Marte Eidsand Kjørven, Kristian Gjøsteen, Tone Linn Wærstad
2026.11.29Computer Law & Security Review
Abstract
To promote autonomy, safety, and inclusion in the digital age, the eIDAS 2.0 Regulation obliges all member states to provide citizens with a European Digital Identity Wallet (EDIW). A central principle underpinning this framework is sole control , which ensures that the use of EDIWs – as well as electronic IDs and signatures – can be attributed to their rightful users. While the cryptographic understanding of sole control focuses on technical safeguards, its real-world application is far more complex. Practical control over one’s digital identity is often out of reach for individuals with limited digital skills, disabilities, or for those who rely on third-party assistance. Others may fall victim to fraud, coercion, or social engineering attacks. This paper critically examines how the cryptographic concept of sole control has shaped Scandinavian legal frameworks, turning a debatable assumption about user behaviour into a legal obligation. The result is increased exclusion and a troubling shift in legal responsibility from perpetrators to victims of identity theft and abuse. eIDAS 2.0 risks replicating this dynamic, raising serious human rights concerns across the EU. We explore how exclusion, fraud, and coercion can be mitigated through a combination of legal and technical safeguards. We propose a balanced approach – one that acknowledges the inevitability of some fraudulent use without placing the legal responsibility on end users. Otherwise, the EDIW may end up deepening digital inequality or compromising security, thus failing those it was meant to empower.
Zitationsformat
KJØRVEN, Marte Eidsand; GJØSTEEN, Kristian; WÆRSTAD, Tone Linn. Safe and inclusive or unsafe and discriminatory? European digital identity wallets and the challenges of ‘sole control’. Computer Law & Security Review, 2026, 60: 106235.