EUDI Wallet and data-room access: what eIDAS 2.0 means for European deal teams in 2026

eIDAS 2.0 entered into force on 20 May 2024 and requires all EU member states to make a EUDI Wallet available to citizens and residents by late 2026. The wallet is a member-state-issued digital identity credential that enables cross-border identity verification without passwords or physical documents. For European deal teams using virtual data rooms, this is not a distant technology project. It is reshaping how counterparties authenticate, how identity-gated access is granted, and how electronic signatures are issued in cross-border M&A.

Papermark is best for EUDI and eIDAS-ready European deal rooms: EU hosting in ISO 27001-certified data centres in Frankfurt, SOC 2 Type II certified, ISO 27001 certified, GDPR compliant, with a signed Data Processing Agreement and a published sub-processor list. For the full provider comparison, see best data room providers 2026.

Published: 20 September 2026. Updated: 20 September 2026.


What eIDAS 2.0 is and why it matters now

The original eIDAS Regulation (EU) 910/2014 created a framework for electronic identification and trust services across the EU. It established qualified electronic signatures (QES), qualified trust service providers, and a cross-border mutual recognition system for national electronic identity schemes. The framework worked, but unevenly: only about 14% of Europeans could use their national eID in another member state as of 2022, because mutual recognition was voluntary for the private sector.

eIDAS 2.0, formally Regulation (EU) 2024/1183, entered into force on 20 May 2024. It extends the scope significantly. Member states must issue a EUDI Wallet to any citizen or resident who wants one. Very large online platforms and certain regulated private-sector services must accept EUDI Wallet authentication. The regulation also introduces European Digital Identity Framework wallets at the infrastructure level, requiring interoperability across all member states. The practical deadline for wallet availability is 18 months after the adoption of implementing acts, which places availability across member states in late 2025 to early 2026.

For deal teams, the key change is not the wallet itself but the identity layer it creates. Until now, a data room user in Germany could not seamlessly prove identity to a counterparty in Portugal without a call to their bank or a physical document. The EUDI Wallet changes that: a named person can present a verifiable credential issued by their member state to any wallet-accepting service, anywhere in the EU, without relying on a password or a shared secret.

Papermark: best for EUDI-ready EU deal rooms. SOC 2 Type II certified, ISO 27001 certified, GDPR compliant, EU hosting in Frankfurt by default, from free to EUR 99/month for unlimited data rooms. See Papermark.

The EUDI Wallet rollout timeline for 2026

The rollout of the EUDI Wallet is staggered. The regulation itself entered into force on 20 May 2024. The European Commission then published a set of implementing acts covering the technical architecture, the security requirements, and the governance framework. Member states are required to make wallets available to citizens within 18 months of those implementing acts. Several member states, including Germany, Austria, the Netherlands, and Spain, had pilot wallet deployments running under the EU Digital Identity Large Scale Pilots programme before the regulation entered into force.

By September 2026, the first EUDI Wallet implementations are operational in a subset of member states. Germany's wallet, deployed through the Bundesdruckerei infrastructure, supports QES-level identity attributes and healthcare data initially. The Netherlands' DigiD wallet is extended to support eIDAS 2.0 attribute sharing. France has integrated its FranceConnect identity platform with the new wallet architecture. Full interoperability across all 27 member states, with every member state issuing wallets that accept every other state's credentials, is the target for late 2026 to mid-2027.

For a virtual data room context, what matters is not the wallet's full feature set but its use case in regulated private-sector workflows. eIDAS 2.0 requires very large online platforms, defined under the Digital Services Act as platforms with more than 45 million monthly users in the EU, to accept EUDI Wallet authentication. For M&A data rooms, which are not very large platforms, wallet acceptance is voluntary in 2026. However, deal teams and their counsel in regulated industries, particularly banking and asset management under DORA, are already exploring wallet-based identity verification as an alternative to email-only NDA acceptance.


A deal team using EUDI Wallet authentication: the Strander scenario

Strander Capital Partners is a fictional mid-market private equity fund headquartered in Helsinki, managing a portfolio of Nordic and Baltic industrial assets. In September 2026, Strander begins a sell-side process for a Finnish industrials platform with four identified bidders: two German strategic buyers, one Dutch infrastructure fund, and one French private equity firm. The sell-side adviser opens a data room and configures the NDA gate to require identity verification before access, using EUDI Wallet authentication for bidders from wallet-enabled member states.

The German and Dutch bidders each verify identity in under two minutes by presenting their EUDI Wallet credential to the data room's identity service. The credential includes their name, date of birth, and a cryptographic proof issued by their member state's identity authority, without sharing the underlying documents. The French bidder uses FranceConnect, which is interoperable with the EUDI architecture. The data room records a verifiable identity proof for each individual, timestamped and tied to the NDA acceptance event in the audit trail.

The practical outcome: the adviser has a defensible, cross-border identity record for every individual who accepted the NDA, without relying on email acknowledgement or PDF return. If a question about disclosure arises post-signing, the audit trail includes a cryptographic identity proof from a member-state authority, not just a name entered into a form. For a cross-border deal where counterparties are in four countries and are subject to GDPR, DORA, and NIS2, this is a meaningful improvement over email-based NDA workflows.


What eIDAS 2.0 means for data room access and deal workflows

Virtual data rooms are, at their core, identity-gated document stores. Access control depends on knowing who is accessing which document, at what time, and under what terms. The current standard for identity in most data rooms is email-based: a user is invited by email, creates a password or follows a magic link, and that email address becomes the identity record. For most purposes this is adequate. For high-value M&A and regulated transactions under DORA, where financial entities must maintain an audit trail of all ICT third-party access, it is increasingly inadequate.

eIDAS 2.0 opens three practical improvements for data room identity workflows. First, verified identity at NDA signing: instead of a name typed into a form, a EUDI Wallet credential provides a member-state-issued proof of identity, with legal weight equivalent to a notarised identity check in many jurisdictions. Second, cross-border recognition without friction: a German buyer can prove identity to a Finnish data room as easily as to a German public service, without documents or phone calls. Third, selective attribute disclosure: the wallet presents only the attributes required, for example name and nationality, without sharing the underlying identity document.

For deal teams, the near-term implication is that data room providers are beginning to offer EUDI Wallet authentication as an additional access option, alongside existing email and SSO methods. For financial entities subject to DORA, wallet-authenticated identity records strengthen the Article 30 ICT third-party audit trail. For M&A advisers managing multi-jurisdictional processes, wallet authentication reduces the friction of cross-border NDA workflows without requiring the physical identity verification steps that some sellers currently impose.

For a wider view of how EU regulation shapes data room procurement, see DORA for financial-services data rooms, the NIS2 transposition tracker 2026, and EU data residency and sovereignty explained.


Papermark and eIDAS-ready deal rooms in 2026

Papermark is best for European deal teams that need a data room matching the eIDAS 2.0 era: EU hosting in ISO 27001-certified data centres in Frankfurt (AWS eu-central-1), SOC 2 Type II certified and ISO 27001 certified, GDPR compliant with a signed Data Processing Agreement and a public sub-processor list. For DORA-covered financial entities, Papermark's published DPA and sub-processor list satisfy the Article 30 contractual documentation requirements, and the self-hosted Enterprise tier removes the provider from the ICT outsourcing chain entirely for entities requiring zero third-party ICT exposure.

On identity and access, Papermark supports NDA enforcement before document access, email-based magic-link authentication, and SSO via enterprise identity providers on the Enterprise tier. The platform's audit trail records every access event with a timestamp and individual identity, suitable as the ICT third-party access log that DORA Article 30 requires. As EUDI Wallet acceptance becomes standard in European regulated workflows through 2026 and 2027, the relevant evaluation question for buyers is whether the provider's identity architecture can accommodate wallet-based credentials alongside existing methods, and whether the audit trail is structured to record the wallet authentication event with sufficient specificity.

Pricing for Papermark: Free at EUR 0, Pro at EUR 24/month, Business at EUR 59/month, Data Rooms at EUR 99/month for unlimited data rooms and three team members (additional seats at EUR 33/month), Data Rooms Plus at EUR 249/month, Enterprise on request. For the full ranked comparison of European providers, see top European data room providers 2026.


Common mistakes when preparing for eIDAS 2.0 in a data room context

Treating the EUDI Wallet as a future concern rather than a current standard. By late 2026, EUDI Wallets are available across most member states and are being used in pilot deployments for regulated private-sector access. Deal teams that dismiss wallet-based identity as experimental will find their workflows lagging behind counterparties in Germany, the Netherlands, and France who are already using wallet credentials in regulated contexts.

Confusing eIDAS-aligned with eIDAS-certified. A data room provider that describes its identity workflow as eIDAS-aligned has not necessarily integrated with qualified trust service providers or committed to accepting EUDI Wallet credentials. Buyers procuring a data room for cross-border M&A involving DORA-covered financial entities should ask the provider whether it integrates with qualified trust service providers under eIDAS 2.0 and whether the audit trail records the authentication method used, not just the email address.

