ORBIS.ID Open the walletWallet

Regulations & law

A market being written into law.

Most emerging markets are demand forecasts. This one has statutes with dates. Between now and mid-2027, digital identity wallets move from optional innovation to legal obligation across the world’s largest single market — and the infrastructure to meet it has to exist before the deadline, not after.

eIDAS 2.0 — Regulation (EU) 2024/1183

The European Union’s revised electronic identification regulation has been in force since May 2024, with implementing acts completed through July 2025. It obliges all 27 member states to offer a European Digital Identity (EUDI) Wallet to every citizen and resident, and it obliges relying parties across ten regulated sectors — plus very large online platforms and gatekeepers — to accept it.

This is the sentence that matters for infrastructure: fewer than a third of member states currently meet the readiness benchmark, which means a scramble for compliant infrastructure through 2027. The European Commission’s Digital Decade target is EUDI wallet availability to 80% of citizens by 2030.

A proposed European Business Wallet (November 2025) would extend the same framework to companies, with projected administrative savings of at least €150B per year.

The compliance clock

Dated, statutory demand — who must act, and by when.

Source: European Commission, Regulation (EU) 2024/1183 and Regulation (EU) 2024/1624, as compiled in the ORBIS.ID market research, July 2026.
Deadline Obligation Who must act
Dec 2026 Every EU member state must offer a European Digital Identity Wallet to all citizens and residents (eIDAS 2.0). Fewer than a third currently meet readiness benchmarks. 27 EU governments and their technology suppliers
Jul 2027 The EU Anti-Money-Laundering Regulation requires customer due diligence that accepts eIDAS-notified digital identity — a second, converging forcing function. All EU financial institutions
Late 2027 Relying parties in banking, transport, energy, health, telecoms, social security, education, water, postal and digital infrastructure — plus very large online platforms and gatekeepers — must accept EUDI wallet credentials. Effectively every regulated European enterprise
Ongoing Age-verification mandates: the UK Online Safety Act live since July 2025; roughly 23 US state laws, upheld by the Supreme Court in 2025; an EU age-verification blueprint built on EUDI. UK digital verification services register live; 21 US states issue mobile driver’s licenses. Platforms, publishers and retailers globally

2024

eIDAS 2.0 enters force

EU law mandates digital identity wallets for all 27 member states.

2025

The standards go final

OID4VP 1.0, OID4VCI 1.0, W3C VC 2.0, SD-JWT (RFC 9901), HAIP 1.0. Apple and Google ship wallet-ID verification on the web.

2026

Wallets ship

Member-state EUDI wallet deadline in December; 21 US states issue mobile driver’s licenses; age-verification mandates live across UK, US and EU.

2027

Acceptance becomes law

Banking, telecoms, platforms and eight more sectors must accept wallet credentials; EU AML rules converge on the same rails in July.

AML convergence

The EU Anti-Money-Laundering Regulation (2024/1624) applies from 10 July 2027 and requires customer due diligence that accepts eIDAS-notified electronic identity and EUDI wallets. For a bank, this is a second deadline pointing at the same rails as eIDAS 2.0 — which is why wallet-based onboarding is being modelled as a cost story as well as a compliance one: a projected reduction from €70–100 to €3–8 per customer (Corbado / EIC 2026).

Age verification

Age assurance became a global relying-party mandate in 2025. The UK Online Safety Act’s “highly effective age assurance” duties commenced in July 2025, with Ofcom reporting deployment at unprecedented scale. In the United States, the Supreme Court upheld state age-verification laws (FSC v. Paxton, June 2025), with roughly 23 states legislating. The EU released an EUDI-based age-verification “mini-wallet” blueprint with five pilot states.

Selective disclosure is the technical answer these mandates need: prove you are over the threshold without handing over a document, a face, or a database record. That is exactly what an SD-JWT VC credential does — see how ORBIS implements it.

United States — mobile driver’s licenses

21 US states plus Puerto Rico issue ISO 18013-5 mobile driver’s licenses, accepted at TSA checkpoints. Apple Wallet and Google Wallet carry state IDs and passport-based digital IDs, and both shipped web-based identity verification via the W3C Digital Credentials API in 2025–2026 — which is what turns a phone credential into something a website can actually ask for.

United Kingdom and elsewhere

  • United Kingdom. Digital Verification Services law commenced December 2025; trust framework 1.0 effective September 2026 with 46 registered providers; GOV.UK Wallet live (veteran card, driving licence trial); a mandatory digital-ID scheme for right-to-work was announced September 2025.
  • Switzerland. State e-ID approved by referendum in September 2025 (swiyu wallet).
  • Australia. The Digital ID Act commenced December 2024, with private-sector expansion phasing from around 2026.
  • Elsewhere. Bhutan runs the world’s first national SSI system; Singapore and India piloted cross-border verifiable employment credentials in December 2025.

GDPR operations — shipped in the product

Data-protection operations are normally an entirely separate software category. In ORBIS.ID they are part of the platform, live today, and available to operators through the back office at /admin under role-based access with an approvals ladder and append-only audit.

Live

Data-subject access requests

A composed lookup across the platform’s stores produces an export bundle for the data subject — while the audit row that records the export carries identifiers and counts only, never the exported personal data.

Live

Verified erasure

Erasure requests are tracked through their lifecycle with masked list and detail views, a dry-run before execution, a refusal guard against empty-scope erasure, and a redaction backlog for historical audit rows.

Live

Retention rules

Retention classes per data category with an upsert-able rule set, a purge preview whose counts must equal what execution performs, and a hard guard that makes purging a personal-data class impossible by construction.

Live

Records of processing (RoPA)

A processing snapshot with controller and cross-border flags that are recorded, never guessed, plus an audited purpose register per credential type — and a meta-inventory that reports patterns and counts, never values.

Live

Incident register

Incident lifecycle with the 72-hour notification clock computed exactly, audit rows on every transition, and affected-scope bounds recorded per data class — never fabricating who can be contacted.

Live

Role separation & audit

Role-based access with eight roles, an approvals ladder for high-risk actions, append-only audit on every privileged operation, and role-separation attestations.

Why the architecture helps before the tooling does

The verifiable-credential model removes the honeypot: a relying party can check a claim without re-collecting and re-storing the underlying personal data, and a holder discloses field by field rather than handing over a document. Data minimisation stops being a policy and becomes the default shape of the transaction.

Scheduled, not done

In the spirit of the platform’s own honesty law, the gap is stated rather than implied:

  • Penetration test, GDPR audit and SOC 2 are scheduled, not done. They sit on the roadmap, several gated by the next funding milestone.
  • Identity verification is not production-grade yet. Today’s capture is a demonstration around one real issuer round-trip; a production identity-verification provider is a later milestone.
  • ORBIS.ID is not a notified EUDI wallet provider. The platform implements the standards the regulation converges on; notification and certification are separate, jurisdictional processes.
  • This page is information, not legal advice. Regulatory dates and obligations are reproduced from the published sources named below; anyone relying on them for a compliance decision should take their own counsel.

Regulatory sources: European Commission (Regulation (EU) 2024/1183 eIDAS 2.0; Regulation (EU) 2024/1624 AMLR; age-verification blueprint), Ofcom (2026), US Supreme Court (FSC v. Paxton, 2025), UK Digital Verification Services, Swiss federal referendum (Sept 2025), Australian Digital ID Act; cost figures Corbado / EIC 2026. Compiled in the ORBIS.ID market research, July 2026.