report parliamentary committee draft, 1 April 2026
On the proposal for a regulation of the European Parliament and of the Council on the establishment of European Business Wallets
Document ITRE-PR-785244 · (COM(2025)0838 – C100305/2025 – 2025/0358(COD))
Committee on Industry, Research and Energy · Rapporteur: Eero Heinäluoma
AI:In short
This is the rapporteur's draft report on the proposed regulation establishing European Business Wallets, a digital tool for economic operators and public sector bodies. It amends the Commission proposal to add security, data-sovereignty and interoperability requirements, and to exempt small municipalities from the obligation to accept the wallets. The amendments require wallet providers, qualified electronic registered delivery service providers and cloud providers hosting wallet data to be established in the Union, with wallet data stored and processed only in the Union. They add rules on automated transactions by digital or AI-driven agents, on data export and portability between wallets, and on strict limits to the attributes that relying parties may request. They set a transition period of 36 months after entry into force of the implementing acts during which public sector bodies may keep alternative solutions, and require the Commission to review the regulation three years after entry into force.
Position. The rapporteur proposes to amend the Commission proposal to strengthen security, data sovereignty and interoperability, to exempt small municipalities from public sector obligations, to add rules on automated transactions and data portability, and to require safeguards and mutual recognition agreements for third-country systems.
Key points
- The draft report adopts Parliament's position at first reading and calls on the Commission to refer the matter to Parliament again if it substantially amends its proposal.
- It amends the recitals to state that wallets should enable secure interaction between economic operators as well as with public administrations, and to support innovation without compromising security.
- It adds that more than one qualified electronic registered delivery service should serve as the mandatory secure legal communication channel, and that their providers must be established in the Union and not controlled by a third country.
- It requires wallet-relying parties to request only attributes strictly necessary for the procedure and to apply state-of-the-art security measures to protect business data.
- It provides that automated processes, including those run by digital or AI-driven agents under a valid, auditable and revocable authorisation, must be verifiable and auditable and offer an equivalent level of assurance.
- It requires wallet providers and supporting infrastructure service providers, including cloud providers, to be established in the Union, and provides that wallet data is exclusively stored and processed in the Union.
- It gives wallet owners the right to export their data in a structured, commonly used and machine-readable format and to import it into another wallet, to avoid vendor lock-in.
- It requires public sector bodies to enable the use of wallets by economic operators 24 months after entry into force of the implementing acts, and exempts municipalities with 10,000 inhabitants or less.
- It allows public sector bodies, for 36 months after entry into force of the implementing acts, to keep alternative solutions that comply with qualified electronic registered delivery service requirements and offer a gateway to the wallets.
- It requires the Commission to assess third-country wallet systems for equivalence of cybersecurity and data protection and independence from high-risk entities, with equivalence decisions lasting no more than three years while mutual recognition agreements are negotiated.
- It requires the Commission and member states to inform economic operators, especially small and medium-sized enterprises, and public sector bodies about the wallets, and the Commission to develop an implementation roadmap with milestones and use-cases.
- It requires the Commission to review the regulation three years after entry into force and every four years thereafter, assessing administrative burden reduction, cross-border interoperability and uptake.
Who is affected
- Economic operators, including small and medium-sized enterprises: wallet use is voluntary; they gain a tool for digital interaction with public bodies and each other.
- Public sector bodies: must enable wallet use in relevant procedures, except municipalities with 10,000 inhabitants or less, which are exempt.
- Wallet providers, qualified electronic registered delivery service providers and cloud providers: must be established in the Union and keep wallet data in the Union.
- Self-employed persons and sole traders: may use the secure communication channel as a standalone service with their European Digital Identity Wallet.
- Third-country economic operators: may obtain European Business Wallets and have their systems recognised as equivalent under conditions.
Figures and deadlines
- 24 months after entry into force of the implementing acts: deadline for public sector bodies to enable wallet use.
- 36 months after entry into force of the implementing acts: end of the transition period during which alternative solutions may be used.
- 10,000 inhabitants or less: threshold below which municipalities are exempted from the obligations.
- 15 calendar days: deadline for a notifying entity to respond to a request for additional information.
- 30 calendar days: period after which a supervisory body must inform the notifying entity of the reason for delay.
- 24 hours: deadline for the Commission to add or revoke a provider and update the list.
- three years: maximum period of an equivalence decision for third-country systems.
- 3 years after entry into force: deadline for the Commission's review report.
Legal basis. Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union.
Written by AI from the full text · every figure comes from the text · ¶ opens the paragraph · 25 Sept 2026 · Report a problem
Full text
Jump to an amendment (140)
- Amendment 1
- Amendment 2
- Amendment 3
- Amendment 4
- Amendment 5
- Amendment 6
- Amendment 7
- Amendment 8
- Amendment 9
- Amendment 10
- Amendment 11
- Amendment 12
- Amendment 13
- Amendment 14
- Amendment 15
- Amendment 16
- Amendment 17
- Amendment 18
- Amendment 19
- Amendment 20
- Amendment 21
- Amendment 22
- Amendment 23
- Amendment 24
- Amendment 25
- Amendment 26
- Amendment 27
- Amendment 28
- Amendment 29
- Amendment 30
- Amendment 31
- Amendment 32
- Amendment 33
- Amendment 34
- Amendment 35
- Amendment 36
- Amendment 37
- Amendment 38
- Amendment 39
- Amendment 40
- Amendment 41
- Amendment 42
- Amendment 43
- Amendment 44
- Amendment 45
- Amendment 46
- Amendment 47
- Amendment 48
- Amendment 49
- Amendment 50
- Amendment 51
- Amendment 52
- Amendment 53
- Amendment 54
- Amendment 55
- Amendment 56
- Amendment 57
- Amendment 58
- Amendment 59
- Amendment 60
- Amendment 61
- Amendment 62
- Amendment 63
- Amendment 64
- Amendment 65
- Amendment 66
- Amendment 67
- Amendment 68
- Amendment 69
- Amendment 70
- Amendment 71
- Amendment 72
- Amendment 73
- Amendment 74
- Amendment 75
- Amendment 76
- Amendment 77
- Amendment 78
- Amendment 79
- Amendment 80
- Amendment 81
- Amendment 82
- Amendment 83
- Amendment 84
- Amendment 85
- Amendment 86
- Amendment 87
- Amendment 88
- Amendment 89
- Amendment 90
- Amendment 91
- Amendment 92
- Amendment 93
- Amendment 94
- Amendment 95
- Amendment 96
- Amendment 97
- Amendment 98
- Amendment 99
- Amendment 100
- Amendment 101
- Amendment 102
- Amendment 103
- Amendment 104
- Amendment 105
- Amendment 106
- Amendment 107
- Amendment 108
- Amendment 109
- Amendment 110
- Amendment 111
- Amendment 112
- Amendment 113
- Amendment 114
- Amendment 115
- Amendment 116
- Amendment 117
- Amendment 118
- Amendment 119
- Amendment 120
- Amendment 121
- Amendment 122
- Amendment 123
- Amendment 124
- Amendment 125
- Amendment 126
- Amendment 127
- Amendment 128
- Amendment 129
- Amendment 130
- Amendment 131
- Amendment 132
- Amendment 133
- Amendment 134
- Amendment 135
- Amendment 136
- Amendment 137
- Amendment 138
- Amendment 139
- Amendment 140
Draft european parliament legislative resolution 716 paragraphs
(COM(2025)0838 – C100305/2025 – 2025/0358(COD))
(Ordinary legislative procedure: first reading)
The European Parliament,
–having regard to the Commission proposal to Parliament and the Council (COM(2025)0838),
–having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C100305/2025),
–having regard to Article 294(3) of the Treaty on the Functioning of the European Union,
–having regard to the European Parliament draft report on the proposal for a regulation of the European Parliament and of the Council establishing the Single Market and Customs Programme for the period 2028- 2034 and repealing Regulations (PE785.258v01-00),
–having regard to the report of the Committee on Industry, Research and Energy (A100000/2026),
–having regard to the opinion of the European Economic and Social Committee,
–having regard to Rule 60 of its Rules of Procedure,
–having regard to the opinions of the Committee on the Internal Market and Consumer Protection and the Committee on Legal Affairs,
1.Adopts its position at first reading hereinafter set out;
Read the rest (704 paragraphs)
2.Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
3.Instructs its President to forward its position to the Council, the Commission and the national parliaments.
Amendment 1
Proposal for a regulation
Recital 1
| Text proposed by the Commission | Amendment |
|---|---|
| (1) In its Communication of 29 January 2025 ‘A Competitiveness Compass for the EU’(2 ) the Commission announced that European Business Wallets, building on the European Digital Identity Framework, will constitute the cornerstone for conducting business in a simple and digital manner within the Union, providing companies with a seamless environment in which to interact with public administrations. | (1) In its Communication of 29 January 2025 ‘A Competitiveness Compass for the EU’(2 ) the Commission announced that European Business Wallets, building on the European Digital Identity Framework, will constitute the cornerstone for conducting business in a simple, secure and digital manner within the Union, providing companies with a seamless environment in which to interact with public administrations and with other economic operators. |
| 2 Communication from the Commission to the European Parliament, the European Council, the Council, the European Economic and Social Committee and the Committee of the Regions ‘A Competitiveness Compass for the EU’, COM(2025) 30 final. | 2 Communication from the Commission to the European Parliament, the European Council, the Council, the European Economic and Social Committee and the Committee of the Regions ‘A Competitiveness Compass for the EU’, COM(2025) 30 final. |
Or. en
Amendment 2
Proposal for a regulation
Recital 2
| Text proposed by the Commission | Amendment |
|---|---|
| (2) Regulation (EU) No 910/2014 of the European Parliament and of the Council(3 ) establishes the European Digital Identity Framework and introduces the European Digital Identity Wallets, enabling users to securely store and manage their digital identity and electronic attestations of attributes, and to access a wide range of online services. The European Digital Identity Framework features new trust services, including the issuance of electronic attestations of attributes, thereby enhancing the security and reliability of online transactions and interactions. | (2) Regulation (EU) No 910/2014 of the European Parliament and of the Council(3 ) establishes the European Digital Identity Framework and introduces the European Digital Identity Wallets, intended for voluntary use by individuals, enabling users to securely store and manage their digital identity and electronic attestations of attributes, and to access a wide range of online services. The European Digital Identity Framework features new trust services, including the issuance of electronic attestations of attributes, thereby enhancing the security and reliability of online transactions and interactions. |
| 3 Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC (OJ L 257, 28.8.2014, p. 73, ELI: http://data.europa.eu/eli/reg/2014/910/oj). | 3 Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC (OJ L 257, 28.8.2014, p. 73, ELI: http://data.europa.eu/eli/reg/2014/910/oj). |
Or. en
Amendment 3
Proposal for a regulation
Recital 4
| Text proposed by the Commission | Amendment |
|---|---|
| (4) In order to ensure the interoperability and security of European Business Wallets, the technical specifications established in Regulation (EU) No 910/2014 and subsequent implementing regulations established pursuant to that Regulation as well as the technology and standards developments and the work carried out on the basis of Recommendation (EU) 2021/946, and in particular the Architecture and Reference Framework, should apply, with the specifications laid down in this Regulation taking precedence in the event of any inconsistency. | (4) In order to ensure trust and a high degree of interoperability and security of European Business Wallets as well as effective standardisation, the technical specifications established in Regulation (EU) No 910/2014 and subsequent implementing regulations established pursuant to that Regulation as well as the technology and standards developments and the work carried out on the basis of Recommendation (EU) 2021/946, and in particular the Architecture and Reference Framework, should apply, with the specifications laid down in this Regulation taking precedence in the event of any inconsistency. The technical trust architecture underpinning European Business Wallets should support innovation and new market-driven solutions, without compromising on security. |
Or. en
Amendment 4
Proposal for a regulation
Recital 5
| Text proposed by the Commission | Amendment |
|---|---|
| (5) In order to enhance the functioning of the digital single market, ensure interoperability and reduce administrative burdens, it is essential to ensure compatibility between and European Business Wallets and existing systems and solutions at both Union and national level. As prescribed by the Interoperable Europe Act and to enhance secure and efficient data exchanges across the Union, the implementation of the European Business Wallets should, to the extent possible, where appropriate and following technical analysis, make use of existing EU digital infrastructures and building blocks, including those developed under the Once Only Technical System, the Business Registers Interconnection System and the European Digital Identity Wallet, thereby ensuring complementarity, interoperability, and efficient use of public resources. | (5) In order to enhance the functioning of the digital single market, ensure interoperability and reduce administrative burdens, duplication and unnecessary costs, it is essential to ensure compatibility between European Business Wallets and existing systems and solutions at both Union and national level. As prescribed by the Interoperable Europe Act and to enhance secure and efficient data exchanges across the Union, the implementation of the European Business Wallets should, to the extent possible, where appropriate and following technical analysis, make use of existing EU digital infrastructures and building blocks, including those developed under the Once Only Technical System, the Business Registers Interconnection System and the European Digital Identity Wallet, thereby ensuring complementarity, interoperability, and efficient use of public resources. |
Or. en
Amendment 5
Proposal for a regulation
Recital 6
| Text proposed by the Commission | Amendment |
|---|---|
| (6) The European Business Wallets are a digital tool for economic operators to interact with public sector bodies in the context of meeting reporting obligations and fulfilling administrative procedures. The use of the core functionalities of the European Business Wallets to identify and authenticate, sign or seal, submit documents and send or receive notifications should be without prejudice to procedural requirements that might be part of an administrative procedure and that cannot be fulfilled by the core functionalities of the European Business Wallets. These procedural requirements may include any additional safeguards or verifications, such as checks to ensure the awareness or understanding of the contents of a document or the implications of the signature of a contract, or specific actions that are required as part of an administrative procedure and are not supported by the core functionalities of the European Business Wallets. Public sector bodies should therefore ensure that all relevant procedural requirements are met, including any specific actions or processes which need to be fulfilled as part of an administrative procedure and which cannot be performed through the European Business Wallets. | (6) The European Business Wallets are a digital tool which enable economic operators to interact with public sector bodies in the context of meeting reporting obligations and fulfilling administrative procedures and which enable secure interaction with other economic operators. The use of the core functionalities of the European Business Wallets to identify and authenticate, sign or seal, request or share electronic attestations of attributes, submit documents and send or receive notifications should be without prejudice to procedural requirements that might be part of an administrative procedure and that cannot be fulfilled by the core functionalities of the European Business Wallets. These procedural requirements may include any additional safeguards or verifications, such as checks to ensure the awareness or understanding of the contents of a document or the implications of the signature of a contract, or specific actions that are required as part of an administrative procedure and are not supported by the core functionalities of the European Business Wallets. Public sector bodies should therefore ensure that all relevant procedural requirements are met, including any specific actions or processes which need to be fulfilled as part of an administrative procedure and which cannot be performed through the European Business Wallets. |
Or. en
Amendment 6
Proposal for a regulation
Recital 10
| Text proposed by the Commission | Amendment |
|---|---|
| (10) This Regulation should be without prejudice to the right of legal persons to submit only once information to public sector bodies as well as to the right of Member States to continue using other systems for the submission of documents and data between competent authorities as established under Union law, such as in Regulation 2018/1724(4 ) and Directive (EU) 2017/1132 establishing the Business Registers Interconnection System | (10) This Regulation should be without prejudice to the right of legal persons to submit only once information to public sector bodies as well as to the right of Member States to continue using other systems for the submission of documents and data between competent authorities as established under Union law, such as in Regulation 2018/1724(4 ) establishing the Single Digital Gateway and Once-Only Technical System and Directive (EU) 2017/1132 establishing the Business Registers Interconnection System. |
