23 Amendments of Jeroen LENAERS related to 2021/0136(COD)
Amendment 21 #
Proposal for a regulation
Recital 6
Recital 6
(6) Regulation (EU) No 2016/67919 applies to the processing of personal data in the implementation of this Regulation. Therefore, this Regulation should lay down specific safeguards to prevent providers of electronic identification means and electronic attestation of attributes from combining personal data from other services with the personal data relating to the services falling within the scope of this Regulation. Data protection by design and by default, as well as data minimisation, as foreseen in Regulation (EU) 2016/679, should be leading principles in the set-up of this European Digital Identity Wallet. _________________ 19 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), OJ L 119, 4.5.2016, p. 1
Amendment 23 #
Proposal for a regulation
Recital 8
Recital 8
(8) In order to ensure compliance within Union law or national law compliant with Union law, service providers should communicate their intent to rely on the European Digital Identity Wallets to Member States. That will allow Member States to protect users from fraud and prevent the unlawful use of identity data and electronic attestations of attributes as well as to ensure that the processing of sensitive data, like health data, can be verified by relying parties in accordance with Union law or national law. Member States should prevent the unlawful use of identity, and ensure that the relying parties only require data that is strictly necessary for the provision of the service.
Amendment 28 #
Proposal for a regulation
Recital 9 a (new)
Recital 9 a (new)
(9 a) The European Digital Identity Wallet should be developed in a manner that ensures a high level of security, including the encryption of content. The Wallet should also allow the user to consult the history of the transactions, export the wallet’s data, restore the access on a different device and block access to the wallet in case of a security breach, allowing for the data suspension, revocation or withdrawal, and offer the possibility to contact support services of the wallet’s issuer.
Amendment 29 #
Proposal for a regulation
Recital 9 b (new)
Recital 9 b (new)
(9 b) One of the objectives of the European Digital Identity Wallet should be to improve the possibilities of citizens to make their own choices about what data they share, to minimise the amount of shared data for the service they want to use and to better manage and control the shared data.
Amendment 30 #
Proposal for a regulation
Recital 10
Recital 10
(10) In order to achieve a high level of security and trustworthiness, this Regulation establishes the requirements for European Digital Identity Wallets. The conformity of European Digital Identity Wallets with those requirements should be certified by accredited public or private sector bodies designated by Member States. Relying on a certification scheme based on the availability of commonly agreed standards with Member States should ensure a high level of trust and, interoperability and data protection. Certification should in particular rely on the relevant European cybersecurity certifications schemes established pursuant to Regulation (EU) 2019/88120 . Such certification should be without prejudice to certification as regards personal data processing pursuant to Regulation (EC) 2016/679 _________________ 20 Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act), OJ L 151, 7.6.2019, p. 15
Amendment 32 #
Proposal for a regulation
Recital 11
Recital 11
(11) European Digital Identity Wallets should ensure the highest level of security for the personal data used for authentication irrespective of whether such data is stored locally or, on cloud-based solutions or on a combination of both, taking into account the different levels of risk. Using biometrics to authenticate is one of the identifications methods providing a high level of confidence, in particular when used in combination with other elements of authentication. Nevertheless, it should not be a precondition for using the European Digital Identity Wallet. Since biometrics represents a unique characteristic of a person, the use of biometrics requires organisational and security measures, commensurate to the risk that such processing may entail to the rights and freedoms of natural persons and in accordance with Regulation 2016/679. Storing information from the European Digital Identity Wallet in the cloud, including biometric data, has to be an optional feature only active after the user has given explicit consent and should be revocable at all times. Personal data used for authentication should always be encrypted, regardless of whether they are stored locally or on cloud-based solutions.
Amendment 45 #
Proposal for a regulation
Recital 17
Recital 17
(17) Service providers use the identity data provided by the set of person identification data available from electronic identification schemes pursuant to Regulation (EU) No 910/2014 in order to match users from another Member State with the legal identity of that user. However, despite the use of the eIDAS data set, in many cases ensuring an accurate match requires additional information about the user and specific unique identification procedures at national level. To further support the usability of electronic identification means, this Regulation should require Member States to take specific measures to ensure a correct and targeted identity match in the process of electronic identification. For the same purpose, this Regulation should also extend the mandatory minimum data set and require the use of a unique and persistent electronic identifier in conformity with Union law in those cases where it is necessary to legally identify the user upon his/her request in a unique and persistent way. Such process should be driven by the data minimisation principle.
