EUDI Wallet roles explained
An EUDI transaction involves several independent roles. Naming them correctly prevents an organisation from assigning the wrong legal, security or operational responsibility to its wallet vendor.
The EUDI Regulation defines the ecosystem and obligations. Ireland's wallet testing material identifies public bodies involved in the current test, but the production allocation of every Irish role should be checked as implementation develops.
For: product, legal, privacy, security and architecture teams. This is independent information, not legal, compliance or security advice.
Role map
| Role | Main job | Buyer question |
|---|---|---|
| Wallet provider | Provides and operates a recognised wallet solution. | Who is accountable for wallet conformity and lifecycle? |
| PID provider | Issues the core person-identification data. | Which authority verifies and signs the identity attributes? |
| EAA/QEAA provider | Issues electronic attestations of attributes. | What makes the attribute trustworthy and current? |
| Relying party | Requests and validates data for a service. | What data is requested, for what purpose and under which rule? |
| Trust service provider | Provides signatures, seals, timestamps or related trust services. | Is qualified status required for this transaction? |
| Assessor/certifier | Evaluates conformity or security against an applicable scheme. | What exact product and version was assessed? |
One company can hold several roles
A commercial organisation may provide a verifier, orchestration layer and managed service. That does not collapse the roles. Map each processing operation, contractual duty and technical trust decision separately.
The issuer-holder-verifier flow
- An issuer validates attributes and issues a signed credential.
- The holder stores it in a wallet under the wallet's security model.
- A relying party identifies itself and requests specified attributes.
- The holder reviews and authorises a presentation.
- The verifier checks signatures, status, trust and transaction binding before the service decides what to do.
Irish project worksheet
- Name the organisation performing each role.
- Record the legal and technical source for the role.
- Document the attributes exchanged and why each is required.
- Separate the wallet transaction from the service's final eligibility decision.
- Assign incident, support, correction and revocation responsibilities.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
- Regulation (EU) 2024/1183
- European Commission EUDI Wallet Toolbox and ARF
- Government Digital Wallet data privacy notice
- OpenID Digital Credentials Protocols
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing