By clicking "Accept", you agree to the storing of cookies on your device to enhance site navigation, analyze site usage and assist in our marketing efforts. More info

EUDI Verifier Registration, Explained

Published
July 30, 2026

Join 14,000+ identity enthusiasts who subscribe to our newsletter for expert insights.

By subscribing you agree to with our Privacy Policy.
Success! You’re now subscribed to the newsletter.
Oops! Something went wrong while submitting the form.

One of the most misunderstood parts of the European Digital Identity Wallet is the role of verifier registration.

It’s often assumed to be a gatekeeping or approval mechanism. According to Mirko Mollik, Identity Architect at SPRIND (Germany’s Federal Agency for Breakthrough Innovation), that assumption is wrong.

In Germany’s EUDI approach, verifier registration exists primarily because of GDPR, not because the government wants to approve or monitor every interaction.

GDPR limits what can be requested and when

Mirko was clear that GDPR fundamentally shapes verifier behavior.

If there is no legal requirement to identify a person, services must allow the use of pseudonyms.

He contrasted regulated use cases, such as banking or AML-driven onboarding, with social platforms like LinkedIn or YouTube.

In regulated scenarios, requesting strong identity attributes is legally justified.

In unregulated scenarios, services may still ask for names, but they must also allow users to choose a pseudonym.

This distinction is critical for understanding what EUDI is trying to enforce:
purpose limitation and proportionality, not blanket identification.

The verifier registry is about transparency, not pre-approval

Germany’s verifier registry is not designed to approve every request or validate every business model.

Mirko explicitly explained why that would not scale.

Instead, the registry requires verifiers to:

  • Identify who they are
  • Declare what data they intend to request and for what purpose
  • The registry does not approve each request ahead of time.

What it does create is:

  • Strong business identification (KYB/KYC)
  • Public transparency around declared purposes
  • A clear basis for legal enforcement if data is misused

If a verifier over-collects, misrepresents its purpose, or abuses access, there is a documented trail that enables accountability after the fact.

This is a fundamentally different model from pre-approval, and one designed to scale to thousands of verifiers.

Peer-to-peer data exchange is a core design principle

Credential presentation happens peer-to-peer:

  • Directly between the user’s wallet and the relying party

The registry does not see:

  • Which wallet is interacting with which verifier
  • Which credentials are being presented
  • When a specific transaction takes place

This separation is intentional.

The registry’s role is limited to:

  • Issuing verifier certificates
  • Providing revocation information
  • Acting as a trust anchor

It is explicitly designed to avoid centralized tracking of interactions.

As Mirko framed it, the goal is to make misuse legally risky, not to make every interaction visible to the state.

Why this matters

Taken together, these two design choices explain a lot about how EUDI is meant to work in practice:

  • GDPR sets the boundaries on what verifiers can ask for
  • Registration creates accountability, not approval
  • Peer-to-peer exchange preserves privacy, even at scale

If EUDI succeeds, it won’t be because every verifier was pre-approved.

It will be because the system makes over-collection and misuse hard to hide, while keeping everyday identity interactions private.

That balance — transparency without surveillance — is one of the most important architectural decisions in Europe’s digital identity rollout.

A unified identity experience, without rebuilding your stack

Truvera helps you issue and verify digital IDs using the identity systems you already have. Connect IAM, IDV, and partner systems to create a unified identity experience that reduces re-verification, lowers friction across channels, and enables trusted interactions at scale.