Faultline Faultline Kommando 161

Politics · de.indymedia · · 1h

Digital wallet d-you: Experts warn of security risks and loss of trust

Deutsch (original) · Auto-translated to English

Symbolbild · Yevgeny Khaldei / Adam Cuerden / Public domain · Wikimedia Commons

A few months before its launch, the digital wallet was missing crucial functions, experts criticized at a hearing in the Bundestag. Improved security is necessary to create trust for d‑you.


https://cdn.netzpolitik.org/wp-upload/2026/10/d-you_handy_1900.jpg"class="attachment-landscape-860 size-landscape-860 wp-post-image" alt="A smartphone with the d-you logo, in the background a green-colored, splintered glass pane" decoding="async" loading="lazy" srcset="https://cdn.netzpolitik.org/wp-upload/2026/10/d-you_handy_1900.jpg1900w,https://cdn.netzpolitik.org/wp-upload/2026/10/d-you_handy_1900-860x484.jpg860w,https://cdn.netzpolitik.org/wp-upload/2026/10/d-you_handy_1900-1200x675.jpg1200w,https://cdn.netzpolitik.org/wp-upload/2026/10/d-you_handy_1900-380x214.jpg380w,https://cdn.netzpolitik.org/wp-upload/2026/10/d-you_handy_1900-1536x864.jpg1536w" sizes="auto, (max-width: 1900px) 100vw, 1900px" />
A few weeks before the launch of the digital wallet, experts believe that more and more cracks are appearing. – All rights reserved: IMAGO / Herrmann Agency Photography, editing: netzpolitik.org

Trust is crucial to the success of the digital wallet. This was done by 14 experts in a hearing in the Bundestaghttps://www.bundestag.de/ausschuesse/a23_digitales_staatsmodernisierung/...Tuesday clearly. And many of them doubt that the state wallet “d‑you” meets the requirements for this.


The hearing was about thathttps://bmds.bund.de/service/gesetzigungverfahren/digitale-identitaete...Identity Law, about which the Bundestaghttps://netzpolitik.org/2026/bundestag-debatiert-ueber-digitale-briefta...negotiated. It is intended to provide the legal basis for the state wallet. The digital wallet is scheduled to launch on January 2, 2027 – less than three months. In the future, citizens will be able to store digital identification documents, certificates and hotel reservations in the smartphone app.


At the beginning, however, only the ID function should be available, followed later by a driver's license and proof of photo. Only then will further functions be gradually added, which should also ensure more security as well as consumer and data protection.


Experts warn of “Cookie Banner 2.0”


Essential protection functions such as pseudonymous logins, zero-knowledge proofs and selective data sharing are missing at the start. What sounds a bit cumbersome has tangible consequences in everyday digital life: They enable users to protect their identity or only reveal the bare minimum of information. Without these functions, the wallet only offers real name identification, as emphasized by the representative of the Federal Commissioner for Data Protection and Freedom of Information (BfDI), Andreas Hartl.


Unlike in other EU countries, in Germany there is “no check whatsoever as to whether the data being requested is proportionate,” said Thomas Lohninger from the Austrian civil rights organization epicenter.works. He fearshttps://www.bundestag.de/resource/blob/1222150/Stellungnahme-DIdG_Lohnin...his opinionthat companies request an excessive amount of data from the wallet right from the start. In doing so, the federal government is creating a de facto standard that is anything but data protection-friendly, it sayshttps://www.bundestag.de/resource/blob/1222434/Stellungnahme-DIdG_Kastl-...by Bianca Kastlfrom the Innovation Association for Public Health (InÖG).


Lina Ehrig from the Federal Association of Consumer Organizations (vzbv) criticized the fact that responsibility for data protection was being passed on to users. As with cookie banners, they may be overwhelmed by releasing the right data, Ehrig said.


“Signed data follows people for their entire lives”


Excessive data sharing is even more serious because the data is signed cryptographically, several experts warned. This verified data carries something like a government seal of authenticity, which also makes it extremely valuable for data trading and identity theft, warned Bianca Kastl.


The experts were particularly critical of the federal government's decision to make it mandatory to include the biometric photo in the wallet, which is also signed with it. “Signed data follows people throughout their lives,” said Thomas Lohninger.


Kastl is also critical of the decision to use a cloud-based hardware security module as a security anchor. This approach creates a central “single point of failure” that “massively increases the extent of damage caused by data outflows” and the principleSecurity by designcontradict.


Thorsten Lodderstedt from Common Codes GmbH, which develops the state wallet for the Digital Ministry, defended the architectural decision. It offers “the best balance of security, data protection and user-friendliness”. France also took this path for these reasons.

–––

The hut is on fire! We're going in.
We oppose fascisation. We fight for a free, open and solidarity-based society. We defend basic rights for everyone.https://netzpolitik.org/spenden/?via=rss">Thisonly possible with your support.

–––


More control with “trusting parties”


Instead of shifting responsibility for data protection to individual users, the experts suggested several alternatives.


Jiska Classen from the University of Potsdam demanded that only smartphones with a so-called security element should use the wallet, i.e. with a certified, separate hardware component. There is also a need for better liability regulations in the event of misuse of a hacked device.