| 4 Regulation (EU) 2018/1724 of the European Parliament and of the Council of 2 October 2018 establishing a single digital gateway to provide access to information, to procedures and to assistance and problem-solving services and amending Regulation (EU) No 1024/2012 (OJ L 295, 21.11.2018, pp. 1, ELI: https://eur-lex.europa.eu/eli/reg/2018/1724/oj/eng) | 4 Regulation (EU) 2018/1724 of the European Parliament and of the Council of 2 October 2018 establishing a single digital gateway to provide access to information, to procedures and to assistance and problem-solving services and amending Regulation (EU) No 1024/2012 (OJ L 295, 21.11.2018, pp. 1, ELI: https://eur-lex.europa.eu/eli/reg/2018/1724/oj/eng) |
Or. en
Amendment 7
Proposal for a regulation
Recital 11 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (11a) In order to avoid single points of failure and ensure competition among solution providers, more than one QERDS should serve as a mandatory secure legal communication channel for European Business Wallets as set out in the Annex to this Regulation. In light of the role of European Business Wallets in the Union’s digital infrastructure and in order to safeguard integrity and accountability and ensure the security of data stored or exchanged in the European Business Wallets ecosystem, the providers of QERDS, which are integrated into the European Business Wallets, should be established within the Union, have their principal place of business and main operations in the Union and not present a risk to the security of the Union. In particular, they should not be subject to control by a third country or by a third-country entity. |
Or. en
Amendment 8
Proposal for a regulation
Recital 12
| Text proposed by the Commission | Amendment |
|---|---|
| (12) In order to provide a tailored solution for self-employed persons and sole traders, it is essential to ensure the seamless integration of European Digital Identity Wallets with European Business Wallets. That integration should enable those persons to authenticate using their European Digital Identity Wallet and access trust services offered for the European Business Wallets, including the QERDS established as a secure communication channel in this Regulation, using those Wallets, without the need to create a separate business identity. Providers of European Business Wallets should therefore be allowed to offer the secure communication channel as a standalone service to self-employed persons and sole traders that use European Digital Identity Wallets in a business capacity, with ensured interoperability to facilitate app switching, as well as trust services such as electronic signatures and qualified and non-qualified time stamping services. Such access to the secure communication channel for self-employed persons and sole traders, should be promoted by ensuring an offer, at reasonable and affordable prices, that reflects the usage needs and is accompanied by terms of use that do not impose an undue burden on those persons. | (12) In order to provide a tailored solution for self-employed persons and sole traders, it is essential to ensure the seamless integration of European Digital Identity Wallets with European Business Wallets, while also preserving privacy. That integration should enable those persons to authenticate using their European Digital Identity Wallet and access trust services offered for the European Business Wallets, including the QERDS established as a secure communication channel in this Regulation, using those Wallets. Access to European Business Wallet services should take place in a way that clearly distinguishes whether an individual is using their European Digital Identity Wallets, for business purposes or as an individual. Providers of European Business Wallets should be allowed to offer the secure communication channel as a standalone service to self-employed persons and sole traders that use European Digital Identity Wallets in a business capacity, with ensured interoperability to facilitate app switching, as well as trust services such as electronic signatures and qualified and non-qualified time stamping services. Such access to the secure communication channel for self-employed persons and sole traders, should be promoted by ensuring an offer, at reasonable and affordable prices, that reflects the usage needs and is accompanied by terms of use that do not impose an undue burden on those persons. Self-employed persons and sole traders that would use the European Business Wallet would be considered “data subjects” under Regulation (EU) 2016/679. |
Or. en
Amendment 9
Proposal for a regulation
Recital 13
| Text proposed by the Commission | Amendment |
|---|---|
| (13) The European Business Wallets, in combination with Regulation (EU) 2018/1724, should support the forthcoming 28th Regime(5 ) by providing the digital infrastructure for fully digital procedures, enabling start-ups and scale-ups to conduct EU-wide operations in a rapid and efficient manner. The Business Wallets should provide the digital infrastructure for the 28th Regime's digital-first strategy, streamlining cross-border interactions and reducing administrative burden, such as facilitating the secure storing and signature of contracts and certificates or submitting, receiving and sharing electronic applications and documents. By providing this infrastructure, the Business Wallets should help make the "digital by default" principle a reality, facilitating the growth and development of EU companies and enhancing their competitiveness. | (13) The European Business Wallets, in combination with Regulation (EU) 2018/1724, should support the forthcoming 28th Regime(5 ) by providing the digital infrastructure for fully digital procedures, enabling start-ups and scale-ups to conduct EU-wide operations in a rapid and efficient manner. The Business Wallets should provide the digital infrastructure for the 28th Regime's digital-first strategy, streamlining cross-border interactions and reducing administrative burden, such as facilitating the secure storing and signature of contracts and certificates or submitting, receiving and sharing electronic applications and documents, including structured, machine-readable data as electronic attestations of attributes. By providing this infrastructure, the Business Wallets should help make the "digital by default" principle a reality, facilitating the growth and development of EU companies and enhancing their competitiveness. |
| 5 European Commission, Call for Evidence: 28th regime – a single harmonized set of rules for innovative companies throughout the EU, 8th of July, available at https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14674-28th-regime-a-single-harmonized-set-of-rules-for-innovative-companies-throughout-the-EU_en | 5 European Commission, Call for Evidence: 28th regime – a single harmonized set of rules for innovative companies throughout the EU, 8th of July, available at https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14674-28th-regime-a-single-harmonized-set-of-rules-for-innovative-companies-throughout-the-EU_en |
Or. en
Amendment 10
Proposal for a regulation
Recital 14
| Text proposed by the Commission | Amendment |
|---|---|
| (14) Given the objective of creating a unified digital ecosystem for electronic identification, authentication, and the exchange of electronic documents, notifications, and attestations of attributes, the inclusion of Union entities among public sector bodies covered this Regulation, is necessary. Such an inclusion should create a coherent framework for owners of European Business Wallets to engage with all levels of public administration thereby reducing administrative complexities and driving uptake of the European Business Wallets. | (14) Given the objective of creating a unified digital ecosystem for electronic identification, authentication, and the exchange of electronic documents, notifications, and attestations of attributes, the inclusion of Union entities among public sector bodies covered by this Regulation, is necessary. Such an inclusion should create a coherent framework for owners of European Business Wallets to engage with all levels of public administration thereby reducing administrative complexities and driving uptake of the European Business Wallets. |
Or. en
Amendment 11
Proposal for a regulation
Recital 15
| Text proposed by the Commission | Amendment |
|---|---|
| (15) In order to ensure the proper issuance and integration of European Business Wallets throughout the operations and systems of Union entities, this Regulation should have due regard to the specific nature and structure of such institutions, bodies, offices and agencies. To ensure the respect of administrative autonomy and security of Union entities. They should be allowed to acquire European Business Wallets from already established providers of European Business Wallets, or develop their own European Business Wallets or act themselves as provider for Union entities. Where Union entities act as providers of European Business Wallets, they should also be subject to a supervisory framework. In such cases, the Commission should be tasked to the supervise the provision of European Business Wallets by Union entities. | (15) In order to ensure the proper issuance and integration of European Business Wallets throughout the operations and systems of Union entities, this Regulation should have due regard to the specific nature and structure of such institutions, bodies, offices and agencies. To ensure the respect of administrative autonomy and security of Union entities, they should be allowed to acquire European Business Wallets from established providers of European Business Wallets, or develop their own European Business Wallets or act themselves as provider for Union entities. Where Union entities act as providers of European Business Wallets to other Union entities, they should also be subject to a supervisory framework. In such cases, the Commission should be tasked to the supervise the provision of European Business Wallets by Union entities. |
Or. en
Amendment 12
Proposal for a regulation
Recital 17
| Text proposed by the Commission | Amendment |
|---|---|
| (17) The European Business Wallets should allow individuals granted the power to act on behalf of an entity in legal, financial, and administrative matters to exercise their functions by signing any attestations, declarations, or documents executed through a legally valid electronic signature within the meaning of Regulation (EU) 910/2014, which establishes that electronic signatures shall have the equivalent legal effect of a handwritten signature. | (17) The European Business Wallets should allow individuals granted the power to act on behalf of an entity in legal, financial, and administrative matters to exercise their functions by signing any attestations, declarations, or documents executed through a legally valid electronic signature within the meaning of Regulation (EU) 910/2014, which establishes that qualified electronic signatures shall have the equivalent legal effect of a handwritten signature. |
Or. en
Amendment 13
Proposal for a regulation
Recital 18
| Text proposed by the Commission | Amendment |
|---|---|
| (18) To support the delegation of powers and mandates within a professional context, the European Business Wallets should incorporate a mandate and role-based authorisation system that governs access to services and transactions within the European Business Wallet in such a way as to preserve the integrity of the identity of the owner of that Wallet. That system should enable economic operators and public sector bodies to assign rights to authorised representatives through clearly defined technical mandates allowing the owner of a specific European Business Wallet to grant full rights to generally use the solution and act on its behalf, and an administrative mandate, allowing the owner of a Business Wallet to assign roles and responsibilities to various users of the solution within their organisation. This authorisation system should ensure compatibility with the EU digital power of attorney, as established by Directive (EU) 2025/25 of the European Parliament and of the Council6 . This authorisation system should be robust and scalable, to ensure that economic operators and public sector bodies, as the owners of European Business Wallets, can delegate authority to multiple users, including employees or other authorised natural or legal persons, thereby facilitating the efficient and secure management of internal activities and ensuring that access to European Business Wallets and their functions is controlled and auditable. This system should govern access to services and transactions within the European Business Wallet, preserving the integrity of the owners' identities. | (18) To support the delegation of powers and mandates within a professional context, the European Business Wallets should incorporate a mandate and role-based authorisation system that governs access to services and transactions within the European Business Wallet in such a way as to support the various business needs and to preserve the integrity of the identity of the owner of that Wallet. That system should enable economic operators and public sector bodies, within a comprehensive framework, to assign rights to authorised representatives through clearly defined technical mandates allowing the owner of a specific European Business Wallet to grant full rights to generally use the solution and act on its behalf, and an administrative mandate, allowing the owner of a Business Wallet to assign and manage clearly defined and restricted roles and responsibilities to various users of the solution within their organisation. This authorisation system should allow the use of European Digital Identity Wallets, but should not require users to have them, as the use of European Digital Wallets remains voluntary. The authorisation system should ensure compatibility with the EU digital power of attorney, as established by Directive (EU) 2025/25 of the European Parliament and of the Council6 . This authorisation system should be robust and scalable, to ensure that economic operators and public sector bodies, as the owners of European Business Wallets, can delegate authority to multiple users, including employees or other authorised natural or legal persons, thereby facilitating the efficient and secure management of internal activities and ensuring that access to European Business Wallets and their functions is controlled, revokable, traceable, and auditable. This system should govern access to services and transactions within the European Business Wallet, preserving the integrity of the owners' identities. |
| 6 Directive (EU) 2025/25 of the European Parliament and of the Council of 19 December 2024 amending Directives 2009/102/EC and (EU) 2017/1132 as regards further expanding and upgrading the use of digital tools and processes in company law (OJ L, 2025/25, 10.1.2025, ELI: http://data.europa.eu/eli/dir/2025/25/oj). | 6 Directive (EU) 2025/25 of the European Parliament and of the Council of 19 December 2024 amending Directives 2009/102/EC and (EU) 2017/1132 as regards further expanding and upgrading the use of digital tools and processes in company law (OJ L, 2025/25, 10.1.2025, ELI: http://data.europa.eu/eli/dir/2025/25/oj). |
Or. en
Amendment 14
Proposal for a regulation
Recital 18 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (18a) Given the highly sensitive nature of the information exchanged via the European Business Wallet, including trade secrets and sensitive corporate attributes, it is essential that Business Wallet-relying parties adhere to strict security and transparency requirements. To prevent unauthorised access to business data or the misuse of such data, Business Wallet-relying parties should be technically and legally restricted to requesting only those attributes which are strictly necessary for the administrative or commercial procedure concerned. Furthermore, where a Business Wallet-relying party processes credentials provided by a European Business Wallet, they should implement state-of-the-art security measures to ensure the confidentiality and non-repudiation of the exchange, ensuring that the legal entity's data is protected against unauthorised access or exfiltration. |
Or. en
Amendment 15
Proposal for a regulation
Recital 19
| Text proposed by the Commission | Amendment |
|---|---|
| (19) In order to facilitate the conduct of cross-border business transactions, reduce administrative burdens, and promote economic growth, it is necessary to establish a clear and predictable legal framework that recognises the legal equivalence between the use of the European Business Wallets, or their core functionalities and the secure communication channel where the latter is used by self-employed persons and sole traders, and other accepted methods for economic operators to identify, authenticate, submit documents and receive notifications when interacting with public sector bodies in the Union. To that end, the use of the core functionalities of a European Business Wallet, or the secure communication channel where the latter is used by self-employed persons and sole traders, should have the same legal effect as if lawfully carried out in person, in paper form, or via any other means or process that would otherwise be deemed compliant with applicable legal, administrative, or procedural requirements. | (19) In order to facilitate the conduct of cross-border business transactions, reduce administrative burdens, and promote economic growth, it is necessary to establish a clear and predictable legal framework that recognises the legal equivalence between the use of the European Business Wallets, or their core functionalities that are based on qualified trust services, and the secure communication channel where the latter is used by self-employed persons and sole traders, and other accepted methods for economic operators to identify, authenticate, submit documents and receive notifications when interacting with public sector bodies in the Union. To that end, the use of the core functionalities of a European Business Wallet or the secure communication channel where the latter is used by self-employed persons and sole traders, should have the same legal effect as if lawfully carried out in person, in paper form, or via any other means or process that would otherwise be deemed compliant with applicable legal, administrative, or procedural requirements. |
Or. en
Amendment 16
Proposal for a regulation
Recital 20
| Text proposed by the Commission | Amendment |
|---|---|
