
Digital identity in Europe: SSI, Web 3.0 and the European Digital Identity Wallet
In today’s digital world, where digital identity is becoming increasingly central, we are navigating a world of growing complexity. For a long time, the management of our online identity has been in the hands of large platforms and centralised databases – a Web 2.0 model which, whilst practical, has revealed significant weaknesses. Security breaches, data misappropriation and the lack of individual control over our own information have become systemic problems, leading to the fragmentation of our digital footprint across multiple data "silos".
Europe has been positioning itself as a pioneer in shaping a digital future which, ideally, places privacy, security and user control at the heart of its strategy. This approach, often presented in contrast to more centralised models – where the accumulation and monetisation of data by large corporations have become the norm – is an ambitious one. In the context of Web 3.0 and the evolution of digital identity, several initiatives driven by European institutions stand out, centred on promoting a digital ecosystem aligned with the fundamental values of the European Union.
Europe’s digital ambition goes beyond mere technological innovation; it embodies a profound ideological stance. The European Commission, for example, has outlined a strategy for blockchain and Web 3.0 that aims to establish Europe as a hub for innovation and a home for significant platforms and companies in this field. In line with Europe’s regulatory principles, this approach emerges as a deliberate response to the shortcomings of Web 2.0, in which control over and the monetisation of personal data rest with large digital operators. The European Union (EU) is thus seeking to build a digital future that respects fundamental rights from the outset, adopting a proactive regulatory approach aimed at shaping the technology rather than simply reacting to its consequences. This stance not only sets the European model apart on the global stage but also sets a precedent for responsible and ethical technological development, although its full implementation is still ongoing and faces considerable obstacles.
Beyond the username and password: The challenge of digital identity
Web 3.0, or simply Web3, is envisaged as the next evolution of the World Wide Web, distinguished fundamentally by its openness and decentralisation. This new iteration of the internet aims to transform the way users interact online, offering them greater control over their digital footprint. However, it is essential to recognise that many of these features are more utopian than achievable in today’s world.
Definition and characteristics
Decentralisation in Web 3.0 represents a shift away from the dominant structure of Web 2.0, where many digital services and platforms are controlled by large corporations. In this new approach, the aim is to distribute power amongst a network of interconnected users and devices, promoting a more open, participatory and resilient internet. Blockchain technology can serve as the foundation for many Web 3.0 applications, seeking to eliminate dependence on centralised servers or databases — which, in theory, enhances both resistance to censorship and the resilience of services. However, in practice, many Web 3.0 solutions continue to rely on centralised infrastructure at various points within their architecture — such as network access points, data cataloguing services or interfaces with external systems — which contrasts with the rhetoric of total decentralisation.
Openness is another of its characteristics, as it is developed by a community that uses open-source code. This open nature limits censorship or control over online activities, as all information is transparent and is not restricted to specific locations, services or servers. In this context, the blockchain ensures that all digital assets recorded on Web 3.0 are immutable, guaranteeing their integrity. The concepts of ‘trustless’ and ‘permissionless’ are often associated with Web 3.0, suggesting that users do not need to seek permission from any authority to access content on the internet, enabling secure use without intermediaries. However, trust is often placed in the code itself — which requires rigorous analysis — or in network nodes, where access is restricted. Furthermore, ‘permissionless’ does not mean ‘cost-free’ or ‘without technical barriers’, as interactions on public blockchains generally involve costs or fees and require more technical digital literacy.
Increased user utility is a central pillar because, unlike its predecessors, Web 3.0 is a ‘read-write-own’ web, emphasising user interaction and control over their data and digital assets. This capability enables peer-to-peer transactions to be carried out without the need for intermediaries (servers or third-party services). However, the complexity of personal data and usability challenges can make it difficult to fully realise this feature in practice, with the idea of total ‘ownership’ of data still being more of an aspiration than a universally achieved reality.
Enabling technologies
The transition to this new digital paradigm is underpinned by a complex technological infrastructure, in which different components evolve at different rates:
- Artificial Intelligence and Machine Learning: These technologies are used to enable computers to understand information with intelligence approximating that of humans, with the aim of providing rapid and personalised responses. Natural Language Processing, a component of Artificial Intelligence, has evolved from basic tasks to the ability to read, understand and extract meaning from words or phrases; examples of this include voice assistants and spam filters.
- The Semantic Web: sometimes identified as an integral part of Web 3.0, the Semantic Web — combined with Natural Language Processing and Machine Learning — enables computers to interpret information more effectively. Based on standards defined by the W3C, it aims to make data on the internet machine-readable. Its aim is to establish a common foundation that facilitates the sharing and reuse of data between applications, organisations and communities, promoting interoperable formats and exchange protocols based on the Resource Description Framework (RDF). However, the widespread adoption of this model outside specialised contexts has been slower than initially expected. Despite its potential, the Semantic Web faces practical obstacles due to the existence of multiple competing models, which are often incompatible with one another. Technologies such as RDF and JSON-LD, OWL and SKOS, or vocabularies such as schema.org and Dublin Core reflect different approaches to structuring and describing data. This fragmentation hinders interoperability between systems and contributes to uneven adoption, particularly outside technical or specialised contexts. Furthermore, the coexistence of different query languages — such as SPARQL and more recent alternatives like GraphQL — highlights the tension between semantic precision and ease of use, making it difficult to achieve a truly interconnected web.
- Blockchain: is a decentralised ledger technology that ensures data integrity and transparency through an immutable system in which transactions are validated by consensus and stored in interconnected blocks. This structure prevents retroactive alterations, making it extremely difficult to manipulate or delete data, which helps to strengthen trust in digital interactions. In the context of a more decentralised internet, blockchain enables users, in principle, to own and manage their own data and digital assets, facilitating peer-to-peer transactions without the need for intermediaries. However, this autonomy also brings new challenges: responsibility falls directly on individuals, requiring technical knowledge to manage digital wallets, protect private keys and interact with smart contracts. Furthermore, significant practical limitations remain. Many public blockchains still face scalability issues, high transaction fees and high energy costs — particularly in proof-of-work-based networks. Furthermore, despite the rhetoric surrounding decentralisation, a large proportion of interactions with these networks rely on platforms, wallets and infrastructure maintained by centralised entities, which can lead to the re-centralisation of critical control points.
- NFTs: or non-fungible tokens, are unique digital assets that represent ownership of a specific item — be it an image, a video, a virtual object or even a digital right. Unlike common cryptocurrencies, such as Bitcoin, which are interchangeable with one another, each NFT is distinct and indivisible, functioning as a digital certificate of authenticity and ownership recorded on a blockchain. This technology enables creators, artists and users to sell, buy and exchange digital assets with a guarantee of originality and scarcity, paving the way for new forms of commerce and interaction on the decentralised internet. NFTs are fundamental to the concept of ‘digital ownership’ in Web3, giving users direct control over their digital assets. However, ownership of an NFT does not necessarily imply the right to use or reproduce the associated content, which can lead to confusion or disputes. Finally, technical barriers and the cost of entry may limit widespread adoption, calling into question the democratisation that the technology aims to promote.
- 3D Graphics and the Metaverse: Three-dimensional environments, such as those that make up the Metaverse, play a strategic role in the evolution of the internet towards a more immersive and interactive experience. By integrating 3D graphics with Web3 technologies — such as blockchain, sovereign digital identities and tokenised assets — it is possible to create permanent virtual worlds where users not only interact, but also own digital assets, build personalised experiences and participate in decentralised economies. This integration has practical applications beyond the gaming sector, with a growing impact on virtual real estate, where plots of land and buildings are represented by NFTs; in e-commerce, with interactive virtual shops; and in education and healthcare, through immersive simulations and remote training. 3D interactivity enhances the utility of Web3 by transforming the web from a static information network into a more engaging social, economic and sensory space.
- Connectivity and ubiquity: Ubiquity means that users will be able to access internet services and content anywhere, at any time, via any device. This is facilitated in Web 3.0, where semantic metadata ensures that information on the web is more interconnected.
The European vision of Web 3.0 is intrinsically linked to digital sovereignty and data protection. Decentralisation and the Semantic Web are viewed not merely as technological improvements, but as pillars of an architecture that resists the centralisation of power. The emphasis on the ‘trustless’ and ‘permissionless’ nature of Web 3.0, combined with user ownership of data, directly addresses the privacy concerns that emerged with Web 2.0. The incorporation of the Semantic Web is fundamental, as it enables intelligent agents to represent users’ interests, promoting individual autonomy over the control exercised by large platforms. This strategy aims to build a Web 3.0 that, from its very conception, respects European regulatory principles, such as the GDPR, thereby avoiding the need for subsequent adaptations to ensure compliance. The European model views Web 3.0 as a tool for regaining digital sovereignty, going beyond a mere technological upgrade.
To illustrate the evolution and differences between the generations of the internet, the following image presents a comparison centred on the European perspective of Web 3.0. This visual representation is particularly useful as it offers a concise overview of the key transformations, highlighting how Web 3.0, with its ‘read-write-own’ paradigm, aligns with the European priority of user ownership and control. It facilitates a quick understanding of the fundamental differences and justifies European investment in this new phase, which aims to address the shortcomings of Web 2.0 regarding data privacy and corporate control.

