DocbyteFacebookPixel
Join the Docbyte Vault 26.3 Executive Preview — Thu 29 October, 12:00–18:00, Ghent — Request an invitation

Zero-Knowledge Proofs: The EUDI Wallet Is Not a Privacy Threat. It Can Give You More Control.

[tta_listen_btn]

Table of Content

When people hear “digital identity wallet”, many imagine a central database containing everything about them.

That concern is understandable. A European Digital Identity Wallet may hold identity data, driving licences, education credentials and other official documents. But the core idea behind the EUDI Wallet is not to make people share more information.

It is to help them share less.

 

Today, proving one thing often reveals many others

Imagine that a website needs to check whether you are over 18.

Today, you may be asked to show an identity card or passport. That document contains much more than your age: your name, address, nationality, photograph and document number.

The service receives all of that information, even though it only needs one answer.

With a privacy-preserving wallet, the service could receive a much smaller statement:

This person is 18 or older.

Your exact date of birth and address would not need to be shared.

That principle is called selective disclosure. The wallet shares the specific information required for a service, while keeping unrelated information private. The European Commission describes selective disclosure as a data-minimisation feature that gives users more control over their personal data. [1]

 

The wallet is a controlled intermediary

In a typical wallet interaction, three parties are involved:

  • The issuer: a government, university, employer or other trusted organisation that issues and signs a digital credential.
  • The wallet: an application on the user’s device that stores the credential and helps the user present it.
  • The verifier: a bank, website, airport, employer or public service that needs to check a specific fact.

 

The issuer signs the credential so that the verifier can check its origin and integrity. When a verifier asks for information, the wallet can show the user what is being requested before anything is shared.

The interaction is therefore not simply:

Here is my entire identity.

It can be:

This service is asking for this specific fact. Do you want to share it?

 

From a full document to one relevant fact

Selective disclosure could be used to prove that:

  • someone is over 18;
  • someone is a student;
  • someone lives in a particular municipality;
  • someone holds a valid driving licence;
  • someone has a professional qualification;
  • someone meets a financial condition.

 

In the last example, a person might prove that their balance is above a required threshold without revealing the exact amount.

That is where zero-knowledge proofs can become useful.

 

What is a zero-knowledge proof?

A zero-knowledge proof allows someone to prove that a statement is true without revealing all the information behind it.

For example, a wallet could prove:

This person is at least 18 years old.

without disclosing the exact date of birth.

Or it could prove:

This account satisfies the required balance condition.

without revealing the account balance itself.

The European Digital Identity Framework explicitly points towards privacy-preserving technologies, including zero-knowledge proofs, and requires the wallet architecture to support selective disclosure. [2]

 

What happens behind the scenes?

The technical details involve digital signatures, hashes and sometimes special cryptographic proof systems.

A digital signature allows a verifier to check that a credential was issued by a trusted organisation and was not altered.

A hash is a kind of digital fingerprint. It helps a verifier check that a disclosed value corresponds to the value that was originally issued.

Some approaches add a random value, called a salt, before creating the hash. This makes it harder to recognise the same value across different transactions.

These mechanisms do not make a person invisible. They are tools for reducing unnecessary disclosure and making different transactions harder to link together.

 

Is the wallet automatically private?

No. This is an important qualification.

A wallet is not a magic privacy button. Its privacy benefits depend on how it is built, regulated and used.

A well-designed wallet should:

  • clearly show which data a service is requesting;
  • require informed user consent;
  • avoid unnecessary universal identifiers;
  • reduce the ability to link separate transactions;
  • disclose only what is needed;
  • provide a transparent history of data sharing;
  • be independently tested and securely implemented.

 

The EUDI Wallet architecture is explicitly based on privacy by design, data minimisation and user control. The European Commission also describes a privacy dashboard showing what was requested and shared. [3]

But the implementation still matters. A service could ask for too much information. A confusing interface could lead users to approve something they did not understand. A poorly secured wallet could create new risks.

Privacy is therefore not guaranteed merely because an application is called a wallet.

 

Privacy is not the same as complete anonymity

A wallet does not make every interaction anonymous.

When opening a bank account, a bank may legally need to know who you are. When using a public service, identification may be necessary.

In this context, privacy means:

The organisation receives the information it genuinely needs, and not everything that happens to be available.

That distinction matters. The goal is not to hide all identity information in every situation. The goal is to give people more control over what they reveal, to whom and for what purpose.

 

Why this can be a privacy improvement

Today, people often face two poor choices:

  1. hand over a complete document;
  2. lose access to a service.

A privacy-preserving wallet can create a third option:

Prove what is necessary without revealing everything else.

That matters because digital information is easy to copy, store, combine and reuse. If a service does not receive your address, it cannot later use that address for a purpose unrelated to the original transaction.

The wallet does not protect privacy by hiding all information. It protects privacy by reducing unnecessary information flows.

 

What should users ask?

When using a wallet, the important questions are:

  • What information is being requested?
  • Why is it needed?
  • Can I refuse without losing an unrelated service?
  • Is only the minimum information being shared?
  • Can I see who received it?
  • Can different transactions be linked to me unnecessarily?
  • Can I request deletion where the law allows it?

 

These questions are more useful than simply asking whether a wallet is “good” or “bad” for privacy.

 

Conclusion

The EUDI Wallet is not intended to be a digital passport that users must show in full every time.

Its more promising model is:

“Prove what is needed. Share no more than necessary.”

Selective disclosure and zero-knowledge techniques can make that model practical. The technology and standards are still evolving, and advanced cryptographic schemes are not all equally mature or formally accepted for public-sector use. ENISA maintains guidance on cryptographic mechanisms used in cybersecurity certification. [4]

The direction, however, is clear. Digital identity does not have to mean distributing more personal data. If implemented properly, it can help people share less, understand more and regain control over their digital identity.

 

Sources

1. European Commission: What is selective disclosure of attributes?

2. Regulation (EU) 2024/1183 on the European Digital Identity Framework

3. European Commission: Security and privacy of the EUDI Wallet

4. ENISA: EUCC Guidelines on Cryptography

Picture of Frederik Rosseel
Frederik Rosseel

Hi, I’m Frederik, CEO of Docbyte. Having pioneered solutions in digital archiving and qualified trust services for years, I distill that invaluable experience into writing. My goal is to help businesses achieve robust data security and seamless regulatory compliance through crystal-clear insights

Contact Us


At Docbyte, we take your privacy seriously. We’ll only use your personal information to manage your account and provide the products and services you’ve requested from us.

Are you interested in contributing to our blog?
Recent News