EU digital identity national ID

Germany's d-you Wallet Should Ship Late Rather Than Launch Without Pseudonyms and Selective Disclosure

Bundestag experts say Germany's EUDI wallet will launch on 2 January 2027 as real-name ID only. Delay the privacy gaps, not the whole rollout.

Germany's d-you Wallet: Launch Snapshot People of Internet Research · EU 2 Jan 2027 Planned launch date Nationwide start of the d-you wall… 15 Oct Bundestag vote scheduled Plenary vote on the DIdG in 2026. >90% Local officials still preparing Of 300+ surveyed in an early prepa… peopleofinternet.com
Germany's d-you Wallet: Launch Snapsho… People of Internet Research · EU 2 Jan 2027 Planned launch date 15 Oct Bundestag vote scheduled >90% Local officials still preparing peopleofinternet.com

Key Takeaways

A launch date that is running ahead of the design

On 6 October 2026 the Bundestag's Committee on Digital Affairs and State Modernisation held a public hearing on the Digitale Identitätengesetz (DIdG, Drucksache 21/7408), the bill that implements the EU's European Digital Identity Wallet in German law. According to the Bundestag's hearing summary, the wallet, branded "d-you", is meant to start on 2 January 2027, and the plenary vote was scheduled for 15 October. netzpolitik.org reported that experts warned the launch version lacks pseudonymous logins, zero-knowledge proofs and selective disclosure. That would leave real-name identification as the only mode. Critics also raised the absence of a proportionality check on data requests, the signed biometric photo, a cloud-based hardware security module as a single point of failure, and the lack of a data protection impact assessment. The developer defended the architecture as the best balance of security, privacy and usability.

The strongest case for shipping now

The case for speed is serious. The EU framework obliges Member States to offer wallets to citizens, and the European Commission states the deadline as the end of 2026. A wallet that exists, even in limited form, creates the market in which banks, municipalities and employers start accepting digital credentials. Torsten Lodderstedt of SPRIND told the committee that 2 January is "the start of scaling", and wallet ecosystems are complex enough that staged rollouts are normal. Germany's federal data protection commissioner, Andreas Hartl, welcomed the legal basis for a first version that will not yet meet every eIDAS requirement, while asking for clear public communication about what it can and cannot do. Digital Minister Karsten Wildberger has argued in the Bundestag debate that credentials are stored encrypted, use is voluntary and users decide what to share, as netzpolitik.org reported. None of this is bad faith. Identity infrastructure is hard, and perfect is the enemy of deployed.

Why a real-name-only wallet is the wrong first version

The trouble is that the missing features are not polish. They are the properties that make a wallet different from a digital copy of an ID card. The Commission's own description says citizens can choose "which aspects of their identity and data they share with third parties." A wallet that discloses full identity to prove one fact, such as being over 18, is a regression from that promise. Hartl himself said at the hearing that the lack of pseudonymous use is a problem from a data protection perspective. The consumer federation vzbv wants pseudonymous use, selective disclosure and data-minimising age verification from day one, and warns that without them the wallet may be rejected by a majority of the public.

That last point is the innovation argument. A digital identity system only creates value if people and businesses adopt it voluntarily. Adoption depends on trust, and Green MP Rebecca Lenhard put it bluntly: trust cannot be delivered later as a software update. A wallet that launches as a surveillance-friendly login button risks poisoning the category for the private-sector credentials the ecosystem needs.

There is a design-risk argument as well. Bianca Kastl of the Innovationsverbund Öffentliche Gesundheit warned of a "cookie banner 2.0" if service-provider registration lacks safeguards. Lina Ehrig of vzbv said registration has limited effect and that data requests should be limited to what is strictly necessary. Without a proportionality check, every website that asks for more than it needs becomes a collection point, and the user clicks "accept" because the alternative is no service. Prof. Jiska Classen of the University of Potsdam added that much of the security architecture is neither public nor independently assessed, and that smartphones are a high-risk extraction surface. Skipping a data protection impact assessment for a system intended for tens of millions of people is hard to square with the evidence-based approach the project claims.

Readiness is also a problem outside the wallet

The rollout has a second weakness: demand-side readiness. netzpolitik.org reported that in a Union-faction expert meeting, over 90 percent of the 300-plus mayors, district officials and IT staff said they were still in an early preparation phase. The Städte- und Gemeindebund said the draft does not adequately involve municipalities, and the Landkreistag noted that the central issuing and verification service will only arrive later in 2027, with citizen-mailbox issuance initially supporting one use case. A wallet that few offices can accept gains little from a hard January date.

What proportionate regulation would look like

The fix is not to abandon the wallet or to demand perfection before any launch. It is to separate two things the current timetable bundles together. The Bundestag can pass the DIdG on schedule while writing binding, dated commitments into the law: pseudonymous authentication and selective disclosure by a fixed date, a published data protection impact assessment, a statutory requirement that relying parties justify each attribute they request, and independent security review of the hardware security module architecture. Until those arrive, the wallet should be positioned as a pilot, with the existing eID card remaining the default for sensitive transactions. If the Commission's end-of-2026 deadline cannot be met with the privacy features intact, a brief slip is cheaper than a trust failure.

There is also a sovereignty angle worth keeping honest. As the EFF argues, digital sovereignty should mean users gain real control over their data, not merely that a government controls the infrastructure instead of a foreign firm. A national wallet that maximises state-visible identification does the second without the first.

Germany has an opportunity to show that a democratic state can build identity infrastructure that is useful, minimal and trusted. Launching a real-name-only version first is a bet that people will forgive the gap. History with digital ID suggests they will simply not use it.

Sources & Citations

  1. Bundestag hearing summary on the Digitale Identitätengesetz
  2. European Commission: European Digital Identity Regulation
  3. netzpolitik.org: Bundestag debates the digital wallet
  4. EFF: Digital Sovereignty: What It Is, What It Could Be