From centralised control to self-determination: The promise of Self-Sovereign Identity (SSI)
Self-Sovereign Identity (SSI) represents a paradigm shift in digital identity management, placing individuals at the centre of control over their personal information. This user-centred approach is fundamental to the European vision of a digital future that values autonomy and privacy. However, its widespread adoption still faces significant obstacles, ranging from technical and interoperability issues to regulatory and, above all, cultural challenges.
Key concepts of SSI and the trust triangle model
Self-Sovereign Identity (SSI) describes a model in which individuals have the ability to control and manage their digital identity without the mediation of third parties responsible for identity management. This approach gives users control over their digital presence, in contrast to the dominant paradigm of today’s internet, where personal data is frequently stored, managed and exploited by service providers, often without the user’s knowledge or informed consent. SSI seeks to transpose the logic of the physical world into the digital environment, where only the information strictly necessary to access a service is shared. For example, when creating an account on a social network, it would be sufficient to provide an email address, a password and proof of age — without this implying continuous tracking of online behaviour.
At the heart of the decentralised identity model underpinning Self-Sovereign Identity (SSI) lies the fundamental concept of the trust triangle, which translates human relationships of trust into the digital context. This model is based on three essential pillars:
- Issuers: entities responsible for creating and issuing verifiable credentials, such as identity documents, academic certificates or proof of address.
- Holders: individuals or organisations that hold these credentials. They store them in a secure digital wallet and have control over what information they share, with whom and in what context.
- Verifiers: entities that enable the authenticity of credentials presented by holders to be confirmed, such as financial institutions or public bodies.
SSI allows credentials to be issued once, stored by the user and reused in various contexts. The aim is to avoid the duplication of personal data across multiple platforms and to facilitate quick and secure identity verification.
The importance of data sovereignty and privacy by design, and the challenges of adoption
Self-Sovereign Identity (SSI) represents not merely a technical improvement, but a fundamental redefinition of the power dynamics in the digital space, by transferring that power from centralised entities to the individual themselves. SSI ensures that users retain control over their verifiable credentials and that their consent is always required for their use, minimising the unintentional sharing of personal data. The principle of ‘privacy by design’ is one of the cornerstones of SSI, manifesting itself in a set of cybersecurity technologies that facilitate the sharing and processing of personal data in a way that preserves privacy.
The European Union has been actively promoting this vision through initiatives such as eIDAS2 and the European Digital Identity project. The aim is to create a self-sovereign digital identity that can be used throughout Europe, with the ambition that, by 2030, at least 80 per cent of EU citizens will have access to a digital identification solution. The European Commission recognises the potential of blockchain technology and Decentralised Identifiers (DIDs) to strengthen trust, security and privacy in the management of digital identity. By placing ‘privacy by design’ and data sovereignty at the heart of its policies, the European Union is not merely reacting to the risks of the digital age — it is asserting itself as a leader in building a technological and regulatory architecture where privacy is a fundamental value, rather than an afterthought. This vision clearly distinguishes the European model from the more permissive or market-oriented approaches seen in other international contexts.
However, the widespread adoption of SSI faces significant obstacles. Despite its high level of technical maturity, this is not sufficient to ensure its large-scale use. The value proposition of SSI is unlikely to gain traction based solely on the perceived protection of privacy. Decentralisation, in itself, is not a sufficiently strong market argument. To achieve widespread adoption, SSI will need to offer clear and sustainable benefits over current centralised models — otherwise, its implementation may remain negligible.
Furthermore, SSI may exacerbate social inequalities and exclude those with limited access to technology or low levels of digital literacy. This model presupposes access to the internet, compatible devices and digital skills. There is also a problem of ‘semantic ambiguity’ surrounding the concept of SSI, which highlights the importance of developing a consistent narrative and terminology within the community. The complexity of personal data — which is too rich and diverse to be treated uniformly — represents yet another significant challenge for decentralised identity management.
To make it easier to understand the principles underpinning this transformation, the following image provides an overview of the key elements of Self-Sovereign Identity. This visual representation is particularly useful as it distils a complex concept into clear operational principles, which are fundamental to assessing the compatibility of new technologies with European values. It serves as an accessible reference to the ideas underpinning the EU’s digital identity strategy, emphasising user empowerment and data protection, whilst acknowledging the challenges involved in fully implementing it.

The European Digital Identity Wallet (EUDIW): A cornerstone of the EU’s strategy
The European Digital Identity Wallet (EUDIW) represents a strategic and comprehensive response by the European Union to the challenges of digital identification in the modern era. Its main objective is to provide a secure, reliable and privacy-oriented means of digital identification for all citizens, residents and businesses in Europe. Whilst it constitutes a significant step towards user autonomy, it is important to understand the differences compared to a strictly decentralised implementation of Self-Sovereign Identity (SSI), as well as the limitations inherent to the EUDIW.