Amendment 47 #
Proposal for a regulation
Recital 25
Recital 25
(25) In the European single market, citizens need to have the opportunity to exchange information about their identity across borders. However, in most cases, citizens and other residents cannot digitally exchange, across borders, information related to their identity, such as addresses, age and professional qualifications, driving licenses and other permits and payment data, securely and with a high level of data protection. This may result in the fact that they are transferring this data in a less secure and disorganised manner.
Amendment 52 #
Proposal for a regulation
Recital 28 a (new)
Recital 28 a (new)
(28 a) Unless specific rules of Union law or national law require users to identify themselves for legal purposes, the use of services anonymously or under a pseudonym should be allowed and should not be restricted by Member States, for example by imposing a general obligation on service providers to limit the pseudonymous or anonymous use of their services.
Amendment 54 #
Proposal for a regulation
Recital 29
Recital 29
(29) The possibility for users to disclose their data in a selective way, so that the user can decide to share only the minimum amount of data really needed to make use of the service, must become one of the key features and advantages of the European Digital Identity Wallet. The European Digital Identity Wallet should, therefore, technically enable the selective disclosure of attributes to relying parties in a secure and user-friendly manner. This feature should become a basic design feature thereby reinforcing convenience and personal data protection including minimisation of processing of personal data. The European Digital Wallet should prevent the tracking of the user and respect the principle of purpose limitation, which implies a right to pseudonymity to ensure the user cannot be linked across several relying parties.
Amendment 66 #
Proposal for a regulation
Recital 35
Recital 35
(35) The certification as qualified trust service providers should provide legal certainty for use cases that build on electronic ledgers. This trust service for electronic ledgers and qualified electronic ledgers and the certification as qualified trust service provider for electronic ledgers should be notwithstanding the need for use cases to comply with Union law or national law in compliance with Union law. Use cases that involve the processing of personal data must comply with Regulation (EU) 2016/679. Use cases that involve crypto assets should be compatible with all applicable financial rules for example with the Markets in Financial Instruments Directive23 , the Payment Services Directive24 and the future Markets in Crypto Assets Regulation25 , Funds Transfer Regulation25a. _________________ 23 Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU Text with EEA relevance, OJ L 173, 12.6.2014, p. 349– 496. 24 Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC, OJ L 337, 23.12.2015, p. 35– 127. 25 Proposal for a Regulation of the European Parliament and of the Council on Markets in Crypto-assets, and amending Directive (EU) 2019/1937, COM/2020/593 final. 25a Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on information accompanying transfers of funds and certain crypto-assets (recast) (Text with EEA relevance) 2021/0241(COD).
Amendment 82 #
Proposal for a regulation
Article 1 – paragraph 1 – point 3 – point i
Article 1 – paragraph 1 – point 3 – point i
Regulation (EU) No 910/2014
Article 3 – point 42
Article 3 – point 42
(42) ‘European Digital Identity Wallet’ is a product and service that allows the user to store identityand manage identity data, confirmations of consent to share personal data, credentials and attributes linked to her/his identity, to provide them to relying parties on request and to use them for authentication, online and offline, for a service in accordance with Article 6a; and to create qualified electronic signatures and seals;
Amendment 103 #
Proposal for a regulation
Article 1 – paragraph 1 – point 4
Article 1 – paragraph 1 – point 4
Regulation (EU) No 910/2014
Article 5
Article 5
Processing and protection of personal data, and pseudonyms in electronic transaction
Amendment 106 #
Proposal for a regulation
Article 1 – paragraph 1 – point 4
Article 1 – paragraph 1 – point 4
Regulation (EU) No 910/2014
Article 5
Article 5
Processing of personal data shall be carried out by implementing the principles of data minimisation, purpose limitation, and data protection by design and by default, in accordance with Regulation (EU)2016/679;
Amendment 110 #
Proposal for a regulation
Article 1 – paragraph 1 – point 4
Article 1 – paragraph 1 – point 4
Regulation (EU) No 910/2014
Article 5
Article 5
Without prejudice to the legal effect given to pseudonyms under national law, the use of pseudonyms in electronic transactions shall not be prohibited.;or their anonymous use shall be permitted without restrictions.