In addition, several experts called for a risk-based registration and verification procedure for service providers to be included in the Digital Identity Act. When banks, online shops or authorities register, the supervisory authority should check in advance whether the so-called “trusting parties” only request the absolutely necessary minimum data. You should also only receive sensitive data if there is an explicit legal obligation to do so. This can be the case, for example, when opening an account. Social platforms, on the other hand, do not require address data.


A publicly accessible directory should then transparently show which data companies are allowed to request, for what purpose and on what legal basis. “The eIDAS regulation was intended to create an alternative to Google and Co.,” Lohninger recalled the origins of the wallet at the hearing. “But I am very worried that corporations could benefit from the wallet.” Their hunger for data can only be curbed with strict rules and the greatest possible transparency.


The right to a pseudonym


If a wallet offer does not necessarily require ID, the use of pseudonyms should be the standard, according to another requirement. Users can then use names of their own choosing, such as “brieftaube123”, which do not allow any conclusions to be drawn about their true identity. Yesterday, the Federal Data Protection Commissioner viewed the fact that there was no such option for starting the wallet as “unfortunate”.


A pseudonym prevents “over-identification”, tracking and commercial profiling, said Bianca Kastl. In her statement she refers to the research on thehttps://netzpolitik.org/databroker-files/">DatabrokerFilesfrom netzpolitik.org. These have shown “how comprehensive, location-resolved profiles of people can be created using metadata alone.” The wallet threatens to exacerbate this problem.


Lina Ehrig from vzbv also warns that digital wallet providers could offer discounts and additional functions if, in return, users agree that evidence from the digital wallet can be linked across different services. The association is calling for a clear ban on such tie-in transactions. “This is the only way to prevent the digital wallet from becoming an instrument for cross-departmental profile building,” writes the associationhttps://www.bundestag.de/resource/blob/1222152/Stellungnahme-DIdG_Ehrig_...his opinion.


Against the creeping coercion


In addition, it should be left to the user to upload the photo to their wallet. This should not cause them any disadvantages, as they dohttps://netzpolitik.org/2026/biometric-passfotos-statt-pseudonyme-eu-...Requirements of the EU Commissionprovide.


“There is therefore an urgent need for at least one opt-out option with which users can decide against storing their biometric photo in their digital wallet,” writes the vzbv. And Thomas Lohninger added: “Trust is hard earned, the quickest way to lose it is to force people to do something.”


The experts also warned that the wallet itself could gradually become de facto mandatory. Digital identity systems in other countries, such as India, have become a prerequisite over time in order to be able to use administrative services, as Lohninger explained.

–––

The work of netzpolitik.org is financed by donations from our readers.
Become part of this unique community and support our public interest-oriented, advertising- and tracking-free journalismhttps://netzpolitik.org/spenden/?via=rss">nowwith a donation.

–––


For example, more and more government agencies could rely on the wallet as a standard requirement for their services. Teachers could be forced by their schools to use the wallet in internal IT systems, said Lohninger.


“Don’t forget the garbage collection”


If companies violate requirements, users should be able to report this anonymously to an independent contact point. At best, this message should be made directly and “without media disruption” from the app’s planned data protection dashboard, demands Kastl.


The dashboard is intended to provide users in the wallet with an overview of the requested, shared and deleted data. This control tool is currently missing from “d‑you” because the EU Commission has not yet implemented the protocols for deletion requests and complaints.


In the event of violations, the relying parties should also be sanctioned. The penalty should go so far that companies' registration will be revoked and they will be excluded from the wallet ecosystem. “You are building an ecosystem here, don’t forget the garbage collection,” said Thomas Lohninger to the members of the Bundestag.


Trust has to be earned


In view of the abundance of deficits in data protection and security, the Federal Data Protection Commissioner and Thomas Lohninger called for at least an interim solution for the launch of the wallet: initially, it should only be used where there is a legal requirement to provide ID. Only when users can use pseudonyms should the scope of use be expanded.


Bianca Kastl sees it similarly: “Starting with a wallet that cannot be used to save data represents a significant deficiency.” Like the vzbv, it demands that the wallet only be used “in a consumer context” if it offers data-saving core functions.


In addition, the experts demand that a comprehensive data protection impact assessment be carried out before the wallet is launched. To date, there has been no such impact assessment, nor is there a binding commitment to independent data protection certification. “The publication of such a reflection,”https://www.bundestag.de/resource/blob/1222490/Stellungnahme-DIdG_BfDI-6...the BfDI, “would create transparency and a basis of trust.”


Disclosure: Bianca Kastl writes a monthly column on netzpolitik.org.


–––

The work of netzpolitik.org is financed by donations from our readers.
Become part of this unique community and support our public interest-oriented, advertising- and tracking-free journalismhttps://netzpolitik.org/spenden/?via=rss">nowwith a donation.

https://vg03.met.vgwort.de/na/d3ac851f74e54fa382f5396bc9a73508"width="1" height="1" alt>

Web address: https://netzpolitik.org/2026/fachleute-warnen-vor-sicherheitsrisken-und-vertrustsloss/Author/Group: Daniel LeisegangTopics: Netactivismfeed date: Wednesday, October 7, 2026 - 12:22

Read the full story at the source

Source: de.indymedia