Your monthly guide to EU digital identity & compliance by Liudmyla (Mila) Rabchynska, Director of Global Regulatory & Government Affairs at IDnow.
March was anything but quiet. The month brought a landmark UK framework launch, a Dutch Supreme Court referral that could reshape how every organization handles GDPR and identity documents, a wave of EUDI Wallet technical publications showing the ecosystem is moving faster than the Member States implementing it. For those tracking rollouts in Czechia, Germany, France, the Netherlands, and Spain, the signals are now clear: December 2026 is looking less like a firm deadline and more like a shared aspiration. Two themes defined this month. First, national digital identity frameworks reaching genuine maturity – most notably in the UK, and progressively in Germany. Second, identity verification providers now must navigate a growing tangle of overlapping regulations all at once: the AI Act, GDPR, NIS2, and eIDAS 2.0. Something for everyone this month – whether you’re in AML compliance, building identity tech, or watching the EUDI Wallet timeline with cautious optimism. Come take a look.
Liudmyla (Mila) Rabchynska, Director of Global Regulatory & Government Affairs, IDnow
🇩🇪 Germany: Framework-Building Season
Germany’s TKG amendment formally recognises the EUDI Wallet for telco identification
- What: Telecommunications / eID / eIDAS 2.0
- Who’s affected: Sales & CS, Product & Security
- Action: One to watch
What happened: The Federal Ministry for Digital and Transport (BMDS) published the draft Telecommunications Act Amendment Bill 2026 (TKG-Änderungsgesetz 2026). The key change for our space is a complete rewrite of §172 Abs. 2, which now lists ten accepted identification methods, including, explicitly, other eIDAS-notified eIDs at Level of Assurance “high” and the EUDI Wallet under Article 3(42) eIDAS 2.0. A new §172 Abs. 2a consolidates provisions on alternative methods. Notably, BNetzA also receives a new general power to set detailed requirements for the standard verification methods, motivated by a documented increase in violations in in-store verification processes.
My take: This is, as far as I am aware, one of the first instances of a national legislator writing the EUDI Wallet into a sectoral compliance obligation by name. §172 TKG governs how telecoms operators must verify subscriber identities, a market where IDnow is an active provider, so the explicit statutory inclusion of the EUDI Wallet as an accepted method is a direct product-planning signal. The BNetzA power to set detailed requirements for standard methods is also worth watching: it responds to real-world enforcement problems and signals that the regulator intends to use its new toolbox actively. This draft will now go through consultation; I will be tracking its progress closely.
Germany’s DIdG: A national EUDI Wallet law with a provision on minors
- What: eIDAS 2.0 / EUDI Wallet / National Implementation
- Who’s affected: Product & Security, Compliance & Legal
- Action: One to watch
What happened: The German federal government published the draft Digital Identity Act (Digitales-Identitäten-Gesetz / DIdG), establishing the legal basis for Germany’s national EUDI Wallet implementation. Among its provisions, the draft expressly permits the experimental issuance of person identification data to natural people from age 12, but only where a prior risk assessment confirms that no overriding risks to the reliability and integrity of the identification infrastructure arise. This is a tightly conditioned testing power, not a decision to make the wallet routinely available to minors.
My take: The DIdG is the legislative foundation Germany needed to move from EUDI Wallet pilots toward a regulated production environment. The provision on minors is drafted with commendable caution – risk-assessment-gated experimental issuance is a far cry from a blanket policy to deploy digital identity to under-18s, and the distinction matters for how implementers should read it. More broadly, Germany is, characteristically, building the legislative framework before the wallet infrastructure is ready, which is the right sequencing but confirms that a production-grade German EUDI Wallet will not appear before early 2027, consistent with what we are hearing across major Member States.
Germany submits AI Act implementation law to Bundestag
- What: AI Act / Market Surveillance / Regulatory Sandboxes
- Who’s affected: Compliance & Legal, Product & Security
- Action: One to watch
What happened: The German Cabinet has submitted the AI Market Surveillance and Innovation Promotion Act (KI-Marktüberwachungs- und Innovationsförderungsgesetz) to the Bundestag. BNetzA is designated as the national AI Act market surveillance authority; BaFin covers the financial sector. BNetzA will also operate Germany’s AI regulatory sandbox (KI-Reallabor), building on a completed pilot project run jointly with the Hessian Ministry for Digitalisation and the Federal Data Protection Commissioner. The EU deadline for establishing at least one national AI sandbox is 2 August 2026.