| (20) To ensure a consistent user experience and to guarantee the utility, reliability, and interoperability of European Business Wallets across the Union, providers of European Business Wallets should implement a core set of functionalities. They should retain the freedom to offer additional features as part of their commercial offering, fostering innovation and responding to market needs. In order to ensure uniform conditions for the development and use of the core functionalities, implementing powers should be conferred on the Commission to set out requirements and technical specifications necessary to ensure interoperability and seamless functioning across the Union. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council(7 ) and should include the powers to define the necessary standards and protocols for the secure communication channel, taking into account the latest technological developments. | (20) To ensure a consistent user experience and to guarantee the utility, reliability, and interoperability of European Business Wallets across the Union, providers of European Business Wallets should implement a core set of functionalities. They should retain the freedom, as part of their commercial offering, fostering innovation and responding to market needs, to offer additional features, which adhere to the security requirements laid down in this Regulation. In order to ensure uniform conditions for the development and use of the core functionalities, implementing powers should be conferred on the Commission to set out requirements and technical specifications necessary to ensure security, interoperability and seamless functioning across the Union. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council(7 ) and should include the powers to define the necessary standards and protocols for the secure communication channel, taking into account the latest technological developments. The technical specifications should enable the incorporation of new models for authorisation, automation and data exchange, as they become available, while preserving interoperability and a consistent level of security and assurance. |
| 7 Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by the Member States of the Commission's exercise of implementing powers (OJ L 55, 28.2.2011, p. 13, ELI: http://data.europa.eu/eli/reg/2011/182/oj). | 7 Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by the Member States of the Commission's exercise of implementing powers (OJ L 55, 28.2.2011, p. 13, ELI: http://data.europa.eu/eli/reg/2011/182/oj). |
Or. en
Amendment 17
Proposal for a regulation
Recital 20 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (20a) European Business Wallets could facilitate automated processes which do not require manual intervention or direct user action. Such automated processes could entail enabling automated transactions executed by, for example, a digital agent or AI-driven agent authorised to perform actions under a valid, auditable and revocable authorisation issued by the European Business Wallet owner or user. Such automated processes should always be verifiable and auditable and ensure an equivalent level of assurance and accountability compared with actions performed by a user. |
Or. en
Amendment 18
Proposal for a regulation
Recital 21
| Text proposed by the Commission | Amendment |
|---|---|
| (21) European Business Wallets should simplify the complex interactions between economic operators and public sector bodies, and could also facilitate interactions among economic operators themselves, reducing administrative burden on economic operators in a broad range of economic sectors. In order to foster innovation and competitiveness, the European Business Wallets should enable sector-specific use cases and enhance operational efficiencies, while ensuring flexibility and adaptability to support the unique requirements of different sectors, including, but not limited to, agriculture, energy, environment, social security coordination. | (21) European Business Wallets should simplify the complex interactions between economic operators and public sector bodies, and should also facilitate interactions among economic operators themselves, reducing administrative burden on economic operators in a broad range of economic sectors. In order to foster innovation and competitiveness, the European Business Wallets should enable sector-specific use cases and enhance operational efficiencies, while ensuring flexibility and adaptability to support the unique requirements of different sectors, including, but not limited to, agriculture, energy, environment, social security coordination. |
Or. en
Amendment 19
Proposal for a regulation
Recital 22
| Text proposed by the Commission | Amendment |
|---|---|
| (22) The use of the European Business Wallets in such contexts can aid in the reduction of costs and promote a wide range of applications and use cases across the Union, such as the submission of declarations, applications for public funding, access to public services and facilitating secure data sharing and access within data spaces, such as the submission of A1 certificates concerning posted workers provided for under Regulation (EU) 883/2004. | (22) The use of the European Business Wallets in such contexts can aid in the reduction of costs and promote a wide range of applications and use cases across the Union, such as Know Your Customer (KYC) and Know Your Business partner (KYB) processes, beneficial ownership verification, business permits, public procurement, digital product passports, the submission of declarations, certificates and compliance data, applications for public funding, access to public services and facilitating secure cross-border data sharing and access within data spaces, such as the submission of A1 certificates concerning posted workers provided for under Regulation (EU) 883/2004. |
Or. en
Amendment 20
Proposal for a regulation
Recital 23
| Text proposed by the Commission | Amendment |
|---|---|
| (23) The establishment of the European Business Wallets alongside the Once Only Technical System is expected to create powerful synergies that maximise efficiency and operational ease. In particular, economic operators should be able to use the European Business Wallet to hold and transmit evidence retrieved from competent public authorities through the Once-Only Technical System. Where appropriate, economic operators should also be able to combine evidence held in the European Business Wallet with evidence retrieved via the Once Only Technical System in the context of public procedures. Consequently, by providing a secure digital platform for storing and exchanging business documents, the European Business Wallets should facilitate the exchange of such documents between public sector bodies through the mechanisms established under Once-Only Technical System. | (23) The establishment of the European Business Wallets alongside the Once Only Technical System is expected to create powerful synergies that maximise efficiency and operational ease. To maximise coherence and reduce duplication, the European Business Wallets should function as an interoperable unifying architectural layer rather than an additional platform, enabling integration with existing and future national and Union-level digital gateways for efficient interaction of economic operators with public sector bodies. In particular, economic operators should be able to use the European Business Wallet to hold and transmit evidence retrieved from competent public authorities through the Once-Only Technical System. Where appropriate, economic operators should also be able to combine evidence held in the European Business Wallet with evidence retrieved via the Once Only Technical System in the context of public procedures. Consequently, by providing a secure digital platform for storing and exchanging business documents, the European Business Wallets should facilitate the exchange of such documents between public sector bodies through the mechanisms established under Once-Only Technical System. The technical system supporting such interactions should also enable the exchange of machine-readable structured data. |
Or. en
Amendment 21
Proposal for a regulation
Recital 23 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (23a) The Commission should provide further guidance on how possible overlaps between the requirements stemming from Regulation 2018/1724 and this Regulation could be avoided, in order to improve synergies, efficiencies and interoperability. |
Or. en
Amendment 22
Proposal for a regulation
Recital 25
| Text proposed by the Commission | Amendment |
|---|---|
| (25) To facilitate a flexible and efficient exchange of information and services when using European Business Wallets, and to ensure seamless integration of European Business Wallets with existing digital identity solutions, it should be possible to use European Digital Identity Wallets and electronic attestations of attributes for onboarding to and access management of the European Business Wallets. This should enable users to leverage existing digital identities and electronic attestations of attributes to access European Business Wallets, thereby streamlining the onboarding process and enhancing the overall user experience. The use of electronic attestations of attributes in the context of the European Business Wallets should cater to the diverse needs of European Business Wallet owners and may be used to issue and enable the secure and trustworthy verification of key attributes, such as an owner's current address, VAT registration number, tax reference number, Legal Entity Identifier (LEI), Economic Operator Registration and Identification (EORI) number and excise number. European Business Wallets should support a wide range of use cases, from simple authentication and identification to more complex transactions and interactions. | (25) To facilitate a flexible and efficient exchange of information and services when using European Business Wallets, and to ensure seamless integration of European Business Wallets with existing digital identity solutions, in addition to other electronic identification means, which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels ‘high’, it should be possible to use European Digital Identity Wallets and electronic attestations of attributes for onboarding to and access management of the European Business Wallets. This should enable users to leverage existing digital identities and electronic attestations of attributes to access European Business Wallets, thereby streamlining the onboarding process and enhancing the overall user experience. The use of electronic attestations of attributes in the context of the European Business Wallets should cater to the diverse needs of European Business Wallet owners and may be used to issue and enable the secure and trustworthy verification of key attributes, such as an owner's current address, VAT registration number, tax reference number, Legal Entity Identifier (LEI), Economic Operator Registration and Identification (EORI) number and excise number. European Business Wallets should support a wide range of use cases, from simple authentication and identification to more complex transactions and interactions. |
Or. en
Amendment 23
Proposal for a regulation
Recital 27 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (27a) In order to ensure a competitive market for providers of European Business Wallets, to enhance consumer choice and avoid vendor lock-in, European Business Wallet owners should be able to export their data, including issued European Business Wallet owner identification data, electronic attestations of attributes, communication logs, and interaction records, in a structured, commonly used and machine-readable format to another European Business Wallet; |
Or. en
Amendment 24
Proposal for a regulation
Recital 28
| Text proposed by the Commission | Amendment |
|---|---|
| (28) In order to ensure that the standards and technical specifications for European Business Wallets ensure harmonisation across various solutions, it is necessary to define the standards and protocols for the core functionalities and technical requirements for European Business Wallets in an Annex to this Regulation. The Annex should set out the requirements for the implementation of European Business Wallets. To ensure the long-term viability and effectiveness of the European Business Wallets, implementing powers should be conferred on the Commission to establish and update the procedures and technical specifications on the implementation of core functionalities, thereby allowing for the integration of additional features and new technologies that would enable new use cases, such as agentic AI or the provision of a digital identity to an owner’s asset, and enabling the European Business Wallets to continue to support the evolving needs of economic operators in a secure and trustworthy manner. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council. To the extent possible, the standards and technical specifications of the European Business Wallet should take into account relevant technical solutions and standards used by existing ICT systems by economic operators, facilitating the alignment of these systems to be aligned to and made interoperable with the European Business Wallet. | (28) In order to ensure that the standards and technical specifications for European Business Wallets ensure harmonisation across various solutions, it is necessary to define the standards and protocols for the core functionalities and technical requirements for European Business Wallets in an Annex to this Regulation. The common protocols and interfaces should be clear and unambiguous to avoid giving rise to different interpretations. The Annex should set out the requirements for the implementation of European Business Wallets. To ensure the long-term viability and effectiveness of the European Business Wallets, implementing powers should be conferred on the Commission to establish and update the procedures and technical specifications on the implementation of core functionalities, thereby allowing for the integration of additional features and new technologies that would enable new use cases, such as agentic AI or the provision of a digital identity to an owner’s asset, and enabling the European Business Wallets to continue to support the evolving needs of economic operators in a secure and trustworthy manner. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council. To the extent possible, the standards and technical specifications of the European Business Wallet should take into account relevant technical solutions and standards used by existing ICT systems by economic operators, facilitating the alignment of these systems to be aligned to and made interoperable with the European Business Wallet. |
Or. en
Amendment 25
Proposal for a regulation
Recital 30
| Text proposed by the Commission | Amendment |
|---|---|
| (30) To ensure the high level of trust, functionality, and security of European Business Wallets necessary to the cross-border provision of their services, and in particular to mitigate the risk of fraud, providers of European Business Wallets should be subject to clear and proportionate requirements and obligations without being subject to additional national requirements. | (30) To ensure the high level of trust, functionality, and security of European Business Wallets necessary to the cross-border provision of their services, and in particular to mitigate the risk of fraud, providers of European Business Wallets should be subject to clear and proportionate requirements and obligations without being subject to additional national requirements. Providers should notify the Member State supervisory body without undue delay of any substantive changes to their services or overall structure which could impact the compliance of the provider with this Regulation. |
Or. en
Amendment 26
Proposal for a regulation
Recital 30 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (30a) To facilitate trusted participation of economic operators, the European Business Wallets and supporting infrastructure must be secure-by-design and adhere to high standards in protecting confidentiality, availability and integrity of data processed by the European Business Wallets. Providers of European Business Wallets should comply with Directive (EU) 2022/2555 to ensure a high level of cybersecurity and trust in the European Business Wallets. Given the key role of European Business Wallets in the Union’s digital infrastructure, the providers of European Business Wallets and QTSPs should be ready to adapt to the quantum era and ensure they are PQC ready in advance of the quantum breakthrough. |
Or. en
Amendment 27
Proposal for a regulation
Recital 31
| Text proposed by the Commission | Amendment |
|---|---|
| (31) To ensure proper supervision in line with this Regulation, entities that would like to become providers of European Business Wallets should be required to notify their intention to provide such European Business Wallets to the supervisory bodies prior to offering their services. In order to safeguard the integrity and accountability of European Business Wallet providers and to ensure the security of data stored or exchanged in the European Business Wallets ecosystem, providers should be established within the Union. This should ensure that such providers fall under the jurisdiction and supervision of a competent body in a Member State, allowing for effective enforcement of this Regulation and the protection of users' rights and data. Furthermore, providers of European Business Wallets should not present a risk to the security of the Union, namely by not being subject to control by a third country or by a third-country entity, to ensure that the Union's critical digital infrastructure remains secure and resilient. In line with the requirements set out in this Regulation, the Commission may adopt implementing acts to ensure cooperation and interoperability with solutions established or endorsed by like-minded partners of the Union. | (31) To ensure proper supervision in line with this Regulation, entities that would like to become providers of European Business Wallets should be required to notify their intention to provide such European Business Wallets to the supervisory bodies prior to offering their services so that supervisory bodies can assess whether providers meet the relevant requirements of this Regulation. In order to safeguard the integrity and accountability of European Business Wallet providers and to ensure the security of data stored or exchanged in the European Business Wallets ecosystem, providers should be established within the Union. This should ensure that such providers fall under the jurisdiction and supervision of a competent body in a Member State, allowing for effective enforcement of this Regulation and the protection of users' rights and data. Furthermore, providers of European Business Wallets should not present a risk to the security of the Union, namely by not being subject to control by a third country or by a third-country entity, to ensure that the Union's critical digital infrastructure remains secure and resilient. In line with the requirements set out in this Regulation, the Commission may adopt implementing acts to ensure cooperation and interoperability with solutions established or endorsed by like-minded partners of the Union. |
Or. en
Amendment 28
Proposal for a regulation
