Italy has turned its digital wallet from a pilot into a formal state system. The decree of 19 March 2026, published in Gazzetta Ufficiale n. 178 on 3 August 2026, sets out the rules for the IT-Wallet system and its services. It implements Article 64-quater, paragraph 5 of the Digital Administration Code (Legislative Decree 82/2005). It follows the guidelines decree published in Gazzetta n. 169 on 23 July 2026, which the hook material dates to 17 June 2026.
The policy is sound in most respects. Its weak point is not the wallet. It is the legal weight the decree gives a single piece of infrastructure.
What the decree does
The decree divides the work between two bodies. According to Certifico's summary of the decree, PagoPA S.p.A. runs the public wallet solution. The State Printing Works and Mint (IPZS) runs the IT-Wallet register and is the sole issuer of electronic attestations of personal identification and public interest. Reporting on the decree adds that AgID handles supervision and registration, and the National Cybersecurity Agency handles security requirements.
The timetable is staggered. Il Sole 24 ORE reports that public administrations have until 3 August 2027 to register as authentic sources and supply their data as electronic attestations. IPZS can issue identification attestations from 3 February 2028, once it has verified a user's identity with the CIE.
The decree also carries a principle that gets less attention than the deadlines. Under Article 64-quater, as summarised from Normattiva, public administrations must accept wallet attestations with an exemption from the checks normally required under the administrative documentation rules. Il Sole reports that authenticating through IT-Wallet is treated as equivalent to SPID and CIE.
The strongest case for the decree
The case for the decree deserves a fair hearing. Italians today juggle SPID providers, the CIE, paper certificates and repeated requests for the same data. Requiring administrations to register as authentic sources means a citizen no longer carries a certificate from one office to another. Exempting wallet attestations from re-verification is what makes that work. Without it, the wallet is just another PDF.
Citizens also keep a choice. Sky TG24 reports that individuals can continue to use traditional document formats, and the obligations fall on public administrations, not on individuals. The wallet is also aligned with the European framework. Regulation (EU) 2024/1183 requires wallets that let users selectively disclose attributes, and it says Member States should not limit access to services for people who do not opt in.
Where proportionality is at risk
The main risk is concentration. One state-controlled register issues the attestations, and one public app hosts them. Sky TG24 reports that under PNRR provisions IPZS becomes majority shareholder of PagoPA with 51%, while Poste Italiane keeps 49%. The Italian state will therefore control both the issuer and the infrastructure operator. That is efficient. It also means a policy change, a security failure or a mission creep decision would spread across every service that trusts the wallet.
The European regulation offers the right design test. It states that wallet providers should ensure unobservability by not collecting data and not having insight into users' transactions, and that use of the wallet should not lead to processing of data beyond what is necessary. The decree's implementation should be measured against those two sentences, not against the number of documents loaded.
The exemption from documentary checks raises a second risk. It is powerful because it removes friction, and it is dangerous for the same reason. If an attestation is wrong, a citizen may have no simple way to challenge it, because the receiving office is legally excused from looking behind it. The 2027 authentic-source deadline therefore needs a data-quality and correction mechanism attached, not just a registration duty. A wrong civil-status record that follows a person into every service is a worse outcome than a slow paper process.
A third issue is scale. Il Sole reports that some 200 documents are due to become available. Widening the catalogue is welcome. But each new attestation type should be justified by a real service need, and relying parties should request only the attributes they need. Selective disclosure is only a safeguard if verifiers are actually barred from asking for the whole record.
What a proportionate rollout looks like
The timetable gives Italy room to get this right, and four steps would help:
- Publish verifier rules. Public and private relying parties should have to state which attributes they request and why. Unnecessary requests should be auditable.
- Build in correction rights. Each authentic source should have a fast, documented route to fix or revoke an attestation, with a stated response time.
- Keep alternatives real. The voluntary character should hold in practice, especially for older citizens and people without recent smartphones. Offices that accept the wallet must not treat paper or SPID or CIE users as second-class.
- Separate issuance from usage logs. IPZS and PagoPA should be barred from keeping records of where and when attestations are used, in line with the European unobservability principle.
The decree was adopted jointly by the government departments concerned, with the Data Protection Authority consulted, according to Certifico's summary. That consultation is a good sign. The next test is whether the Garante's concerns are visible in the technical specifications and in the register's operating rules.
The verdict
Italy is doing the hard part of digital identity, which is getting administrations to share data instead of pushing the burden onto citizens. The decree deserves credit for treating the wallet as public infrastructure with fixed dates. But equal legal weight with SPID and CIE, a state-owned issuer and operator, and an exemption from checks add up to a great deal of trust in one system. Pro-innovation policy should make that trust earned: publish the verifier rules, guarantee correction rights, and hold the wallet to the unobservability standard Europe has already set. If it does, IT-Wallet can become a model for the EU wallet rollout. If it does not, Italy will have built a faster route for its records to reach every counter, wrong entries included.