My take: The designation of BNetzA as Germany’s primary AI Act authority, combined with its new powers under the TKG amendment, makes it an increasingly central counterpart for any organisation providing AI-assisted identity verification in Germany. The KI-Reallabor is genuinely interesting as a mechanism: a supervised environment where companies, particularly SMEs and start-ups, can develop and validate AI systems under regulatory oversight before market entry. For identity verification providers navigating the AI Act high-risk classification and conformity assessment requirements, this is a pathway worth understanding now rather than in August.
🇬🇧 UK: The moment DVS became real
The UK Digital Identity Trust Framework reaches v1.0
- What: Digital Identity / Trust Framework
- Who’s affected: Everyone
- Action: One to act on
What happened: On 3 March 2026, the UK’s Office for Digital Identities and Attributes (ODIA) published DIATF version 1.0 – the first release to carry a “1.0” designation and the first to introduce version-controlled supporting documents. Beta (0.3) certifications expired definitively on 31 March. Gamma-certified providers can undertake a step-up assessment rather than a full re-assessment. All new certifications from this point must be against v1.0. On 26 March 2026, the UK Government published a draft statutory instrument, together with an explanatory memorandum, proposing amendments to the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs). The draft has been submitted for parliamentary approval and formally enables DVS-certified providers to satisfy statutory identity checks under the MLRs, connecting the trust framework directly to a binding legal AML obligation.
My take: This is UK digital identity infrastructure moving from pilot plumbing into real regulatory architecture, and the significance is easy to understate if you have been tracking the framework since its beta drafts. What changed is not just a version number – it is that the framework is now statutory (post-Data (Use and Access) Act), version-controlled, and tied to a concrete compliance obligation in AML law. The DVS-to-AML confirmation is the commercial unlock the market has been waiting for: for the first time, a UK regulated business can satisfy an AML identity check requirement by pointing to a certified digital verification service. That is a structural shift. The 31 March Beta certification expiry was the hard stop that forced the market to decide, and that kind of deadline discipline is, frankly, something EU regulators could learn from.
Also worth your attention this month:
- 🇫🇷 France: French airports will accept the France Identité digital ID from Summer 2026 — a real-world deployment milestone that shows national eID working in high-friction physical use cases.
- 🇸🇪 Sweden: DIGG (Swedish Digitalisation Agency) has published the official timeline for the Swedish EUDI Wallet — one of the clearer, more detailed national roadmaps currently available publicly.
- 🇧🇬 Bulgaria: Bulgaria has published a draft digital ID law but is widely expected to miss the EUDI Wallet December 2026 deadline — adding to the growing list of Member States where implementation timelines are under pressure.
- 🌐 US-EU Biometrics: The United States and the European Union have entered formal negotiations over a biometric data-sharing arrangement that would grant DHS access to fingerprint and biometric records held by EU Member States. Given the current state of transatlantic data relations and the sensitivities around Article 9 GDPR data, this one deserves careful watching.
Looking ahead to April and May, there’s a lot to keep an eye one. The second AI Omnibus trilogue is targeted for 28 April and the European Business Wallet stakeholder consultation closes on 6 May. I will also be tracking how AMLA translates its public hearing feedback into the finalised RTS text, and whether any further Member States signal slippage on the December 2026 EUDI Wallet deadline. There is plenty keeping us all occupied. As always, if any of the topics covered this month intersect with decisions you are working through, I would genuinely love to hear your perspective. Drop a comment below or reach out directly. The most interesting conversations tend to start exactly here. Until next time!
Liudmyla (Mila) Rabchynska, Director of Global Regulatory & Government Affairs, IDnow
By

Liudmyla (Mila) Rabchynska
Director of Global Regulatory & Government Affairs at IDnow
Connect with Mila on LinkedIn