Key features and objectives of EUDIW
EUDIW will not be a single application, but rather a set of digital wallets made available by each EU Member State, all built on the same specifications and designed to be interoperable across the EU. The key features of EUDIW are multifaceted and aim to simplify and strengthen digital interactions:
- Authentication: Enables users to access a wide range of online services, both public and private, by identifying themselves securely whilst protecting their privacy. The aim is to eliminate the need to manage numerous passwords, simplifying the authentication process to just a few taps.
- Store: Users will be able to securely store all the digital documents they need, ensuring immediate access whenever required.
- Share: The digital wallet will facilitate the selective sharing of documents. For example, a user will be able to provide a copy of their academic qualifications to an employer quickly and easily, disclosing only the strictly necessary data, such as age or nationality, without exposing any other information.
- Sign: Users will be able to sign documents with a legally valid electronic signature, making the process of conducting business or entering into agreements anywhere in the EU faster and simpler.
Digital documents stored in the wallet will stand out for ensuring security (through advanced encryption mechanisms), privacy protection (ensuring control at source and allowing only the minimum necessary sharing) and cross-border validity (being officially recognised throughout the European Union).
Large-scale pilot projects and the implementation roadmap
In 2023, the European Union launched four major pilot programmes with the aim of testing and evaluating the EUDIW prior to its formal implementation in the Member States. These projects involve more than 350 organisations, including private companies and public authorities from 26 Member States, as well as Norway, Iceland and Ukraine. These pilot schemes aim to validate the digital wallet in real-life European scenarios, such as:
- Access to public services (e.g., passport applications, tax returns, social security benefits);
- Opening bank accounts and activating SIM cards;
- Using mobile driving licences;
- Signing contracts and obtaining medical prescriptions;
- Facilitating travel and providing proof of organisational identity;
- Identity verification for payments and academic certifications.
The main pilot projects include:
- EWC (EU Digital Identity Wallet Consortium): Focused on the use of digital travel credentials.
- POTENTIAL: Covers a wide range of sectors, including public administration, banking, telecommunications, healthcare, electronic signatures and mobility.
- NOBID: Tests payment authorisation in the Nordic and Baltic countries, as well as in Italy and Germany.
- DC4EU: Supports the education and social security sectors, with a focus on the integration of cross-border digital service infrastructures.
Under European regulations, European Union Member States have until 2026 to make their national digital ID available, as the 24-month deadline began to run following the adoption, in 2023, of the Implementing Acts setting out the technical and certification specifications for the EUDIW. At national level, Portugal has taken concrete steps to strengthen the legal validity of digital identification: in February 2024, Law No. 19-A/2024 was passed, amending Article 4-A of Law No. 37/2014, thereby conferring full legal validity on digital identification documents presented in real time via the Gov.pt app. This legislation establishes that documents such as the Citizen Card or driving licence, when displayed digitally, have the same legal validity as their physical equivalents, thereby strengthening the legal framework for digital identity in Portugal and anticipating the principles of legal recognition and practical functionality that EUDIW seeks to institutionalise at European level. The Portuguese digital wallet already provides access to various official documents, including the Citizen Card, the driving licence, the ADSE Card, the European Health Insurance Card, the War Veteran’s Card and the Blood Donor Card, demonstrating a gradual adoption of document digitisation, in line with the European strategy for an interoperable and user-centred digital identity.
Open source and cross-border interoperability – transparency with nuances
EUDIW is the EU’s main instrument for realising Self-Sovereign Identity and asserting the digital sovereignty of its citizens, not only through technological innovation, but also through a regulatory strategy based on open-source development and common technical standards. The decision to adopt an open-source approach is a key pillar of this architecture, ensuring that the wallet’s resources and code will be publicly available. This transparency promotes collaboration between Member States and private sector actors, encouraging interoperable and auditable solutions.
However, it is important to emphasise that this openness has its nuances. Whilst the software components installed on users’ devices must be open source, Member States retain some leeway to justify why certain elements – particularly those not installed locally – are not made public. This possibility raises concerns regarding auditability and consistency across different national implementations, undermining users’ full confidence.
Interoperability is one of the fundamental pillars of EUDIW, ensuring that all national digital wallets offer a consistent user experience, with equivalent functionalities and full technical compatibility across the European area. This harmonised approach, based on open and shared specifications, is essential for the functioning of the digital single market, ensuring that any European citizen can use their digital wallet regardless of their country of origin.