Recital 31 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (31a) In order to safeguard security and trustworthiness of the whole European Business Wallets ecosystem, given its role in the Union’s digital infrastructure, the providers of QERDS, as well as the providers of supporting infrastructure services for hosting European Business Wallets data, namely cloud providers should be established in the Union, in line with the requirements and obligations for providers of European Business Wallets outlined in this Regulation. This is particularly important because Wallet services rely on cloud environments for the storage, processing, and exchange of data. Applying the requirements and obligations for providers of European Business Wallets outlined in this Regulation would limit exposure to the extraterritorial application of third-country laws that could adversely affect the confidentiality, availability and integrity of data, as well as the control over data processed within the European Business Wallet ecosystem. Furthermore, cloud providers should ensure that European Business Wallets data is exclusively processed and stored within the Union. |
Or. en
Amendment 29
Proposal for a regulation
Recital 31 b (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (31b) Entities operated or controlled by entities established outside the Union, as well as the concepts of control, should be understood in line with the concepts and definitions used in the Regulation on the screening of foreign investments in the Union and repealing Regulation (EU) 2019/452 of the European Parliament and of the Council. Control should encompass the decisive influence over the management, strategic decisions or essential operations of an entity. Direct or indirect control by a third-country government may be exercised in several ways and may be determined on the basis of, inter alia, ownership structure, government funding, specific governance arrangements such as golden shares, or other mechanisms aimed at influencing management decisions. |
Or. en
Amendment 30
Proposal for a regulation
Recital 37
| Text proposed by the Commission | Amendment |
|---|---|
| (37) To ensure that all European Business Wallet owners can be reliably identified and their electronic attestation of attributes are associated with a unique entity, it is also necessary to assign a unique identifier to other economic operators and public sector bodies. To ensure uniform conditions for the implementation of unique identifiers, in particular their effectiveness and consistency, implementing powers should be conferred on the Commission to specify the detailed requirements for the unique identifiers. Those powers should be exercised in accordance with Regulation (EU) No 182/2011. Given the diverse approaches among Member States regarding the registration of some economic operators and public sector bodies, it is important to ensure transparency and accessibility for providers of European Business Wallet owner identification data. To this end, Member States should notify to the Commission the authentic sources that are relevant for the issuance of European Business Wallet owner identification data. | (37) To ensure that all European Business Wallet owners can be reliably identified and their electronic attestation of attributes are associated with a unique entity, it is also necessary to assign a unique identifier to other economic operators and public sector bodies. A unique identifier should upon request by the economic operator be created, without undue delay. To ensure uniform conditions for the implementation of unique identifiers, in particular their effectiveness and consistency, implementing powers should be conferred on the Commission to specify the detailed requirements for the unique identifiers. Those powers should be exercised in accordance with Regulation (EU) No 182/2011. Given the diverse approaches among Member States regarding the registration of some economic operators and public sector bodies, it is important to ensure transparency and accessibility for providers of European Business Wallet owner identification data. To this end, Member States should notify to the Commission the authentic sources that are relevant for the issuance of European Business Wallet owner identification data. |
Or. en
Amendment 31
Proposal for a regulation
Recital 39
| Text proposed by the Commission | Amendment |
|---|---|
| (39) Regulation (EU) 2016/679 of the European Parliament and of the Council applies to all personal data processing activities under this Regulation. Where the European Digital Directory includes the processing of personal data this will be carried out in accordance with the relevant data protection principles, such as the data minimisation and purpose limitation principle, obligations, such as data protection by design and by default, and include, where appropriate, features of pseudonymisation. | (39) Regulation (EU) 2016/679 of the European Parliament and of the Council applies to all personal data processing activities under this Regulation. Where the European Digital Directory includes the processing of personal data this will be carried out in accordance with Regulation (EU) 2018/1725. The relevant data protection principles, such as the data minimisation and purpose limitation principle, obligations, such as data protection by design and by default, and include, where appropriate, features of pseudonymisation should apply to all personal data processing under this Regulation. |
Or. en
Amendment 32
Proposal for a regulation
Recital 40
| Text proposed by the Commission | Amendment |
|---|---|
| (40) To avoid excessive regulatory burdens, ex post supervision of providers of European Business Wallets and monitoring of their activities should be provided for, rather than requiring prior compliance verification for every aspect of their operations. This approach should allow for a more flexible and efficient regulatory environment, while maintaining the necessary safeguards to protect users and ensure compliance with the requirements of the European Business Wallets framework. The notification process for providers of European Business Wallets should be streamlined and efficient, with clear requirements and timelines for applicants. Qualified trust service providers, which are already subject to a robust regulatory framework under Regulation (EU) No 910/2014, should benefit from a particularly light process to be able to provide European Business Wallets. | (40) To avoid excessive regulatory burdens, ex post supervision of providers of European Business Wallets and monitoring of their activities should be provided for, along with proportionate compliance verification. This approach should allow for a more flexible and efficient regulatory environment, while maintaining the necessary safeguards to protect users and ensure compliance with the requirements of the European Business Wallets framework. The notification process for providers of European Business Wallets should be streamlined and efficient, with clear requirements and timelines for applicants. National supervisory authorities should, however, be given adequate time to review, assess, and validate the notified information to ensure the providers comply with the relevant requirements of this Regulation. |
Or. en
Amendment 33
Proposal for a regulation
Recital 41
| Text proposed by the Commission | Amendment |
|---|---|
| (41) In order to ensure transparency and accountability in the European Business Wallet ecosystem, a publicly available list of notified providers of European Business Wallets should be established and maintained by the Commission. That list should include information transmitted by the national supervisory bodies concerning providers, including qualified trust service providers, that have completed the notification process. Making that information publicly available should enable users to verify the authenticity and trustworthiness of providers, thereby promoting a high level of security and trust in the European Business Wallet ecosystem. | (41) In order to ensure transparency and accountability in the European Business Wallet ecosystem, a publicly available list of notified providers of European Business Wallets should be established and maintained by the Commission. That list should include information transmitted by the national supervisory bodies concerning providers, including qualified trust service providers, that have completed the notification process. Making that information publicly available should enable users to verify the authenticity and trustworthiness of providers complying with the requirements and obligations for providers of European Business Wallets as set out in this Regulation, thereby promoting a high level of security and trust in the European Business Wallet ecosystem. |
Or. en
Amendment 34
Proposal for a regulation
Recital 42
| Text proposed by the Commission | Amendment |
|---|---|
| (42) Effective oversight by supervisory bodies, vested with sufficient powers and provided with adequate resources, is essential to ensure that European Business Wallets made available in the Union comply with the requirements laid down in this Regulation. To best ensure such oversight and relevant expertise, Member States should designate the same supervisory body or bodies as designated pursuant to Article 46a(1) and Article 46b(1) of Regulation (EU) No 910/2014. | (42) Effective oversight by supervisory bodies, vested with sufficient powers and provided with adequate resources, is essential to ensure that European Business Wallets made available in the Union comply with the requirements laid down in this Regulation. To best ensure such oversight and relevant expertise, Member States should designate a supervisory body or bodies for the purposes of supervising the application and enforcement of this Regulation. Member States should ensure the effective supervision of providers of European Business Wallets, especially as regards the requirements on being established in the Union and complying with applicable cybersecurity requirements, including those relating to the identification of high-risk suppliers. Providers of European Business Wallets should provide the needed information for assessment of compliance with those requirements. |
Or. en
Amendment 35
Proposal for a regulation
Recital 46
| Text proposed by the Commission | Amendment |
|---|---|
| (46) The Cooperation Group established pursuant to Regulation (EU) No 910/2014 should be given the additional responsibility for the coordination of national practices and policies related to this Regulation and facilitate discussions between competent authorities regarding the Regulation's application and enforcement, thereby delivering on the objectives of the Cooperations Group’s establishment and retaining expertise for the benefit of implementing the European Business Wallet framework. | (46) The Cooperation Group established pursuant to Regulation (EU) No 910/2014 should be given the additional responsibility for the coordination of national practices and policies related to this Regulation and facilitate discussions between competent authorities regarding the Regulation's application and enforcement, thereby delivering on the objectives of the Cooperations Group’s establishment and retaining expertise for the benefit of implementing the European Business Wallet framework. Member States may appoint additional members to the European Digital Identity Cooperation Group established pursuant to the Regulation (EU) No 910/2014 , as the tasks of the Cooperation Group will be extended to cover issues related to the European Business Wallets. The Commission should furthermore ensure that a wide range of relevant stakeholders will be invited to participate in its work, when appropriate, to enable a fruitful cooperation on emerging policy initiatives in the field of digital identity wallets, European Business Wallets, electronic identification means and trust services. |
Or. en
Amendment 36
Proposal for a regulation
Recital 46 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (46a) In order to ensure compatibility between European Business Wallets and existing systems and solutions at both Union and national level, the European Digital Identity Cooperation Group should facilitate cooperation and information sharing on technical and operational issues to ensure the proper implementation and functioning of the European Business Wallets. |
Or. en
Amendment 37
Proposal for a regulation
Recital 46 b (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (46b) The Digital Identity Cooperation Group should also be a platform for sharing best practices around the most relevant use-cases for the European Business Wallets, especially concerning Small and medium-sized enterprises (SMEs) and procedures that are particularly relevant for companies engaged in cross-border activities. |
Or. en
Amendment 38
Proposal for a regulation
Recital 47
| Text proposed by the Commission | Amendment |
|---|---|
| (47) In order to support effective take-up and interoperability, all public sector bodies should be required to enable the use of the European Business Wallet in all relevant administrative procedures for the purposes of identification and authentication, signing or sealing documents, submitting documents and sending or receiving notifications. In this regard, public sector bodies should by [Publications Office, please insert the date 24 months after the entry into force of this Regulation] ensure that the use of European Business Wallets by economic operators is possible and that, where the receipt or communication of documents or notifications is concerned, they are able to access the Business Wallets’ secure communication channel. To ensure seamless and interoperable application of this Regulation in this regard, public sector bodies should own a European Business Wallet for the purposes of receiving or sending documents and notifications. The obligation for public sector bodies to accept European Business Wallets by economic operators should not affect systems used for the exchange or submission of documents or data between competent authorities. | (47) In order to support effective take-up and interoperability, public sector bodies should enable the use of the European Business Wallet in all relevant administrative procedures for the purposes of identification and authentication, signing or sealing documents, submitting documents and sending or receiving notifications. In this regard, public sector bodies should by 24 months after the entry into force of the implementing acts referred to in this Regulation ensure that the use of European Business Wallets by economic operators is possible and that, where the receipt or communication of documents or notifications is concerned, they are able to access the Business Wallets’ secure communication channel. To ensure seamless and interoperable application of this Regulation in this regard, public sector bodies should, where applicable, own a European Business Wallet for the purposes of receiving or sending documents and notifications. The obligation for public sector bodies to accept European Business Wallets by economic operators should not affect systems used for the exchange or submission of documents or data between competent authorities. However, in order to respect the proportionality principle and ensure cost-effective implementation, it is necessary to exempt certain smaller local authorities from the obligations laid down in this Regulation. Municipalities with 10,000 inhabitants or less should be exempt. However, such municipalities can voluntarily choose to have European Business Wallets. This proportionate approach will support the wide uptake of European Business Wallets and allow Member States to prioritise implementation of use-cases with the highest administrative or cross-border relevance, but not result in disproportionate financial burden for smaller public sector bodies. |
Or. en
Amendment 39
Proposal for a regulation
Recital 48
| Text proposed by the Commission | Amendment |
|---|---|
| (48) In order to avoid disrupting existing interactions between economic operators and public sector bodies, it is necessary to enable a transition period until [Publications Office, please insert the date 36 months after the entry into force of this Regulation]. During such period public sector bodies may choose not to offer the European Business Wallets' secure communication channel and instead support alternative solutions already in place which enable economic operators to communicate with public sector bodies prior to offering the European Business Wallets’ secure communication channel. In order to ensure an adequate level of security and interoperability, any alternative solution used during this transition period should comply with the requirements for Qualified Electronic Registered Delivery Services set out in Regulation (EU) No 910/2014 and offer a gateway to European Business Wallets. The gateway should enable users of European Business Wallets to access the alternative solutions used during the transition period. After this period, public sector bodies should support the secure communication channel of the European Business Wallets to ensure a harmonised and efficient means of communication across the Union, to the benefits of European businesses. | (48) In order to avoid disrupting existing interactions between economic operators and public sector bodies, it is necessary to enable a transition period until 36 months after the entry into force of the most relevant implementing acts referred to in this Regulation. During such period public sector bodies may choose not to offer the European Business Wallets' secure communication channel and instead support alternative solutions already in place which enable economic operators to communicate with public sector bodies prior to offering the European Business Wallets’ secure communication channel. In order to ensure an adequate level of security and interoperability, any alternative solution used during this transition period should comply with the requirements for Qualified Electronic Registered Delivery Services set out in Regulation (EU) No 910/2014 and offer a gateway to European Business Wallets. The gateway should enable users of European Business Wallets to access the alternative solutions used during the transition period. After this period, public sector bodies should support the secure communication channel of the European Business Wallets to ensure a harmonised and efficient means of communication across the Union, to the benefits of European businesses. |
Or. en
Amendment 40
Proposal for a regulation
Recital 48 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (48a) To support efficient and wide uptake of the European Business Wallets by economic operators, especially SMEs, and public sector bodies in all Member States, the Commission and Member States should inform economic operators, especially SMEs, and public sector bodies of the benefits of the European Business Wallets. The Commission should develop, in close cooperation with Member States, a comprehensive and forward-looking Implementation Roadmap that extends beyond initial deployment, identifying key milestones and use-cases within business-to-government (B2G), government -to- business (G2B) and business-to-business (B2B) interactions, especially for SMEs, as well as, taking into account cross-border interoperability and interoperability with existing digital solutions at both Union and Member State level. |
