DIN Standards Committee Information Technology and IT Applications
Guidelines for the onboarding of user personal identification data within European Digital Identity Wallets
Abstract
This document defines and describes the concept of on-boarding of person identification data (PID) within a Wallet. The scope of this document includes cases where a natural person is the User in control of a Wallet. This includes a natural person who is in control of their own information, as well as natural persons who control information to represent another natural person or a legal person. This document considers a single set of PID attributes linked to a single Wallet Unit. This does not exclude the issuance of multiple PIDs representing the same set of PID attributes, e.g. batch issuance. It also provides the general workflow, the roles and responsibilities at stake, and links the on-boarding with the Level of Assurance concept underpinning eIDAS [1]; The scope of this document includes cases where a natural person is the User in control of a wallet. This includes a natural person who is in control of their own data as well as natural persons who control data to represent another natural person or legal person. EXAMPLE If a natural person represents a legal person, the PID provider can issue a "representation PID" in an own Wallet Unit for representation purposes controlled by the natural person Wallet User. The "representation PID" is a kind of attestation which contains PID about the natural person (representative) and about the legal person (representee). This document is limited to the on-boarding of an unique set of person identification data, complying with the legal provisions of eIDAS [1], in particular (1) issued in accordance with Union or National laws, and (2) conformant with the relevant implementing act [5]. The following aspects are out of scope of this document: - the on-boarding of person identification data within a Wallet where the User is a legal person; - other types of on-boarding, such as: - provisioning of person identification data after revocation, expiration or deletion; - addition of other Attributes (under the shape of attestations) in accordance with the requirement of Level of Assurance “High” which are not part of the set of person identification data but are part of the legal identity under National's laws; - management of person identification data (deletion, update, etc.); - provisioning of person identification data which is not compliant with the relevant implementing act [5]; - provisioning of a partial set of person identification data; - provisioning of supplemental set(s) of person identification data (multiple PIDs);
Begin
2022-12-14
WI
00224276
Planned document number
FprCEN/TS 18098
Responsible national committee
NA 043-04-17 AA - Cards and security devices for personal identification