What is a digital identity? A plain-language guide
A digital identity is the set of data and proofs that show who you are online. Learn how it works, the main types in Europe and why the EU is reshaping it.
Digital identityPublished
A digital identity is the collection of information that represents you online, together with a method to prove that the information is really yours. It can be as simple as an email address and a password, or as formal as a government-issued eID that a bank accepts for opening an account. What matters is not the technology but the question it answers: who is on the other end, and how sure can the service be?
The three parts of a digital identity
Most digital identities, whatever their form, combine three things.
- Attributes. Facts about you: name, date of birth, address, nationality, a customer number, a professional title, or simply an email address.
- Credentials. The means of showing those attributes: a password, a passkey, a smart card, a mobile app, a signed certificate or a document stored on your phone.
- Verification. The process by which someone checks that the credential is genuine and that you are the person it belongs to. Often this involves a trusted issuer, such as a government or a bank, that vouched for the attributes in the first place.
The difference between a throwaway forum account and a state eID is mostly in the third part. A forum accepts whatever you type in. A bank wants an issuer it can trust to have checked your passport.
Types of digital identity you meet in Europe
| Type | Who issues it | Typical use | Strength of proof |
|---|---|---|---|
| Self-asserted account | You (email, username) | Forums, newsletters, shops | Low |
| Platform or social login | Google, Apple, Microsoft and others | ‘Sign in with…’ on third-party sites | Low to medium |
| Bank or telecom identity | Banks, mobile operators | Online banking, contracts, some e-government | Medium to high |
| National eID | The state (ID card, residence permit, app) | Tax, health, official services, remote signing | High |
| EU Digital Identity Wallet | Member states, under EU law | Cross-border identification and credentials | High (required by law) |
Many countries combine several of these. Estonia and Belgium have issued national eIDs for many years, while several other countries, including Sweden and Norway, rely largely on bank-based schemes. Our country guides show what exists where.
Three ways of organising identity
- Siloed accounts. Every service keeps its own copy of your data and its own password. This is simple for the service and tiring for you.
- Federated login. One provider vouches for you to many services, as with ‘Sign in with…’ buttons or a company single sign-on. You get fewer passwords, but the provider can see where you log in.
- Wallet-based identity. You hold credentials issued by trusted authorities and present them directly. The services check the signatures and no central login provider has to be involved in every transaction. This is the model behind the EU wallet.
None of these is perfect. Federation concentrates data, while wallet-based models move responsibility for the device and its backup to you.
Identity and data protection
Name, date of birth, national identification numbers and similar attributes are personal data under the GDPR. A service should ask only for what it needs for a stated purpose, and it should not keep identity data longer than necessary. As a user, that is a good test: if a website asks for a copy of your ID card to let you read an article, something is wrong.
How identity differs from authentication
People often mix up two ideas. Identification establishes who you are, usually once and with some effort, for example when you enrol for an eID. Authentication confirms later that the same person is returning, for example when you unlock the app with a fingerprint. A passkey is excellent at authentication but does not prove your legal name. We explain the distinction in more detail in identity versus authentication.
Why the way identity works is changing
Historically, each website ran its own identity silo. You created yet another account and handed over a copy of the same data again. Federation (single sign-on) reduced the number of passwords but concentrated power in a few large identity providers. States then added eIDs, but these were mostly national and rarely worked across borders.
The European Union is now setting a common frame. Regulation (EU) 2024/1183, often called eIDAS 2.0, obliges every member state to offer at least one EU Digital Identity Wallet by the end of 2026. The idea is that you hold your identity data and credentials yourself on your phone and decide case by case what to show. A shop that only needs to know you are over 18 should not learn your birthday.
Levels of confidence
Not every service needs the same certainty. European law distinguishes three assurance levels, low, substantial and high, depending on how strictly your identity was checked and how strongly your login is protected. Details are on our page about levels of assurance.
What you can do now
- Know what you have. List the accounts that matter most: email, bank, tax or health portal, cloud storage. These form the core of your identity.
- Protect the foundation. Your main email account can reset almost everything else. Use a passkey or app-based second factor there first. See passkeys explained.
- Check your national eID. If your country issues a smart-card ID or an app, activate it and test it once while you do not urgently need it.
- Plan for the wallet. You do not have to do anything yet. When your country launches its wallet, installation will be voluntary and free of charge.
- Keep recovery options current. A lost phone should be an inconvenience, not a lockout.
For the official picture of the EU programme, the European Commission maintains a portal on the EU Digital Identity Wallet.
Common misunderstandings
A digital identity is not a single database entry. There is no central EU file on every citizen. The wallet approach is built around data kept on your own device, issued by authorities that already hold it.
A digital identity is not necessarily a government product. Banks, telecom operators and platforms all provide identity services, with different legal weight.
Having one does not mean sharing everything. Good design lets you reveal single attributes. Whether a given service actually asks for less is partly up to regulation and partly up to the service, which is why the registration of relying parties matters. More on that in our guide to selective disclosure and unlinkability.
Frequently asked questions
Is a digital identity the same as a login?
No. A login (username plus password or passkey) proves that you control an account. A digital identity is broader: it describes who you are and can be proven to several different services, with different levels of confidence. A login is often just one building block of it.
Do I need a digital identity?
You already have one in the loose sense, because every online account is part of it. Whether you need a state-issued eID depends on your country: some services such as tax filing, health portals or bank account opening increasingly require one.
Is a digital identity safe?
It can be, but safety depends on how it is built and how you protect it. State-issued eIDs and wallets are designed around strong cryptography and certification. The weakest point is usually the account used to recover it, such as an email address or phone number.
What is the difference between identity and attributes?
An identity is the overall picture of a person. An attribute is a single fact within it, such as ‘over 18’, ‘resident in Austria’ or ‘holds a driving licence’. Modern systems aim to let you share only the attribute a service needs, not the whole identity.
More in Digital identity
Digital identity for banking: eID vs video ident
How banks verify your identity online: eID, video identification or bank-issued IDs. What the new AML rules from 2027 and the EUDI Wallet change for onboarding.
EU age verification app: the blueprint explained
The EU age verification blueprint lets you prove you are over 18 without revealing who you are. How it works, who pilots it and how it ties into the DSA.
EU Digital Identity Wallet FAQ: your questions answered
Quick answers on the EU Digital Identity Wallet: cost, whether it is mandatory, availability by country, privacy, lost phones, children and non-EU residents.
EU wallet security: phishing, lost phones, fake verifiers
How secure is the EU Digital Identity Wallet? Risks such as phishing, a lost phone, malware and fake verifiers, built-in protections and your checklist.
EUDI Wallet privacy: selective disclosure and unlinkability
How private is the EU Digital Identity Wallet? What selective disclosure, pseudonyms and unlinkability promise, where gaps remain and what you can do.
EUDI Wallet rollout timeline 2024–2027 (status Oct 2026)
Key dates of the EU Digital Identity Wallet from 2024 to 2027, plus which countries are live, in pilot or still planning, as of October 2026.