Or. en
Amendment 41
Proposal for a regulation
Recital 50
| Text proposed by the Commission | Amendment |
|---|---|
| (50) To ensure that the European Business Wallets ecosystem continues to meet the needs of economic operators and public sector bodies, it is necessary to assess its implementation and impact in light of the purpose of this Regulation. The evaluation should, in particular, take into account the risk of legal fragmentation within the internal market regarding the electronic submission of documents and attestations of attributes as well as the technological developments and progression of the market for European Business Wallets and associated trust services. | (50) To ensure that the European Business Wallets ecosystem continues to meet the needs of economic operators and public sector bodies, it is necessary to assess its implementation and impact in light of the purpose of this Regulation. The evaluation should, in particular, take into account the risk of legal fragmentation within the internal market regarding the electronic submission of documents and attestations of attributes as well as the technological developments and progression of the market for European Business Wallets and associated trust services. The evaluation should furthermore assess whether this Regulation has reduced administrative burdens and compliance costs, especially for SMEs and smaller public sector bodies, supported the wide uptake of European Business Wallets and their respective usage for cross-border business enhanced competitiveness, as well as, facilitated fraud reduction and environmental sustainability. |
Or. en
Amendment 42
Proposal for a regulation
Recital 54
| Text proposed by the Commission | Amendment |
|---|---|
| (54) In order to ensure uniform conditions for the implementation of the recognition and interoperability of business wallets or similar systems and framework from third countries to support and promote partnerships and cooperation, implementing powers should be conferred on the Commission to set the conditions under which such similar systems or framework benefit from the provisions of this Regulation. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council. | (54) In order to ensure uniform conditions for the implementation of the recognition and interoperability of business wallets or similar systems and framework from third countries to support and promote partnerships and cooperation, implementing powers should be conferred on the Commission to set the conditions under which such similar systems or framework benefit from the provisions of this Regulation. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council. Whereas it is important that companies established outside the Union pursuing economic activities within the Union are able to obtain European Business Wallets, it is equally important to ensure that the European Business Wallets can be accepted by third countries. Therefore, the Commission should endeavour to negotiate mutual recognition agreements with the third countries, where appropriate. |
Or. en
Amendment 43
Proposal for a regulation
Recital 57
| Text proposed by the Commission | Amendment |
|---|---|
| (57) To ensure a coherent and horizontal application across sectors of Union legislation, reduce administrative cost on economic operators and to improve budgetary efficiency, Union law concerning electronic identification, authentication, or the exchange of electronic documents, notifications, or attestations of attributes, particularly where specific technical requirements, systems, or protocols are established, should be applied in a manner consistent with this Regulation. Accordingly, any future legislative or non-legislative initiatives in these fields should adhere to the Business-Wallet-by-Default principle and should be designed and developed to build upon and enable the use of European Business Wallets. Where such alignment is not possible, the Commission should provide a written justification through an Impact Assessment, accompanying the relevant initiative, setting out the reasons for not enabling the use of European Business Wallets. The Commission should evaluate and review this Regulation by [Publications Office, please insert the date 3 years post adoption] and every four years thereafter and report to the European Parliament and the Council. This review is essential for assessing the continued relevance of the prescribed core functions and technical specifications, especially those associated with the QERDS as a secure communication channel, in the context of the latest technological advancements. Furthermore, the Commission should evaluate the notification procedures for providers of European Business Wallet, as well as the implementation and effectiveness of the rules on penalties established by Member States, to evaluate market developments and compliance levels. | (57) To ensure a coherent and horizontal application across sectors of Union legislation, reduce administrative cost on economic operators and to improve budgetary efficiency, Union law concerning electronic identification, authentication, or the exchange of electronic documents, notifications, or attestations of attributes, particularly where specific technical requirements, systems, or protocols are established, should be applied in a manner consistent with this Regulation. Accordingly, any future legislative or non-legislative initiatives in these fields should adhere to the Business-Wallet-by-Default principle and should be designed and developed to build upon and enable the use of European Business Wallets. Where such alignment is not possible, the Commission should provide a written justification through an Impact Assessment, accompanying the relevant initiative, setting out the reasons for not enabling the use of European Business Wallets. |
Or. en
Amendment 44
Proposal for a regulation
Recital 57 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (57a) The Commission should evaluate and review this Regulation by ... [three years from the date of entry into force of this Regulation] and every four years thereafter and report to the European Parliament and the Council. This review is essential for assessing the continued relevance of the prescribed core functions and technical specifications, especially those associated with the QERDS as a secure communication channel, in the context of the latest technological advancements. Furthermore, the Commission should evaluate the notification procedures for providers of European Business Wallet, as well as the implementation and effectiveness of the rules on penalties established by Member States, to evaluate market developments and compliance levels. The Commission should assess the overall uptake of European Business Wallets and evaluate the achievement of the expected indirect benefits. Based on the results, the Commission should evaluate whether it is necessary to modify the scope of this Regulation or its specific provisions. Any such modification should be accompanied by an Impact Assessment. |
Or. en
Amendment 45
Proposal for a regulation
Article 1 – paragraph 1 – point 2
| Text proposed by the Commission | Amendment |
|---|---|
| (2) establishes the principle of equivalence, giving equivalent legal effect to actions and transactions carried out through a European Business Wallet as to actions and transactions lawfully carried out in person, in paper form, or via any other means or processes that would be deemed compliant with applicable legal, administrative, or procedural requirements; | (2) establishes the principle of equivalence, giving equivalent legal effect to actions and transactions carried out via qualified trust services through a European Business Wallet as to actions and transactions lawfully carried out in person, in paper form, or via any other means or processes that would be deemed compliant with applicable legal, administrative, or procedural requirements; |
Or. en
Amendment 46
Proposal for a regulation
Article 1 – paragraph 1 – point 8
| Text proposed by the Commission | Amendment |
|---|---|
| (8) provides a framework for the supervision of Union entities, where such public sector bodies provide European Business Wallets; | (8) provides a framework for the supervision of Union entities, where such public sector bodies provide European Business Wallets to other Union entities; |
Or. en
Amendment 47
Proposal for a regulation
Article 1 – paragraph 1 – point 9
| Text proposed by the Commission | Amendment |
|---|---|
| (9) provides a framework for the recognition of third-country systems similar to the European Business Wallets and the issuance of European Business Wallets to third country economic operators. | (9) provides a framework for the recognition of third-country systems similar to the European Business Wallets which offer the same level of security, trust and digital standards as European Business Wallets, and the issuance of European Business Wallets to third country economic operators. |
Or. en
Amendment 48
Proposal for a regulation
Article 3 – paragraph 1 – point 1 – subparagraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| ‘European Business Wallet’ means a digital solution that allows European Business Wallet owners to securely store, manage, and present European Business Wallet owner identification data and electronic attestations of attributes to Business Wallet-relying parties and other entities using European Business Wallets and European Digital Identity Wallets for the following purposes: | ‘European Business Wallet’ means a digital solution that allows European Business Wallet owners to securely request, obtain, combine, store, manage, and present European Business Wallet owner identification data and electronic attestations of attributes to Business Wallet-relying parties and other entities using European Business Wallets and European Digital Identity Wallets for the following purposes: |
Or. en
Amendment 49
Proposal for a regulation
Article 3 – paragraph 1 – point 1 – subparagraph 1 – point a
| Text proposed by the Commission | Amendment |
|---|---|
| (a) to authenticate and provide the verified proofs required by a relying party; | (a) to authenticate and provide the verified proofs required by a European Business Wallet-relying party; |
Or. en
Amendment 50
Proposal for a regulation
Article 3 – paragraph 1 – point 1 – subparagraph 1 – point c
| Text proposed by the Commission | Amendment |
|---|---|
| (c) to enable the creation, management and delegation of mandates to authorised representatives; | (c) to enable the creation, management and delegation of mandates and roles to authorised representatives and users; |
Or. en
Amendment 51
Proposal for a regulation
Article 3 – paragraph 1 – point 1 – subparagraph 1 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| and that may issue electronic attestations of attributes relating to data for which the European Business Wallet owner is the primary source, |
Or. en
Amendment 52
Proposal for a regulation
Article 3 – paragraph 1 – point 7
| Text proposed by the Commission | Amendment |
|---|---|
| (7) ‘European Business Wallet owner’ means an economic operator or public sector body that owns or has a right of use of a European Business Wallet; | (7) ‘European Business Wallet owner’ means an economic operator or public sector body whose identity has been verified from an authentic source that owns or has a right of use of a European Business Wallet; |
Or. en
Amendment 53
Proposal for a regulation
Article 3 – paragraph 1 – point 11
| Text proposed by the Commission | Amendment |
|---|---|
| (11) ‘qualified attestation of attributes’ means qualified attestation of attributes as defined in Article 3, point (45) of Regulation (EU) No 910/2014; | (11) ‘qualified electronic attestation of attributes’ means qualified electronic attestation of attributes as defined in Article 3, point (45) of Regulation (EU) No 910/2014; |
Or. en
Amendment 54
Proposal for a regulation
Article 3 – paragraph 1 – point 17
| Text proposed by the Commission | Amendment |
|---|---|
| (17) ‘qualified electronic stamp’ means a qualified electronic stamp as defined in Article 3, point (34) of Regulation (EU) No 910/2014; | (17) ‘qualified electronic time stamp’ means a qualified electronic time stamp as defined in Article 3, point (34) of Regulation (EU) No 910/2014; |
Or. en
Amendment 55
Proposal for a regulation
Article 3 – paragraph 1 – point 19 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (19a) ‘automated transaction’ means a transaction executed by an authorised digital or AI-driven agent, performing actions under a valid, auditable and revocable authorisation issued by the European Business Wallet owner or authorised user; |
Or. en
Amendment 56
Proposal for a regulation
Article 3 – paragraph 1 – point 22
| Text proposed by the Commission | Amendment |
|---|---|
| (22) ‘user’ means a natural or legal person, or a natural person representing another natural person or a legal person, that uses European Business Wallets or European Business Wallet electronic identification means provided in accordance with this Regulation; | (22) ‘user’ means a natural or legal person, or a natural person representing another natural person or a legal person, that uses European Business Wallets provided in accordance with this Regulation; |
Or. en
Amendment 57
Proposal for a regulation
Article 3 – paragraph 1 – point 24
| Text proposed by the Commission | Amendment |
|---|---|
| (24) ‘wallet unit attestation’ means a data object that describes the components of the European Business Wallet unit or allows authentication and validation of those components; | (24) ‘European Business Wallet unit attestation’ means a data object that describes the components of the European Business Wallet unit or allows authentication and validation of those components; |
Or. en
Amendment 58
Proposal for a regulation
Article 3 – paragraph 1 – point 27
| Text proposed by the Commission | Amendment |
|---|---|
| (27) ‘critical assets’ means assets within or in relation to a European Business Wallet unit of such extraordinary importance that where their availability, confidentiality or integrity are compromised, that would have a very serious, debilitating effect on the ability to rely on the European Business Wallet unit; | (27) ‘critical assets’ means assets within or in relation to a European Business Wallet unit of such extraordinary importance that where their availability, confidentiality or integrity are compromised, that would have a very serious, debilitating effect on the ability to rely on the European Business Wallet unit or have significant operational, financial or reputational impact on the European Business Wallet owner; |
Or. en
Amendment 59
Proposal for a regulation
Article 3 – paragraph 1 – point 43 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (43a) ‘supporting infrastructure service provider‘ means a service provider that provides technical, operational, or security infrastructure essential for the provision of European Business Wallets, without itself providing the wallet for end-users. Such providers include entities such as cloud service providers supplying hosting services, cryptographic key management, secure communication networks or identity verification tools. |
Or. en
Amendment 60
Proposal for a regulation
Article 4 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| Where a European Business Wallet owner makes use of any of the core functionalities of a European Business Wallet referred to in Article 5(1), the resulting action shall have the same legal effect as if the action had been lawfully carried out in person, in paper form, or via any other means or processes that would be deemed compliant with applicable legal, administrative, or procedural requirements. | Where a European Business Wallet owner makes use of any of the core functionalities of a European Business Wallet referred to in Article 5(1) that are based on qualified trust services the resulting action shall have the same legal effect as if the action had been lawfully carried out in person, in paper form, or via any other means or processes that would be deemed compliant with applicable legal, administrative, or procedural requirements. |
Or. en
Amendment 61
Proposal for a regulation
Article 5 – paragraph 1 – point a
| Text proposed by the Commission | Amendment |
|---|---|
| (a) securely issue, request, obtain, select, combine, store, delete, share and present electronic attestations of attributes; | (a) securely request, obtain, select, combine, store, delete, share and present electronic attestations of attributes; |
Or. en
Amendment 62
Proposal for a regulation
Article 5 – paragraph 1 – point f
| Text proposed by the Commission | Amendment |
|---|---|
| (f) issue electronic attestations of attributes to European Business Wallets and European Digital Identity Wallets; | (f) issue electronic attestations of attributes for data for which the European Business Wallet owner is the primary source to European Business Wallets and European Digital Identity Wallets; |
Or. en
Amendment 63
Proposal for a regulation
Article 5 – paragraph 1 – point i
| Text proposed by the Commission | Amendment |
|---|---|
| (i) transmit and receive electronic documents and data by means of a qualified electronic registered delivery service capable of supporting confidentiality and integrity; | (i) transmit and receive electronic documents and data by means of a qualified electronic registered delivery service, which complies with Article 7(2) and the requirements set out in the Annex, and is capable of supporting confidentiality and integrity; |
Or. en
Amendment 64
Proposal for a regulation
Article 5 – paragraph 1 – point j
| Text proposed by the Commission | Amendment |
|---|---|
| (j) authorise multiple users to access and operate the European Business Wallet of the owner, and for the European Business Wallet owner to manage and revoke such authorisations; | (j) authorise multiple users to access and operate the European Business Wallet of the owner, with the possibility to create auditable and clearly defined and restricted delegations of powers, mandates and roles and for the European Business Wallet owner to manage and revoke such authorisations; |
Or. en
Amendment 65
Proposal for a regulation
Article 5 – paragraph 1 – point k
| Text proposed by the Commission | Amendment |
|---|---|
| (k) authorise European Business Wallet-relying parties to request electronic attestations of attributes issued to the European Business Wallet owner, and for the European Business Wallet owner to manage and revoke such authorisations; | (k) authorise European Business Wallet-relying parties to request electronic attestations of attributes issued to the European Business Wallet owner, which are strictly necessary for the purpose of the transaction and prevent unnecessary processing, and for the European Business Wallet owner to manage and revoke such authorisations; |
Or. en
Amendment 66
Proposal for a regulation
Article 5 – paragraph 1 – point l
| Text proposed by the Commission | Amendment |
|---|---|
