter Agius, Pablo Arias Echeverría, Sebastião Bugalho, Henrik Dahl, Dóra Dávid, Christian Doleschal, Kamila Gasiuk-Pihowicz, Seán Kelly, Arba Kokalari, Andreas Schwab, Tomislav Sokol, Dimitris Tsiodras, Inese Vaidere, Axel Voss
- Patriots
- Jaroslav Bžoch, Klara Dostalova, Ernő Schaller-Baross
- Renew
- Sandro Gozi, Svenja Hahn, Anna-Maja Henriksson, Cynthia Ní Mhurchú
- S&D
- Marc Angel, Laura Ballarín Cereza, Katarina Barley, Biljana Borzan, Adnan Dibrani, Maria Grapini, Elisabeth Grossmann, Maria Guzenina, Pierre Jouvet, Christel Schaldemose
- The Left
- Gaetano Pedulla'
- Greens
- Anna Cavazzini, David Cormand, Kim Van Sparrentak
4 · Against
- ESN
- Arno Bausemer, Milan Mazurek
- Patriots
- Elisabeth Dieringer, Virginie Joron
0 · Abstained
Procedure – committee responsible 1 paragraph
| Title | Establishment of European Business Wallets | |||
| References | COM(2025)0838 – C10-0305/2025 – 2025/0358(COD) | |||
| Date submitted to Parliament | 19.11.2025 | |||
| Committee(s) responsible Date announced in plenary | ITRE 19.1.2026 | |||
| Committees asked for opinions Date announced in plenary | BUDG 19.1.2026 | IMCO 19.1.2026 | JURI 19.1.2026 | LIBE 19.1.2026 |
| Not delivering opinions Date of decision | BUDG 11.12.2025 | LIBE 29.1.2026 | ||
| Rapporteurs Date appointed | Eero Heinäluoma 18.12.2025 | |||
| Discussed in committee | 15.4.2026 | |||
| Date adopted | 10.9.2026 | |||
| Result of final vote | +: –: 0: | 64 7 4 | ||
| Date tabled | 23.9.2026 |
Final vote by roll call by the committee responsible 3 paragraphs
64 · For
- ECR
- Elena Donazzan, Rihards Kols, Daniel Obajtek, Diego Solier, Francesco Torselli, Kris Van Dijck, Mariateresa Vivaldini
- EPP
- Hildegard Bentele, Pilar del Castillo Vera, Raúl de la Hoz Quintano, Niels Flemming Hansen, Krzysztof Hetman, Seán Kelly, Łukasz Kohut, Willemien Koning, Eszter Lakos, Angelika Niebler, Andrey Novakov, Mirosława Nykiel, Virgil-Daniel Popescu, Jüri Ratas, Aura Salla, Paulius Saudargas, Oliver Schenk, Matej Tonin, Marion Walsmann, Andrea Wechsler, Iuliu Winkler, Angelika Winzig, Tomáš Zdechovský
- Renew
- João Cotrim De Figueiredo, Sigrid Friis, Bart Groothuis, Michał Kobosko, Ilhan Kyuchyuk, Morten Løkkegaard, Anna Stürgkh, Brigitte van den Berg, Yvan Verougstraete
- S&D
- Estelle Ceulemans, Christophe Clergeau, Annalisa Corrado, Niels Fuglsang, Lina Gálvez, Jens Geier, Bruno Gonçalves, Nicolás González Casares, Maria Grapini, Eero Heinäluoma, Evin Incir, Thomas Pellerin-Carlin, Tsvetelina Penkova, René Repasi, Elena Sancho Murillo, Bruno Tobback, Nicola Zingaretti
- The Left
- Jussi Saramo
- Greens
- Michael Bloss, Damian Boeselager, Markéta Gregorová, Ville Niinistö, Majdouline Sbai, Lena Schilling, Villy Søvndal
7 · Against
- Patriots
- Majbritt Birkholm, Mélanie Disdier, Pierre-Romain Thionnet, Auke Zijlstra
- The Left
- Marina Mesure, Gaetano Pedulla', Dario Tamburrano
4 · Abstained
- ECR
- Claudiu-Richard Târziu
- ESN
- Markus Buchheit
- Patriots
- András Gyürk, Jana Nagyová