Amendment 120 #
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 4 (a) – point 2
Article 6a – paragraph 4 (a) – point 2
(2) for relying parties to request and validate person identification data and electronic attestations of attributes and to be uniquely identified and limited to only request information based on their intended use of the European Digital Identity Wallet in accordance with Article 6b(1);
Amendment 131 #
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 4 (b)
Article 6a – paragraph 4 (b)
(b) ensure that trust service providers of qualified and non-qualified attestations of attributes cannot receive any information about the use of these attributes;
Amendment 133 #
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 4(b a) new
Article 6a – paragraph 4(b a) new
(b a) enable the user to transfer and restore the European Digital Identity Wallet's data, and to block the access to it in case of a security breach, allowing for the data suspension, revocation or withdrawal.
Amendment 141 #
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 4 (e a) new
Article 6a – paragraph 4 (e a) new
(e a) enable the user to access and request a copy, in a readable format, of the list of actions, transactions or uses of electronic attestations of attributes or person identification data, that have been authorized by the user.
Amendment 149 #
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Article 1 – paragraph 1 – point 7
Regulation (EU) No 910/2014
Article 6a – paragraph 7
Article 6a – paragraph 7
7. The user shall be in full control of the European Digital Identity Wallet and the data it stores. The issuer of the European Digital Identity Wallet shall not collect information about the use of the wallet which are not necessary for the provision of the wallet services, nor shall it combine person identification data and any other personal data stored or relating to the use of t, as well as related third-party services or Member States, shall not have any technical possibility to collect information about the use of the wallet by the user. Moreover, providers of electronic attestation of attributes shall not have any possibility to track, link, correlate or otherwise obtain knowledge of transactions or user behaviour. The European Digital Identity Wallet with personal data from any oshall always provide ther uservices offered by this issuer or from an easily accessible possibility to withdraw their consent or to request the removal of theird-party services which are not necessary for the provis personal data, in line with Regulation (EU) 2016/679. Should such action lead to the cessation of the wallet services, unless the user shas expressly requested itll receive a warning beforehand. Personal data relating to the provision of European Digital Identity Wallets shall be kept physically and logically separate from any other data held. If the European Digital Identity Wallet is provided by private parties in accordance to paragraph 1 (b) and (c), the provisions of article 45f paragraph 4 shall apply mutatis mutandis. The issuer of the European Digital Identity Wallet shall be regarded as the controller according to Regulation (EU) 2016/679 when it comes to the processing of personal data.
Amendment 182 #
Proposal for a regulation
Article 1 – paragraph 1 – point 12
Article 1 – paragraph 1 – point 12
Regulation (EU) No 910/2014
Article 11a – paragraph 2
Article 11a – paragraph 2
2. Member States shall, for the purposes of this Regulation, include in the minimum set of person identification data referred to in Article 12.4.(d), a unique and persistent identifier in conformity with Union and national law, to identify the user upon their request in those cross- border cases where identification of the user is required by law.
Amendment 183 #
Proposal for a regulation
Article 1 – paragraph 1 – point 12
Article 1 – paragraph 1 – point 12
Regulation (EU) No 910/2014
Article 11a – Paragraph 3
Article 11a – Paragraph 3
3. Within 6 months of the entering into force of this Regulation, the Commission shall further specify the measures referred to in paragraph 1 and 2 by means of an implementing act on the implementation of the European Digital Identity Wallets as referred to in Article 6a(10) delegated act.
Amendment 213 #
Proposal for a regulation
Article 1 – paragraph 1 – point 22 – point b
Article 1 – paragraph 1 – point 22 – point b
Regulation (EU) No 910/2014
Article 20 – paragraph 2
Article 20 – paragraph 2
Where personal data protection rules appear to have been breached, the supervisory body shall inform the supervisory authorities under Regulation (EU) 2016/679 and the issuer of the European Digital identity Wallet of the results of its audits., without undue delay;