| (l) export their data, including issued European Business Wallet owner identification data, electronic attestations of attributes, communication logs, and interaction records, in a structured, commonly used and machine-readable format, at the request of the owner or in the event of termination of service or revocation of the notification of the provider of the European Business Wallet; | (l) export their data, including issued European Business Wallet owner identification data, electronic attestations of attributes, communication logs, and interaction records, in a structured, commonly used and machine-readable format, at the request of the owner or in the event of termination of service or revocation of the notification of the provider of the European Business Wallet and to import the data exported from a European Business Wallet unit to enable data portability across providers of European Business Wallets; |
Or. en
Amendment 67
Proposal for a regulation
Article 5 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Providers of European Business Wallets may offer additional functionalities beyond those listed in paragraph 1 provided that such functionalities do not interfere with or compromise the confidentiality, availability, or integrity of the minimum core functionalities, and the reliability and interoperability of the European Business Wallets they provide. | 2. Providers of European Business Wallets may offer additional functionalities beyond those listed in paragraph 1 provided that such functionalities adhere to the security requirements set out in Article 6(2), point (c), and do not interfere with or compromise the confidentiality, availability, or integrity of the minimum core functionalities, and the reliability and interoperability of the European Business Wallets they provide. |
Or. en
Amendment 68
Proposal for a regulation
Article 5 – paragraph 5
| Text proposed by the Commission | Amendment |
|---|---|
| 5. The Commission shall, by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the core functionalities of European Business Wallets referred to in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 5. The Commission shall, by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the core functionalities of European Business Wallets referred to in paragraph 1 of this Article, including for wallet-to-wallet transactions between European Business Wallets and European Digital Identity Wallets. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Or. en
Amendment 69
Proposal for a regulation
Article 6 – title
| Text proposed by the Commission | Amendment |
|---|---|
| Technical features for European Business Wallets | Technical requirements for European Business Wallets |
Or. en
Amendment 70
Proposal for a regulation
Article 6 – paragraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Providers of European Business Wallets shall ensure that the European Business Wallets they provide support common protocols and interfaces: | 1. Providers of European Business Wallets shall ensure compliance with the reference standards and specifications set out in paragraph 5 and the technical requirements set out in the Annex to support common protocols and interfaces: |
Or. en
Amendment 71
Proposal for a regulation
Article 6 – paragraph 1 – point b
| Text proposed by the Commission | Amendment |
|---|---|
| (b) for European Business Wallet-relying parties to request and validate European Business Wallet owner identification data and electronic attestations of attributes; | deleted |
Or. en
Amendment 72
Proposal for a regulation
Article 6 – paragraph 1 – point c
| Text proposed by the Commission | Amendment |
|---|---|
| (c) for the sharing and presenting to European Business Wallet-relying parties of European Business Wallet owner identification data, electronic attestation of attributes and of selectively disclosed data; | (c) for the validating, sharing and presenting to European Business Wallet-relying parties of European Business Wallet owner identification data, electronic attestation of attributes and of selectively disclosed data; |
Or. en
Amendment 73
Proposal for a regulation
Article 6 – paragraph 1 – point d
| Text proposed by the Commission | Amendment |
|---|---|
| (d) to allow interaction with the European Business Wallets automatically without manual intervention or through direct user action; | (d) to allow interaction with the European Business Wallets automatically without manual intervention or through direct user action such automated processes should be verifiable and auditable and ensure an equivalent level of assurance and accountability as interactions performed by an authorised user; |
Or. en
Amendment 74
Proposal for a regulation
Article 6 – paragraph 1 – point e
| Text proposed by the Commission | Amendment |
|---|---|
| (e) to securely onboard the European Business Wallet owner remotely via an authorised representative with an electronic identification means of that authorised representative which meets the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels ‘substantial’ or ‘high’; | (e) to securely onboard the European Business Wallet owner or an authorised representative of the European Business Wallet owner remotely with an electronic identification means which meets the requirements of Regulation (EU) No 910/2014 with regard to the assurance level ‘high’; |
Or. en
Amendment 75
Proposal for a regulation
Article 6 – paragraph 1 – point f
| Text proposed by the Commission | Amendment |
|---|---|
| (f) for interaction between European Business Wallets, and between European Business Wallets and European Digital Identity Wallets for the purpose of receiving, validating and sharing European Business Wallet owner identification data and electronic attestations of attributes in a secure manner; | (f) for multidirectional interaction between European Business Wallets, and between European Business Wallets and European Digital Identity Wallets for the purpose of receiving, validating and sharing European Business Wallet owner identification data and electronic attestations of attributes in a secure manner; |
Or. en
Amendment 76
Proposal for a regulation
Article 6 – paragraph 1 – point h
| Text proposed by the Commission | Amendment |
|---|---|
| (h) for European Business Wallet-relying parties to verify the authenticity and validity of European Business Wallets, where the verification of the authenticity and validity is required; | (h) to verify the authenticity and validity of European Business Wallets; |
Or. en
Amendment 77
Proposal for a regulation
Article 6 – paragraph 1 – point l
| Text proposed by the Commission | Amendment |
|---|---|
| (l) for the management of critical assets, for the use of at least one wallet secure cryptographic application and wallet secure cryptographic device and, where critical assets relate to performing electronic identification at assurance level substantial, for ensuring that such cryptographic operators or other operations processing critical assets are performed in accordance with the requirements for the characteristics and design of electronic identification means at assurance level substantial as set out in Commission Implementing Regulation (EU) 2015/1502. | deleted |
Or. en
Amendment 78
Proposal for a regulation
Article 6 – paragraph 2 – point a
| Text proposed by the Commission | Amendment |
|---|---|
| (a) ensure that the European Business Wallet owner identification data is digitally associated with the European Business Wallet of the owner; | (a) ensure that the European Business Wallet owner identification data is cryptographically bound with the European Business Wallet of the owner; |
Or. en
Amendment 79
Proposal for a regulation
Article 6 – paragraph 2 – point c
| Text proposed by the Commission | Amendment |
|---|---|
| (c) ensure security-by-design; | (c) ensure security-by-design and implement and document security controls that provide reasonable assurance ; |
Or. en
Amendment 80
Proposal for a regulation
Article 6 – paragraph 2 – point d
| Text proposed by the Commission | Amendment |
|---|---|
| (d) provide validation mechanisms, in order to ensure that the authenticity and validity of European Business Wallets can be verified; | deleted |
Or. en
Amendment 81
Proposal for a regulation
Article 6 – paragraph 2 – point f – indent 1
| Text proposed by the Commission | Amendment |
|---|---|
| – upon the explicit request of the European Business Wallet owner; | – upon the explicit request of the European Business Wallet owner or authorised user; |
Or. en
Amendment 82
Proposal for a regulation
Article 6 – paragraph 2 – point f – indent 2 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| – where the security of the provider of the European Business Wallet as trust service provider, pursuant to Article 19 of Regulation (EU) 910/2014, has been compromised; |
Or. en
Amendment 83
Proposal for a regulation
Article 6 – paragraph 2 – point f – indent 4
| Text proposed by the Commission | Amendment |
|---|---|
| – where the provider of the European Business Wallet is not included in the list referred to in Article 12(5). | – where the provider of the European Business Wallet is not included in the list referred to in Article 12(3). |
Or. en
Amendment 84
Proposal for a regulation
Article 6 – paragraph 4
| Text proposed by the Commission | Amendment |
|---|---|
| 4. Providers of European Business Wallets shall implement the technical features provided for in paragraphs 1 and 2 in accordance with the requirements set out in the Annex. | 4. Providers of European Business Wallets shall implement the technical requirements provided for in paragraphs 1 and 2 in accordance with the requirements set out in the Annex and implementing acts, pursuant to paragraph 5. |
Or. en
Amendment 85
Proposal for a regulation
Article 6 – paragraph 5
| Text proposed by the Commission | Amendment |
|---|---|
| 5. The Commission shall, by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the technical features of European Business Wallets provided for in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 5. The Commission shall, by means of implementing acts, establish a list of reference standards and where necessary, establish specifications and procedures for the technical requirements of European Business Wallets including those critical for interoperability and security, provided for in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Or. en
Amendment 86
Proposal for a regulation
Article 7 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. European Business Wallets shall be provided by providers of European Business Wallets that are included in the list established pursuant to Article 12(5). | 1. European Business Wallets shall be provided by providers of European Business Wallets that are included in the list established pursuant to Article 12(3). |
Or. en
Amendment 87
Proposal for a regulation
Article 7 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Given the role of European Business Wallets in the Unions digital infrastructure, providers of European Business Wallets shall be established in the Union, have their principal place of business and main operations in the Union and not present a risk to the security of the Union. In particular they shall not be subject to control by a third country or by a third-country entity. | 2. Given the role of European Business Wallets in the Union’s digital infrastructure, providers of European Business Wallets and supporting infrastructure service providers that host European Business Wallets data shall be established in the Union, have their principal place of business and main operations in the Union and not present a risk to the security of the Union. In particular they shall not be subject to control by a third country or by a third-country entity. European Business Wallets data shall be exclusively stored and processed in the Union. |
Or. en
Amendment 88
Proposal for a regulation
Article 7 – paragraph 5
| Text proposed by the Commission | Amendment |
|---|---|
| 5. Providers of European Business Wallets shall comply with applicable cybersecurity requirements laid down in Union and national law, including those relating to the identification of high-risk suppliers. Providers shall also ensure that their suppliers of software and security solutions comply with these requirements and conform to the relevant security standards and requirements. | 5. Providers of European Business Wallets shall comply with applicable cybersecurity requirements laid down in Union and national law, including Regulation ... [ Cybersecurity Act 2 as proposed in COM (2026)11] and those relating to the identification of high-risk suppliers. Providers shall also ensure that their suppliers of software and security solutions comply with these requirements and conform to the relevant security standards and requirements. |
Or. en
Amendment 89
Proposal for a regulation
Article 7 – paragraph 6 – point c
| Text proposed by the Commission | Amendment |
|---|---|
| (c) ensure that authorised representatives of European Business Wallet owners are clearly informed, in a user-friendly, concise and accessible manner, about their rights and obligations in relation to their European Business Wallet unit, in particular, the right to request revocation of their wallet unit attestation, using the authentication mechanism provided in point 1 of the Annex; | (c) ensure that European Business Wallet owners and their authorised representatives are clearly informed, in a user-friendly, concise and accessible manner, about their rights and obligations in relation to their European Business Wallet unit, in particular, the right to request revocation of their European Business wallet unit attestation, using the authentication mechanism provided in point 1 of the Annex; |
Or. en
Amendment 90
Proposal for a regulation
Article 7 – paragraph 6 – point d
| Text proposed by the Commission | Amendment |
|---|---|
| (d) cooperate with the competent supervisory bodies referred to in Article 13(1), or with the Commission in the cases referred to in Article 13(10) and 14(1) and respond without undue delay to any request for information or documentation necessary to verify compliance with this Regulation; | (d) cooperate with the competent supervisory bodies referred to in Article 13(1), or with the Commission in the cases referred to in Article 13(10) and 15(1) and respond without undue delay to any request for information or documentation necessary to verify compliance with this Regulation; |
Or. en
Amendment 91
Proposal for a regulation
Article 7 – paragraph 6 – point e
| Text proposed by the Commission | Amendment |
|---|---|
| (e) notify the relevant national supervisory bodies, or the Commission in the cases referred to in Article 14(1), of any substantive changes to their services or overall structure which may impact the compliance of the provider with this Regulation; | (e) notify without undue delay the relevant national supervisory bodies, or the Commission in the cases referred to in Article 15(1), of any substantive changes to their services, including the intention to suspend or terminate services, or overall structure which may impact the compliance of the provider with this Regulation; |
Or. en
Amendment 92
Proposal for a regulation
Article 8 – paragraph 3 – point b
| Text proposed by the Commission | Amendment |
|---|---|
| (b) electronic attestations of attributes issued by or on behalf of a public sector body responsible for an authentic source, when provided by a public sector body so responsible; | (b) electronic attestations of attributes issued by or on behalf of a public sector body responsible for an authentic source; |
Or. en
Amendment 93
Proposal for a regulation
Article 8 – paragraph 7
| Text proposed by the Commission | Amendment |
|---|---|
| 7. The Commission may, by means of implementing acts, set out requirements for European Business Wallet owner identification data issued pursuant to this Article, including procedures for Member States to notify to the Commission the relevant authentic sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 7. The Commission may, by means of implementing acts, set out harmonised requirements for European Business Wallet owner identification data issued pursuant to this Article, including procedures for Member States to notify to the Commission the relevant authentic sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Or. en
Amendment 94
Proposal for a regulation
Article 9 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Where an economic operator or public sector body has not been attributed a European Unique Identifier, a unique identifier shall be created in accordance with the implementing act referred to in paragraph 4. | 2. Where an economic operator or public sector body has not been attributed a European Unique Identifier, a unique identifier shall upon request by the economic operator be created without undue delay in accordance with the implementing act referred to in paragraph 4. |
Or. en
Amendment 95
Proposal for a regulation
Article 10 – paragraph 1 – point b
| Text proposed by the Commission | Amendment |
|---|---|
| (b) a secure, web-based platform that provides access to authenticated and authorised users and system online portal for European Business Wallet users. | (b) a secure, web-based platform that provides access to authenticated and authorised users via an online portal for European Business Wallet users. |
Or. en
Amendment 96
Proposal for a regulation
Article 10 – paragraph 4
| Text proposed by the Commission | Amendment |
|---|---|
| 4. The Commission shall make the European Digital Directory only accessible to European Business Wallet owners and their authorised representatives and providers of European Business Wallets. | 4. The Commission shall make the European Digital Directory only accessible to European Business Wallet owners and their authorised representatives and providers of European Business Wallets and relevant Member State authorities. |
Or. en
Amendment 97
Proposal for a regulation
Article 11 – paragraph 2 – point c a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (ca) information on of how the provider is compliant with Article 7(2) and (5) |
Or. en
Amendment 98
Proposal for a regulation
Article 11 – paragraph 2 – point d
| Text proposed by the Commission | Amendment |
|---|---|
| (d) a description of any additional functionalities supported by the European Business Wallets the entity intends to provide; | (d) a description of any additional functionalities supported by the European Business Wallets the entity intends to provide and a description of how they are compliant with the security-by-design technical requirement set out in Article 6(2), point (c); |
Or. en
Amendment 99
Proposal for a regulation
Article 11 – paragraph 3
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Qualified trust service providers shall not be subject to the review and verification procedure set out in paragraphs 4 to 6. Upon submitting the information listed in paragraph 2, the competent supervisory body shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(5) and it may immediately offer European Business Wallets. | deleted |
Or. en
Justification
As providers of Qualified Trust Service Providers are not subject to exactly the same rules as European Business Wallets providers, the review and verification procedure set out in paragraphs 4 to 6 should not be waived.