The strategic choice of open-source solutions is therefore more than just a technical option: it is a tool for building institutional trust and protecting digital rights. In contrast to proprietary and opaque approaches, the EUDIW positions itself as a public digital infrastructure based on transparency, privacy by design and informational self-determination. Nevertheless, its effectiveness requires constant oversight of its practical implementation to ensure that justified exceptions do not become recurring deviations capable of undermining the essential principles of the European project.
For a more detailed overview of the features and projects that shape EUDIW, the following images provide a clear and informative summary, outlining the practical applications of the wallet and highlighting its usefulness and user-centred approach, in line with European values of privacy and security.

And the evidence of the diversity and scope of the test scenarios across different Member States, demonstrating the EU’s commitment to ensuring a robust, multi-sectoral and truly pan-European implementation.

The Semantic Web: Giving meaning to decentralised digital identity
The previous article, «Between data and knowledge: the role of metadata in structuring information», already addressed the importance of organising and contextualising data. In the context of Web 3.0, the need to assign meaning becomes even more pressing, particularly when dealing with fragmented and decentralised data. The Semantic Web emerges as a proposal to bridge this gap, although its large-scale implementation continues to face significant technical and organisational challenges.
What is the Semantic Web and how does it relate to digital identity in Web 3.0?
The Semantic Web is conceived as an extension of the current web, in which information takes on a formally defined meaning, enabling more effective cooperation between humans and machines. Through standards established by the World Wide Web Consortium (W3C), such as the Resource Description Framework (RDF), the Semantic Web seeks to make internet data machine-readable. Its aim is to provide a common framework for the sharing and reuse of data amongst different applications, organisations and communities.
In the field of digital identity on Web 3.0, the Semantic Web can play a strategic role:
- Contextualisation of Verifiable Credentials (VCs): A VC is not merely a set of data, but data with explicit meaning. The Semantic Web allows vocabularies and relationships to be defined within a VC (for example: ‘is a degree from’, ‘issued by’, ‘recognised in’), enabling systems to understand the content and links between identity information.
- Decentralised Identifiers (DIDs) and semantic resolution: The Semantic Web can help provide context for DIDs, enabling different systems to interpret what an identifier represents and how it can be used securely and in an interoperable manner.
- Interoperability and digital reputation: With shared ontologies, identity data acquires a common meaning, enabling multiple applications and services — even those from different sources — to interpret it consistently. This is essential for reputation systems and for the cross-cutting integration of digital identity in Web 3.0.
- Machine-based automatic understanding of identity: The Semantic Web aims to enable algorithms and artificial intelligence systems to understand and process identity information autonomously, reliably and efficiently, paving the way for the secure automation of complex verifications and interactions. However, this ‘ability to understand’ on the part of machines remains an evolving objective rather than a fully realised reality.
Challenges in the adoption of the Semantic Web for digital identity
Despite its potential, the adoption of the Semantic Web in the context of digital identity faces significant obstacles:
- Complexity and semantic fragmentation: The difficulty in reaching operational consensus on semantic models and the existence of multiple ontologies covering the same concepts represent practical barriers to interoperability. Resolving semantic disputes effectively remains one of the main technical hurdles.
- Collaborative adoption and maintenance: The creation, validation and maintenance of semantic vocabularies require a coordinated effort amongst various entities — public, private and academic — which can delay their widespread adoption and result in uneven implementation.
- Link to open source: Many Semantic Web standards and tools are developed within open-source communities, which promotes transparency, auditability and participation in defining meanings. However, the fact that they are open does not, in itself, resolve the challenges of fragmentation, complexity and applicability.
The Semantic Web represents a critical layer for digital identity in Web 3.0 to be truly interoperable, meaningful and automatable. However, its full realisation requires more than just available technological solutions — it demands standardisation, multilateral cooperation and an ongoing effort at semantic integration that is still far from being resolved.
Web 3.0, open source and the protection of personal data: Is a marriage with the GDPR possible?
Europe has been a pioneer in creating robust regulatory frameworks for data protection and digital identity, with the General Data Protection Regulation (GDPR) and the eIDAS Regulation 2.0 playing central roles. However, the emergence of technologies such as blockchain and Web 3.0 presents unique challenges that require continuous adaptation of legislation. The open-source philosophy can be a crucial enabler in this context, although it is not a magic bullet.
Principles of the GDPR and potential alignment with Web 3.0 (through open source and the Semantic Web)
The GDPR was designed to empower individuals by giving them meaningful control over their personal data. This regulation stipulates that data must be collected only for specific, explicit and legitimate purposes, and that no more information should be stored than is strictly necessary for those purposes.