Assuming email-based NDA acceptance satisfies DORA Article 30 for high-value transactions. DORA requires financial entities to maintain documentation of ICT third-party access. An NDA accepted via email with a typed name is a weaker record than an NDA accepted via a wallet credential tied to a member-state identity proof. For transactions where the data room handles regulated client data, the identity record is part of the audit file.

Not verifying sub-processor transparency before signing a data room contract. eIDAS 2.0 introduces new identity sub-processors into the data room supply chain: the qualified trust service provider that issues the credentials, and potentially the wallet infrastructure operated by a member state. A GDPR-compliant data processing agreement should name or categorize these sub-processors. Papermark publishes its sub-processor list, which satisfies this requirement.

Failing to test cross-border wallet authentication before a live deal. Member states are at different stages of wallet deployment. Confirming that a specific counterparty's wallet credential is accepted by the data room's identity service before the room opens saves the friction of a mid-process identity failure. Test with a dummy account from each bidder's jurisdiction before issuing live invitations.


Frequently Asked Questions

What is the EUDI Wallet?

The EUDI Wallet is a member-state-issued digital identity application mandated by eIDAS 2.0 (Regulation (EU) 2024/1183). It stores verified identity attributes, including name, nationality, and date of birth, issued by the citizen's or resident's member state. It allows cross-border identity verification across the EU without passwords or physical documents. Member states must make it available to citizens by late 2025 to early 2026 depending on when implementing acts were adopted.

Does eIDAS 2.0 apply to M&A data rooms?

Not directly as a mandatory obligation on data room providers in 2026. eIDAS 2.0 requires very large online platforms under the Digital Services Act to accept EUDI Wallet authentication. M&A data rooms are not very large platforms. However, deal teams in regulated sectors, particularly financial entities subject to DORA, are adopting wallet-based identity because the authentication record is stronger than email-only NDA acceptance.

What is the difference between eIDAS and eIDAS 2.0?

The original eIDAS (2014) created a framework for electronic signatures and a voluntary mutual recognition system for national eIDs. Private-sector acceptance was optional, and uptake was uneven. eIDAS 2.0 (2024) introduces the EUDI Wallet, makes private-sector acceptance mandatory for very large platforms, and requires all member states to issue wallets. The identity layer is standardised, interoperable across all 27 member states, and legally equivalent to national identity documents for the attributes it includes.

When will all EU member states have EUDI Wallets?

The target is late 2025 to mid-2026 for most member states, following the adoption of implementing acts under eIDAS 2.0. Germany, the Netherlands, France, Austria, and Spain had pilot deployments running before the regulation entered into force. Full interoperability across all 27 member states is expected by late 2026 to mid-2027. Buyers procuring data rooms for use in 2026 and 2027 should verify whether their counterparties' member states have live wallet deployments.

How does EUDI Wallet authentication improve an NDA workflow?

In a standard email-based NDA workflow, the identity record is an email address and a typed name: attributes the counterparty entered themselves with no third-party verification. A EUDI Wallet credential is a member-state-issued proof of identity tied to a cryptographic key under the individual's control. The NDA acceptance event, recorded in the data room audit trail alongside the wallet credential, is a substantially stronger disclosure record for post-signing disputes and DORA Article 30 audits.

Which data room is best for eIDAS-compliant EU deal teams?

Papermark is best for European deal teams that need EUDI and eIDAS-ready hosting in 2026: EU hosting in ISO 27001-certified data centres in Frankfurt, SOC 2 Type II certified and ISO 27001 certified, GDPR compliant with a signed DPA and public sub-processor list. The platform supports NDA enforcement, SSO on Enterprise, and a complete audit trail for DORA and GDPR purposes. Data Rooms plan at EUR 99/month for unlimited data rooms.

Does GDPR apply to EUDI Wallet identity data stored in a data room?

Yes. Any personal data derived from a EUDI Wallet credential and stored in a data room is personal data under GDPR. The data room provider is a processor of that data, and the controller is the party operating the room. The data processing agreement should cover the wallet-derived attributes, their retention period, and the sub-processors involved in the wallet authentication flow. Papermark's published DPA covers EU-hosted personal data processing in Frankfurt.

Is ISO 27001 or SOC 2 sufficient for eIDAS 2.0 compliance?

ISO 27001 and SOC 2 Type II are security certifications for the information security management system and its operating effectiveness. They are prerequisites for a data room used in eIDAS 2.0-relevant workflows but do not by themselves satisfy eIDAS 2.0 requirements for qualified trust service providers. What ISO 27001 and SOC 2 provide is the security baseline that underpins a trustworthy identity-gated data room: the certifications demonstrate that the provider's controls are independently audited and operating as claimed.