Amendment 100
Proposal for a regulation
Article 11 – paragraph 4 – subparagraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| When that review leads the supervisory body to conclude that the information is complete and the description referred to in paragraph 2 point (c) appears to correspond to the requirements laid down in Article 5(1), it shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(5). | When that review leads the supervisory body to conclude that the information is complete and the relevant requirements of this Regulation are met, the supervisory body shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(3). |
Or. en
Amendment 101
Proposal for a regulation
Article 11 – paragraph 5
| Text proposed by the Commission | Amendment |
|---|---|
| 5. When that review leads the supervisory body to conclude that the information is not complete or the description referred to in paragraph 2 point (c) appears not to correspond to the requirements laid down in Article 5(1), it shall request additional information or explanations from the notifying entity and set a reasonable deadline, not exceeding 15 calendar days, for response. If that information or those explanations allow the supervisory body to conclude that the information is complete and the description referred to in paragraph 2 point (c) appears to correspond to the requirements laid down in Article 5(1), it shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(5). If not, or no response is received, the supervisory body shall inform the notifying entity that it will not be added to the list referred to in Article 12(5). | 5. When that review leads the supervisory body to conclude that the information is not complete or the relevant requirements laid down in this Regulation are not met, it shall request additional information or explanations from the notifying entity and set a reasonable deadline, not exceeding 15 calendar days, for response. If that information or those explanations allow the supervisory body to conclude that the information is complete and that the relevant requirements laid down in this Regulation are met, it shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(3). If not, or no response is received, the supervisory body shall inform the notifying entity that it will not be added to the list referred to in Article 12(3). |
Or. en
Amendment 102
Proposal for a regulation
Article 11 – paragraph 6
| Text proposed by the Commission | Amendment |
|---|---|
| 6. Where the supervisory body has not provided the notifying entity with a substantive response on the outcome of the review referred to in paragraph 4 within 30 calendar days of receiving the notification, the information shall be considered as complete and the description referred to in paragraph 2 point (c) shall be considered as appearing to correspond to the requirements laid down in Article 5(1), and the supervisory body shall inform the Commission within two working days with a view to the addition of that provider to the list referred to in Article 12(5) | 6. Where the supervisory body has not provided the notifying entity with a substantive response on the outcome of the review referred to in paragraph 4 within 30 calendar days of receiving the notification, the supervisory body shall inform the notifying entity of the reason for the delay and shall complete the review within an additional 15 calendar days. When that review leads to the conclusion by the supervisory body that all information is complete and the relevant requirements of this Regulation are met, the Commission shall within two working days add that provider to the list referred to in Article 12(3). |
Or. en
Amendment 103
Proposal for a regulation
Article 12 – paragraph 2 – point a – indent 1
| Text proposed by the Commission | Amendment |
|---|---|
| – the registration of a notified provider of European Business Wallets not previously present on the list referred to in paragraph 5; | – the registration of a notified provider of European Business Wallets not previously present on the list referred to in paragraph 3; |
Or. en
Amendment 104
Proposal for a regulation
Article 12 – paragraph 2 – point a – indent 2
| Text proposed by the Commission | Amendment |
|---|---|
| – a change to previously submitted information regarding providers of European Business Wallets currently present on the list referred to in paragraph 5; | – a change to previously submitted information regarding providers of European Business Wallets currently present on the list referred to in paragraph 3; |
Or. en
Amendment 105
Proposal for a regulation
Article 12 – paragraph 2 – point a – indent 3
| Text proposed by the Commission | Amendment |
|---|---|
| – a request to remove a provider of European Business Wallets from the list referred to in paragraph 5; | – a request to remove a provider of European Business Wallets from the list referred to in paragraph 3; |
Or. en
Amendment 106
Proposal for a regulation
Article 12 – paragraph 2 – point e
| Text proposed by the Commission | Amendment |
|---|---|
| (e) an indication whether the provider of European Business Wallets is a qualified trust service provider. | (e) an indication whether the provider of European Business Wallets is a qualified trust service provider complying with Article 7(2) of this Regulation. |
Or. en
Amendment 107
Proposal for a regulation
Article 12 – paragraph 3
| Text proposed by the Commission | Amendment |
|---|---|
| 3. On the basis of the information received pursuant to this Article, the Commission shall establish and maintain on the Commission’s website, in a machine-readable format, a list of providers of European Business Wallets. | 3. On the basis of the information received pursuant to this Article, the Commission shall establish and maintain on the Commission’s website, in a machine-readable format, a list of providers of European Business Wallets. Based on the information received, the Commission shall decide to add or revoke a provider and update the list within 24 hours of receiving the information. |
Or. en
Amendment 108
Proposal for a regulation
Article 13 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. In each Member State, the supervisory bodies designated pursuant to Article 46a of Regulation (EU) No 910/2014 shall also be the supervisory bodies for the purposes of this Regulation. | 1. Member States shall ensure effective governance and supervision of providers of European Business Wallets. For this purpose, each Member State shall designate a supervisory body for the purposes of this Regulation. |
Or. en
Amendment 109
Proposal for a regulation
Article 13 – paragraph 1 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. Member States shall notify to the Commission the names and the addresses of their supervisory bodies designated pursuant to paragraph 1 and any subsequent changes thereto. The Commission shall publish a list of the notified supervisory bodies. |
Or. en
Amendment 110
Proposal for a regulation
Article 13 – paragraph 5 – point c
| Text proposed by the Commission | Amendment |
|---|---|
| (c) verify the existence and correct application of termination plans where a provider of European Business Wallets ceases its activities, including how information is kept accessible; | (c) verify the existence and correct application of termination plans where a provider of European Business Wallets ceases its activities, including how information is kept accessible and how data export will be enabled in accordance with Article 5(1), point (l); |
Or. en
Amendment 111
Proposal for a regulation
Article 13 – paragraph 5 – point f
| Text proposed by the Commission | Amendment |
|---|---|
| (f) inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant security breach or loss of integrity of which it becomes aware in the performance of its tasks and, in the case of a significant security breach or loss of integrity which concerns other Member States, to inform the single point of contact designated or established pursuant to Article 8(3) Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of Regulation (EU) No 910/2014 in the other Member States concerned, and to inform the public or require the provider of European Business Wallets to do so where the supervisory body determines that disclosure of the breach of security or loss of integrity would be in the public interest; | (f) inform the relevant competent authorities designated or established pursuant to Article 8(1) of Directive (EU) 2022/2555 of the Member States concerned of any significant incident of which it becomes aware in the performance of its tasks and, in the case of a significant incident which concerns other Member States, to inform the single point of contact designated or established pursuant to Article 8(3) Directive (EU) 2022/2555 of the Member State concerned and the single points of contact designated pursuant to Article 46c(1) of Regulation (EU) No 910/2014 in the other Member States concerned, and to inform the public or require the provider of European Business Wallets to do so where the supervisory body determines that disclosure of the breach of security or loss of integrity would be in the public interest; |
Or. en
Amendment 112
Proposal for a regulation
Article 13 – paragraph 5 – point k
| Text proposed by the Commission | Amendment |
|---|---|
| (k) revoke the inclusion in the list established pursuant to Article 12(5) of a provider of European Business Wallets if the supervisory body determines that the provider no longer meets the requirements laid down in this Regulation or that the provider has failed to comply with the obligations imposed by this Regulation; | (k) request that the Commission revoke the inclusion in the list established pursuant to Article 12(3) of a provider of European Business Wallets if the supervisory body determines that the provider no longer meets the requirements laid down in this Regulation or that the provider has failed to comply with the obligations imposed by this Regulation; |
Or. en
Amendment 113
Proposal for a regulation
Article 13 – paragraph 11
| Text proposed by the Commission | Amendment |
|---|---|
| 11. Based on the evaluation, the Commission may decide that a corrective or restrictive measure is necessary, and after consulting the Member States concerned and the provider, the Commission may determine the appropriate course of action. The Commission shall take into account the nature and severity of the non-compliance, as well as the potential impact on the internal market and the rights of economic operators. | 11. Based on the evaluation, the Commission may decide that a corrective or restrictive measure is necessary, and after consulting the Member States concerned and the provider, the Commission may determine the appropriate course of action and shall provide appropriate justifications for the chosen action to the Member State and provider concerned. The Commission shall take into account the nature and severity of the non-compliance, as well as the potential impact on the internal market and the rights of economic operators. |
Or. en
Amendment 114
Proposal for a regulation
Article 13 – paragraph 12
| Text proposed by the Commission | Amendment |
|---|---|
| 12. On the basis of the consultation, the Commission may adopt implementing acts to provide for corrective or restrictive measures, including temporarily suspending the provider from the list of notified providers or requiring the provider to take specific actions to bring the European Business Wallets into compliance with the Regulation. Those implementing acts shall be adopted in accordance with the examination procedure. | 12. On the basis of the consultation, the Commission may adopt implementing acts to provide for corrective or restrictive measures, including temporarily suspending the provider from the list of notified providers or requiring the provider to take specific actions to bring the European Business Wallets into compliance with the Regulation. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Or. en
Amendment 115
Proposal for a regulation
Article 15 – title
| Text proposed by the Commission | Amendment |
|---|---|
| Governance and supervision of Union entities that are providers of European Business Wallets | Governance and supervision of Union entities that provide European Business Wallets to other Union entities |
Or. en
Amendment 116
Proposal for a regulation
Article 15 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Where a Union entity is a provider of European Business Wallets the Commission shall be its supervisory body. | 1. Where a Union entity provides European Business Wallets to other Union entities the Commission shall be its supervisory body. |
Or. en
Amendment 117
Proposal for a regulation
Article 16 – paragraph 1 – subparagraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| By [Publications Office, please insert the date 24 months after the entry into force of this Regulation] public sector bodies shall enable economic operators to take the following actions by using the core functionalities of European Business Wallets as set out in Article 5(1): | By 24 months after the entry into force of the implementing acts referred to in Articles 5 and 6, public sector bodies shall enable economic operators to take the following actions by using the core functionalities of European Business Wallets as set out in Article 5(1): |
Or. en
Amendment 118
Proposal for a regulation
Article 16 – paragraph 1 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. Municipalities with 10,000 inhabitants or less shall be exempted from the obligations laid down in paragraph 1. However, such municipalities can voluntarily choose to have European Business Wallets and enable economic operators to take the actions listed in paragraph 1. |
Or. en
Amendment 119
Proposal for a regulation
Article 16 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. For the purposes of paragraph 1, points (c) and (d), public sector bodies shall have European Business Wallets, including the qualified electronic registered delivery service referred to in Article 5(1), point (i). | 2. For the purposes of paragraph 1, points (c) and (d), public sector bodies except those exempted under paragraph 1a shall have European Business Wallets, including the qualified electronic registered delivery service referred to in Article 5(1), point (i). |
Or. en
Amendment 120
Proposal for a regulation
Article 16 – paragraph 3 – subparagraph 1 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| By way of derogation from paragraph 2 and until [Publications Office, insert the date 36 months after entry into force of this Regulation], public sector bodies may choose not to offer the qualified electronic registered delivery service referred to in Article 5(1), point (i), and support instead other existing alternative solutions which enable economic operators to take the actions listed in paragraph 1, points (c) and (d), provided those solutions: | By way of derogation from paragraph 5 and until 36 months after the date of entry into force of the implementing acts referred to in Articles 5 and 6 , public sector bodies may choose not to offer the qualified electronic registered delivery service referred to in Article 5(1), point (i), and support instead other existing alternative solutions which enable economic operators to take the actions listed in paragraph 1, points (c) and (d), provided those solutions: |
Or. en
Amendment 121
Proposal for a regulation
Article 17 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The Commission may adopt implementing acts establishing that business wallets or systems offering similar functions that are issued by providers established in third countries are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that such business wallets or systems are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 1. The Commission may adopt implementing acts establishing that business wallets or systems offering similar functions that are issued by providers established in third countries and which offer the same level of cybersecurity and digital standards on authentication, data protection and data integrity as the European Business Wallets are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that such business wallets or systems are supported by reliable trust frameworks and are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Or. en
Amendment 122
Proposal for a regulation
Article 17 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The Commission may adopt implementing acts establishing that third country frameworks for systems offering similar functions as the European Business Wallets are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that the systems provided under that framework are interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. | 2. The Commission may adopt implementing acts establishing that third country frameworks for systems offering similar functions as the European Business Wallets, which offer the same level of cybersecurity and digital standards on authentication, data protection and data integrity, are to be considered as offering assurances that are equivalent to European Business Wallets issued in accordance with this Regulation, provided that the systems provided under that framework are supported by reliable trust frameworks and interoperable with the trust framework laid down in Regulation (EU) 910/2014 and allow for the support of at least an identification and authentication functionality and the exchange of electronic attestations of attributes. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 19. |
Or. en
Amendment 123
Proposal for a regulation
Article 17 – paragraph 2 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 2a. The equivalency decisions referred to in paragraphs 1 and 2 can cover a period not exceeding three years, during which the Commission shall endeavour to negotiate a mutual recognition agreement with the third country. |
Or. en
Amendment 124
Proposal for a regulation
Article 17 – paragraph 3
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Prior to the adoption of the implementing acts referred to in paragraphs 1 and 2, the Commission shall assess whether the assurances can be considered as equivalent to the requirements under this Regulation. | 3. Prior to the adoption of the implementing acts referred to in paragraphs 1 and 2, the Commission shall carry out a thorough assessment of the third-country business wallets, system or frameworks, assessing especially the equivalence of cybersecurity and data protection standards, and the independence of the providers or systems from the control of high-risk entities or third countries. Following the assessment, the Commission shall evaluate whether the assurances can be considered as equivalent to the requirements under this Regulation. |
Or. en
Amendment 125
Proposal for a regulation
Article 17 – paragraph 4
| Text proposed by the Commission | Amendment |
|---|---|