Web 3.0, driven by open source and the Semantic Web, can align with several fundamental principles of the GDPR:
- Control by the Data Subject: SSI and Web 3.0, by their very nature, aim to give users back control over their data, in line with the rights of access, rectification, erasure and portability enshrined in the GDPR. Open source makes this control mechanism auditable and transparent, thereby strengthening trust.
- Privacy by Design and by Default: The architecture of Web 3.0, particularly in the context of SSI, allows for the incorporation of data protection right from the design stage. Open-source development encourages the community to collaboratively build solutions with these features.
- Data Minimisation: With Verifiable Credentials (VCs), users can prove certain attributes (for example, being of legal age) without disclosing sensitive information such as their date of birth. Open-source implementations help to ensure that this principle is strictly adhered to.
- Transparency: The public and auditable nature of blockchains and open-source code increases visibility regarding data processing, facilitating compliance and oversight.
- Explicit Consent: SSI models are based on granular user consent for the sharing of credentials, which can facilitate the management of consent required by the GDPR. Open-source tools can be developed to manage this consent effectively.
GDPR Challenges for Web 3.0: An Ongoing Clash
Despite the points of convergence, the immutability and distributed nature of blockchain technology pose significant challenges to the GDPR:
- Right to Erasure: The immutability of blockchain contrasts with the GDPR’s requirement that personal data be erased without undue delay. The European Data Protection Board (EDPB) has been clear: blockchain “is just a technology like any other” and is therefore not exempt from legal obligations. The April 2025 guidelines emphasise that public blockchains, due to their decentralised nature and immutability, conflict with the principles of the GDPR, which require identifiable entities capable of erasing or rectifying data. The solution currently recommended — keeping personal data off-chain and using only hashes or cryptographic proofs on the blockchain — is a pragmatic compromise, albeit one that is admittedly imperfect.
- Identification of the Data Controller: The concept of ‘data controller’ becomes blurred in decentralised networks. The EDPB suggests that a legal consortium could be established to assume this role, or that node operators could be considered joint controllers.
- International Data Transfers: The cross-border nature of the blockchain makes it difficult to apply the rules governing the transfer of personal data outside the European Economic Area.
- Pseudonymity vs. Anonymity: Whilst Web 3.0 promotes pseudonymity, the GDPR requires, in certain situations, that the data subject can be identified.
The GDPR also introduces the principle of accountability, requiring data controllers to proactively demonstrate their compliance with the regulation.
eIDAS 2.0: The legal framework for digital trust in Europe
The eIDAS Regulation (Electronic IDentification, Authentication and Trust Services), now in its 2.0 version, constitutes the main legal framework for trust in electronic identification within the European Union and is a pillar of the digital single market. The new Regulation (EU) 2024/1183 came into force on 20 May 2024, with the aim of addressing weaknesses in the previous version. Unlike the previous regime, which allowed for voluntary notifications of national systems, eIDAS 2.0 makes it mandatory to provide digital identity wallets to all citizens and businesses in the Member States.
The European Digital Identity Wallet (EUDIW) is at the heart of this reform: an interoperable, self-sovereign identity solution across the EU, which is expected to be accessible to at least 80 per cent of European citizens by 2030. The European Commission has moved swiftly to adopt implementing acts setting out technical requirements, certification rules and registration procedures for the ID cards and the relevant service providers.
In Portugal, the aforementioned Law No. 19-A/2024 of 5 February has strengthened the legal recognition of digital documents via the gov.pt app, confirming their legal validity before public and private authorities. This measure enables citizens to present, via their mobile phones, documents that are fully legally valid within the country.
Under European regulations, Member States must make the national digital ID available within 24 months of the adoption of the implementing acts, which took place in May 2024. In other words, by May 2026, each country must have a fully functional and certified digital ID that is interoperable with those of the other EU countries.
European Initiatives and Research on Digital Identity and Blockchain
Europe is not merely establishing regulatory frameworks; it is also actively investing in the development of infrastructure and research projects that bring its vision of a user-centred digital future to life. However, realising this vision is an ongoing, demanding process that is still evolving.
European Blockchain Services Infrastructure (EBSI) and decentralised identifiers (DIDs)
The European Union is building a pan-European blockchain infrastructure, the European Blockchain Services Infrastructure (EBSI), with the aim of providing a robust foundation for cross-border digital public services. This infrastructure is being designed to ensure interoperability with other platforms, adopting a decentralised approach centred on digital trust.
At the heart of this architecture lie Decentralised Identifiers (DIDs), a new type of identifier that enables the establishment of a verifiable digital identity without relying on centralised entities. DIDs are designed to function independently of centralised registries, identity providers or certification authorities. Control over them can be demonstrated directly by the holder, without the need for validation by third parties.
When a credential is added to the European Digital Identity Wallet (EUDIW), it is linked to a DID registered on a blockchain, creating an immutable and tamper-proof record. EBSI strictly adheres to the W3C standards for Verifiable Credentials (VCs), ensuring a decentralised and permissionless approach.
EBSI also supports the issuance of VCs through standards such as OpenID for Verifiable Credential Issuance (VCI), promoting secure and efficient interactions between issuers, holders and verifiers.
Research and development projects (IDunion, eSSIF-Lab)
In addition to investment in public infrastructure, Europe is also fostering an innovation ecosystem through research and development projects that promote decentralised digital identity solutions based on open source and global standards:
- IDunion: A project funded in Germany with the aim of creating a decentralised and trustworthy ecosystem for self-determined identities. It brings together a broad network of partners from the public and private sectors, committed to the highest standards of data protection, including the GDPR and eIDAS.
- eSSIF-Lab (European Self-Sovereign Identity Framework Lab): A project funded by the European Union, completed in December 2022. Its mission was to accelerate the adoption of SSI as an open and reliable solution for secure digital transactions. Fifty-six projects were funded, many of which focused on the technical improvement and interoperability of open-source solutions for the European SSI ecosystem.
- TNO SSI Lab (Netherlands): This laboratory plays a key role in validating digital identity technologies, with a focus on privacy by design and on resolving semantic challenges that hinder full interoperability between systems.
Adoption of W3C standards and semantic interoperability
The European Union actively promotes technological standardisation through collaboration with international and European bodies such as the W3C, ISO/TC 307, ETSI ISG PDL, CEN-CENELEC JTC19, IEEE and ITU-T. This commitment aims to ensure interoperability between systems and prevent dependence on proprietary technologies that are not aligned with European principles.
The W3C’s Verifiable Credentials constitute a standard representing a set of assertions made by an issuing entity. This specification defines an extensible data model and mechanisms to protect against tampering, underpinning a three-party ecosystem – as previously described – comprising the issuer, the holder and the verifier. EBSI’s adherence to these standards enables the model to be extended to multiple use cases, whilst maintaining flexibility and compatibility between solutions, and ensuring technical and semantic interoperability.
Semantic interoperability is, in fact, a key factor in the success of digital identity. It is not enough simply to ensure that data can be transmitted between systems – these systems must also understand the meaning of the data being exchanged. Initiatives such as the Europass Learning Model (ELM), which facilitates the portability of academic and professional qualifications throughout a European citizen’s life, are concrete examples of this effort. However, the multitude of semantic models currently in existence poses a significant technical challenge, hindering the full harmonisation of data interpretation within the European identity ecosystem.
European Open Source Strategy for Digital Public Services
The European Union’s open source strategy plays a key role in realising its vision for Web 3.0 and digital identity. More than just a technological choice, it is a commitment to transparency, digital autonomy and security, underpinned by public trust and regulatory compliance.
Promoting digital autonomy and transparency
The European Commission’s Open Source Software Strategy (2020–2023), under the motto ‘Think Open’, seeks to harness the transformative, innovative and collaborative value of open source by adopting its development principles and practices. This initiative promotes the sharing and reuse of software solutions, knowledge and expertise, with the aim of delivering better digital services at lower cost and with greater efficiency.
Of these, the following stand out: strengthening Europe’s digital autonomy, promoting the sharing of technological solutions in the public sector, and contributing to a more open and participatory knowledge-based society. The transparency inherent in open source is considered essential for building citizens’ trust in digital services. In this context, all software produced by the Commission’s services — particularly that intended for external use — will be made available as open source via the Joinup platform and under the European Union Public Licence (EUPL). These developments are based on principles such as interoperability and the adoption of open technical specifications.
This direct link between free software and digital autonomy is a strategic decision. By promoting open solutions, the EU reduces its dependence on proprietary software — often of non-European origin — thereby strengthening its technological sovereignty. At the same time, the open nature of the code facilitates auditability, supports compliance with the GDPR and ensures greater control over data. This combination of factors creates a virtuous cycle: open source promotes privacy and security, which, in turn, increases trust and encourages the adoption of digital public services, such as the European Digital Identity Wallet (EUDIW).
Synergies with Web 3.0 and digital identity
The open nature of EUDIW aims to ensure transparency, security and auditability, thereby strengthening citizens’ trust in the processing of their data. Open-source solutions are particularly well-suited to public bodies, not only because of their adaptability to compliance with the GDPR, but also because of their ability to mitigate concerns regarding abusive tracking, algorithmic opacity and the manipulation of personal data.