| 4. The Commission shall, where available information reveals that those assurances can no longer be considered as equivalent to the requirements under this Regulation, to the extent necessary, repeal, amend or suspend the act referred to in paragraphs 1 and 2 by means of an implementing act. | 4. The Commission shall, after the adoption of the implementing acts referred to in paragraphs 1 and 2, monitor that the third country business wallets, systems or frameworks continue to offer assurances that are equivalent. If a Member State identifies a risk regarding a third country system that has been recognised as equivalent under paragraph 1 or 2, it shall provide a report and refer the matter to the Commission. Where available information reveals that those assurances can no longer be considered as equivalent to the requirements under this Regulation, the Commission shall without undue delay and to the extent necessary, repeal, amend or suspend the act referred to in paragraphs 1 and 2 by means of an implementing act. |
Or. en
Amendment 126
Proposal for a regulation
Article 18 – paragraph 5 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| 5. Providers of European Business Wallet owner identification data may issue European Business Wallet owner identification data and unique identifiers pursuant to Articles 8 and 9 to economic operators established outside the Union, provided that: | 5. Providers of European Business Wallet owner identification data may issue European Business Wallet owner identification data and unique identifiers pursuant to Articles 8 and 9 to economic operators established outside the Union, provided that the provider of European Business Wallet owner identification data has confirmed that: |
Or. en
Amendment 127
Proposal for a regulation
Article 18 – paragraph 6 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 6a. The Commission shall establish a list of reference standards and, where necessary, establish specifications for issuing of European Business Wallet owner identification data, including unique identifiers, to economic operators established outside the Union as part of the implementing acts referred to in Articles 8(9) and 9(4). |
Or. en
Amendment 128
Proposal for a regulation
Article 21 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The Commission shall review the application of this Regulation and shall, by [Publications Office, insert the date – 3 years after entry into force], submit a report to the European Parliament and to the Council. The report shall evaluate the effectiveness of the provisions of this Regulation with regard to facilitating the submission of electronic documents and electronic attestations to public sector bodies, by the usage of the European Business Wallets, as well as technological, market, and legal developments. The report shall also assess whether it is necessary to modify the scope of this Regulation or its specific provisions to set out an obligation for the use of the European Business Wallets to address the risks of legal fragmentation. | 1. The Commission shall review the application of this Regulation and shall, by [Publications Office, insert the date – 3 years after entry into force], submit a report to the European Parliament and to the Council. The report shall evaluate the effectiveness of the provisions of this Regulation with regard to facilitating the secure digital identification and authentication of businesses, the submission of electronic documents and electronic attestations and the overall uptake and usage of the European Business Wallets within B2G, G2B and B2B interactions, as well as technological, market, and legal developments. The report shall assess whether the Regulation has reduced administrative burdens and compliance costs, especially for SMEs and smaller public sector bodies, supported cross-border business and competitiveness, as well as, facilitated fraud reduction and environmental sustainability. The report shall also evaluate the cross-border interoperability of the Business Wallets and interoperability with existing digital solutions at both Union and Member State level, including identifying any duplication or parallel systems. The report shall also assess whether it is necessary to modify the scope of this Regulation or its specific provisions to set out an obligation for the use of the European Business Wallets to address the risks of legal fragmentation. |
Or. en
Amendment 129
Proposal for a regulation
Article 21 – paragraph 2 – subparagraph 1 – point d a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (da) the adoption rate of the European Business Wallets, and relevant metrics on the use of European Business Wallets. |
Or. en
Amendment 130
Proposal for a regulation
Article 22 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| It shall apply from [Publications Office, insert the date – 1 year after entry into force]. | It shall apply from [Publications Office, insert the date – 1 year after entry into force]. However, Article 20 shall apply from [the day of entry into force of this Regulation]. |
Or. en
Amendment 131
Proposal for a regulation
Annex – point 2 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| (2) Providers of the European Business Wallets shall ensure integrity, authenticity and confidentiality of the communication between the Business Wallet’s back-end, front-end and secure cryptographic applications and device. | (2) Providers of the European Business Wallets shall ensure integrity, authenticity and confidentiality of the communication within and among all Business Wallet’s back-end, front-end and secure cryptographic applications and device. |
Or. en
Amendment 132
Proposal for a regulation
Annex – point 3 – point 3
| Text proposed by the Commission | Amendment |
|---|---|
| (3) Where critical assets relate to performing electronic identification at assurance level substantial, the European Business Wallets cryptographic operations or other operations processing critical assets shall be performed in accordance with the requirements for the characteristics and design of electronic identification means at assurance level substantial, as set out in Commission Implementing Regulation (EU) 2015/1502. | deleted |
Or. en
Amendment 133
Proposal for a regulation
Annex – point 4 – point 1 – point b
| Text proposed by the Commission | Amendment |
|---|---|
| (b) where they authenticate the European Business Wallet owner in the context of performing electronic identification at assurance level substantial as set out in Implementing Regulation (EU) 2015/1502; | deleted |
Or. en
Amendment 134
Proposal for a regulation
Annex – point 4 – point 1 – point g
| Text proposed by the Commission | Amendment |
|---|---|
| (g) comply with the requirements for the characteristics and design of electronic identification means at assurance level substantial, as set out in Implementing Regulation (EU) 2015/1502. | deleted |
Or. en
Amendment 135
Proposal for a regulation
Annex – point 7 – point 1
| Text proposed by the Commission | Amendment |
|---|---|
| (1) The providers of European Business Wallets shall provide an appropriate logging policy that shall include, at a minimum, electronic signing, electronic sealing, and notifications of all transactions with Business-Wallet-relying parties, other European Business Wallets units, and European Digital Identity Wallets units, irrespective of whether the transaction is successfully completed. | (1) The providers of European Business Wallets shall implement and document an appropriate logging policy that shall include, at a minimum, electronic signing, electronic sealing, and notifications of all transactions with Business-Wallet-relying parties, other European Business Wallets units, and European Digital Identity Wallets units, irrespective of whether the transaction is successfully completed. |
Or. en
Amendment 136
Proposal for a regulation
Annex – point 10 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| Business Wallets shall support the secure export and portability of an owner’s European Business Wallet data in at least an open format. This shall enable the owner to migrate their data to another Business Wallets solution while ensuring a level of assurance of at least "substantial", as defined in Implementing Regulation (EU) 2015/1502. | Business Wallets shall support the secure export, import and portability of an owner’s European Business Wallet data in at least an open format. This shall enable the owner to migrate their data to another Business Wallets solution while ensuring a level of assurance of at least "substantial", as defined in Implementing Regulation (EU) 2015/1502. |
Or. en
Amendment 137
Proposal for a regulation
Annex – point 11 – point 2 – point a
| Text proposed by the Commission | Amendment |
|---|---|
| (a) designate one qualified electronic registered delivery service that shall serve as the mandatory secure legal communication channel for European Business Wallets; | (a) designate one or more qualified electronic registered delivery service, which complies with Article 7(2) of this Regulation, that shall serve as the mandatory secure legal communication channel for European Business Wallets; |
Or. en
Amendment 138
Proposal for a regulation
Annex – point 11 – point 2 – point e
| Text proposed by the Commission | Amendment |
|---|---|
| (e) establish procedures for ensuring continuous availability, redundancy and fallback mechanisms in case of service failure. | (e) ensure that the designated qualified electronic registered delivery services shall establish adequate procedures for ensuring continuous availability, redundancy and fallback mechanisms in case of service failure. |
Or. en
Amendment 139
Proposal for a regulation
Annex – point 12 – point 2 – introductory part
| Text proposed by the Commission | Amendment |
|---|---|
| (2) Providers of European Business Wallets shall ensure the access control mechanism nables fine-grained and auditable authorisation outcomes, ensuring that: | (2) Providers of European Business Wallets shall ensure the access control mechanism enables fine-grained and auditable authorisation outcomes, ensuring that: |
Or. en
Amendment 140
Proposal for a regulation
Annex – point 14 – point 2 – point c
| Text proposed by the Commission | Amendment |
|---|---|
| (c) Wallet solutions shall support mechanisms that enable providers of Business Wallets Owner Identification Data to verify issuance, delivery and activation in compliance with assurance level substantial requirements set out in Commission Implementing Regulation (EU) 2015/1502 (11); | (c) Wallet solutions shall support mechanisms that enable providers of Business Wallets Owner Identification Data to verify issuance, delivery and activation in compliance with assurance level high requirements set out in Commission Implementing Regulation (EU) 2015/1502 (2.2); |
Or. en
Explanatory statement 21 paragraphs
The Rapporteur welcomes the Commission proposal on establishing European Business Wallets to address inefficiencies that economic operators face in the EU’s Single Market regarding digital identification, authentication and data exchange, especially in cross-border situations.
The European Business Wallets framework is closely linked to the proposal on the 28th regime and is included in recent proposals on sectoral legislation as a digital tool for interactions between companies and public authorities, for example in notification and permitting procedures.
Intended as a harmonised, reliable, and user-friendly digital framework, the European Business Wallets would be available for all economic operators, including companies of different sizes, organisations and public sector bodies to enable secure business-to-government (B2G) and business-to-business (B2B) digital interactions, potentially reducing administrative burdens and compliance costs, especially for SMEs.
While many Member States already offer a range of digital public services for businesses, heterogeneous digital environments and lack of interoperability hinder their availability or usability for cross-border users. Credentials issued in one country are not always recognised in another. This leads to repeated verification procedures, document submissions, physical presence requirements, and an array of administrative burdens that may discourage cross-border business expansion.
The European Business Wallets proposal builds on the EU Digital Identity Framework, which lays down rules for trust services and introduced the EU Digital Identity Wallets for citizens, expanding trusted digital identities to all economic operators and public sector bodies. The European Business Wallets would build on the same secure infrastructure, but would be developed for organisational needs, offering traceability, auditability, and the ability for companies or public sector bodies to assign mandates and roles to various users within their organisations. European Business wallets will most likely be server-based solutions relying on cloud data storage and processing, rather than mobile applications like the EU Digital Identity Wallets for citizens.
The European Business Wallets would allow companies, organisations and public sector bodies to share and store specific information and documents relating to the owner, sign documents by qualified electronic signature, create qualified electronic seals and issue and validate qualified and non-qualified electronic attestations of attributes.
To support these functionalities, European Business Wallets would include a qualified electronic registered delivery service (QERDS) as a secure communication channel to enable the secure and legally valid exchange of information between parties.
The Rapporteur considers the European Business Wallets should function as an interoperable unifying architectural layer rather than an additional platform, enabling integration with existing and future national and Union-level digital solutions.
The Commission proposes that all public sector bodies at Union, national, state, regional or local authority level would have to have European Business Wallets and enable their use for the purpose of meeting a reporting obligation or fulfilling an administrative procedure. For economic operators European Business Wallets would be voluntary.
Whilst the Rapporteur can support the wallets being voluntary for economic operators, on the matter of public sector obligations, the Rapporteur wishes to provide nuance and introduces an exemption mechanism to smaller municipalities in Member States, where immediate implementation of the obligations, as set out in the Regulation, could entail disproportionate financial burden.
Many Member States already have well-functioning national systems for digital public services, with which economic operators can interact. For some, especially smaller local authorities, the expected volume of transactions via the European Business Wallets is low and limited cross-border business activity does not immediately support the cost-benefit of adopting European Business Wallets. Therefore, the Rapporteur believes a phased approach to adoption could be justified.
The Rapporteur considers that in general, due regard must be given to existing national and EU level digital solutions and gateways including the Once Only Technical System (OOTS), the Business Registers Interconnection System (BRIS) and the European Digital Identity Wallet, to ensure coherence and cost-effective implementation.
Given the role of European Business Wallets in the Unions digital infrastructure, the Rapporteur welcomes the requirement that European Business Wallet providers must be established in the Union and have their principal place of business and main operations in the Union. The Rapporteur suggests to expand this requirement to also cover closely linked service providers such as QERDS, as well as, the providers of supporting infrastructure services for hosting European Business Wallets data, namely cloud providers, in order to safeguard security and trustworthiness of the whole European Business Wallets ecosystem.
Furthermore, due to sensitivity of the data potentially handled by the European Business Wallets, the Rapporteur suggests that European Business Wallets data should be exclusively processed and stored within the Union.
These measures are essential to strengthen the EU’s digital sovereignty, reduce vulnerabilities and limit exposure to the extraterritorial application of third-country laws that could adversely affect the confidentiality, availability and integrity of data, as well as the control over data processed within the European Business Wallet ecosystem.
The Rapporteur considers trust and security paramount to the success of the business wallets. Providers must abide by the existing EU cybersecurity framework and ensure security-by-design. To further strengthen the security aspects of the wallets, the Rapporteur puts forth amendments that aim to strengthen cybersecurity controls and assurance mechanisms.
European Business Wallets may enable automated processes without manual intervention. The Rapporteur agrees that the wallets should remain innovation-friendly and open to incorporate new technological developments, however, without compromising on the level of assurance, security and accountability. Therefore, the Rapporteur introduces amendments to ensure that such automated processes should always remain verifiable and auditable.
The Rapporteur also puts forth amendments strengthening interoperability and efficiency, including allowing for data exchange to take place not only in document form, but as machine-readable structured data. To ensure an innovative and competitive market of European Business Wallets and enhance choice and affordability, the Rapporteur strengthens the measures allowing for business wallet owners to export their data and switch providers.
The Commission proposal allows for the recognition of similar third countries systems as equivalent, which would facilitate trusted global exchanges with non-EU partners. While the Rapporteur is open to this possibility, it is necessary to ensure that the right safeguards are in place. The Rapporteur considers that a thorough assessment of the third-country business wallets or similar systems must be carried out to ensure the equivalence of cybersecurity and data protection standards, and the independence of the providers or systems from the control of high-risk entities or third countries. Furthermore, the Rapporteur considers that instead of equivalence, mutual recognition agreements would be preferable, to ensure European companies could benefit.
Lastly, the Rapporteur strongly believes that a significant success factor of the European Business Wallets will be their overall uptake. The Rapporteur suggests that Member States and the Commission develop a comprehensive Implementation Roadmap, identifying key milestones and use-cases within B2G, G2B and B2B interactions, especially for SMEs.
The Rapporteur is of the opinion that these targeted amendments support interoperability, security and cost-efficiency, leaving room for innovation and market-based solutions, but highlighting the need to take into account cross-border interoperability and interoperability with existing digital solutions at the EU and Member State levels.