Although not all of the European Commission’s strategic documents establish explicit links between blockchain and open source, this association underlies the European vision of a secure, ethical and interoperable digital ecosystem. The requirement for the EUDIW to be open-source constitutes the practical application of this broader strategy, ensuring that the solutions developed are aligned with European values from the outset.
This synergy between digital identity, free software and European regulation positions Europe as one of the key global players in shaping a sovereign digital future centred on the public interest. It is an approach that rejects dependence on closed commercial infrastructures and champions democratic technological governance, based on principles such as responsible innovation, transparency and lasting interoperability.
Challenges and future prospects: The way forward
The transition to a truly user-centred European digital ecosystem is an ambitious undertaking that demands more than just technical solutions and regulatory frameworks: it requires a clear bridge between theory and practice, overcoming inequalities in access, digital literacy challenges and technological fragmentation.
Barriers to adoption and technological fragmentation
Despite the technical maturity of Self-Sovereign Identity (SSI), its widespread adoption remains limited by a number of factors. Among the main obstacles are the lack of clear and sustainable business models for issuers and verifiers, as well as technological fragmentation that compromises interoperability between different implementations. Furthermore, the SSI model relies on reliable connectivity, compatible devices and a minimum level of digital literacy — conditions that are not evenly distributed and may exacerbate existing inequalities.
The complexity of technical concepts, the multitude of terms and the lack of intuitive interfaces increase the ‘cognitive load’ on users. It is therefore essential that solutions offer tangible value that translates into something useful in everyday life, accompanied by clear communication and user-centred design. Semantic cohesion within the SSI ecosystem is equally necessary to avoid confusion and ensure a harmonised and comprehensible experience.
Balancing innovation, regulation and privacy
Europe also faces the challenge of reconciling the data protection principles enshrined in the GDPR with the inherent characteristics of blockchain — namely immutability and transparency. The European Data Protection Board (EDPB) has been clear: blockchain, being merely a technology, is subject to the same legal obligations as any other system. It is therefore recommended that personal data be kept off-chain, with only encrypted identifiers, proofs or hashes being stored. However, even these approaches are recognised as imperfect, and do not entirely eliminate the difficulties in complying with the principle of data minimisation and the right to erasure.
This dilemma highlights the need for a pragmatic technical and legal compromise, which has yet to be finalised. The European Commission has recognised this complexity and is actively seeking to establish a stable and secure regulatory framework that enables responsible innovation in line with fundamental rights. The investment of around 700 million euros between 2016 and 2024 in blockchain projects demonstrates the EU’s commitment to promoting decentralised solutions that are also interoperable, auditable and energy-efficient.
A holistic strategy for a digital future in Europe
The European Union is building a digital ecosystem that combines technological innovation with ethical responsibility. The GDPR, the eIDAS 2.0 Regulation, the European Digital Identity Wallet (EUDIW) and the European Blockchain Services Infrastructure (EBSI) are interlinked components of this effort, underpinned by a clear strategy on free and open-source software.
Open source is not merely a technical choice — it is a strategic decision that strengthens European digital autonomy, reduces dependence on external suppliers, and promotes auditability and compliance with the GDPR. Esta abordagem fomenta a confiança dos cidadãos e permite um escrutínio democrático das tecnologias públicas, consolidando a transparência como um valor estrutural. Ao exigir que a EUDIW seja construída com base em soluções abertas, interoperáveis e auditáveis, a Europa demonstra um compromisso inequívoco com uma infraestrutura digital soberana, segura e fiável.
Despite the progress made, it is important to recognise that the promise of a fully decentralised ecosystem, where users have absolute control over their data, remains largely unfulfilled. The challenges of usability, semantic consistency, digital inclusion and regulatory compliance call for an ongoing approach to co-creation and iteration between legislators, technologists, businesses and citizens. Europe stands out, however, for its mature regulatory stance and its ethical and strategic vision. The synergy between open source, legal frameworks and investment in decentralised technology positions the EU as a key player in shaping a digital future that respects human dignity, privacy and individual sovereignty. The path ahead is challenging, but the direction is clear: a citizen-centred European digital future, grounded in fundamental rights and driven by responsible innovation.
References and inspiration
- archipels.io
- astrakode.medium.com
- autenticacao.gov.pt
- coinbureau.com
- cordis.europa.eu
- digital-strategy.ec.europa.eu
- digital-strategy.ec.europa.eu
- digital-strategy.ec.europa.eu
- dock.io
- ec.europa.eu
- european-digital-identity-regulation.com
- hub.ebsi.eu
- legalnodes.com
- omfif.org
- rocket.chat
- tno.nl
- wedia-group.com
- w3.org
- w3.org
Duarte Dionísio 

