Towards a Pan-European Trust Framework for Digital Identity

Geneva, Global Digital Collaboration Conference, September 2026

1. Why we are issuing this statement

Europe is not building one digital identity system. It is building several, at the same time, under different legal instruments.

The European Union has eIDAS 2.0 and the EUDI Wallet, extending to the EEA states. Switzerland has the E-ID Act, confirmed by popular vote in September 2025, with rollout through the Swiyu wallet. The United Kingdom has the Digital Identity and Attributes Trust Framework, operated by the Office for Digital Identities and Attributes, alongside GOV.UK One Login. Ukraine has Diia, deployed at national scale under wartime conditions and now part of its accession trajectory. The Western Balkans, the EU candidate countries, Norway, Iceland and Liechtenstein, and the wider membership of the Council of Europe are each moving at their own pace, under their own law.

Each of these is a legitimate exercise of national or Union competence. Together they create a problem that none of them can solve alone. A Swiss employer verifying an EU credential, a Ukrainian professional qualification recognised in an EU Member State, a UK verification service operating across the continent, and a company proving its authorised representatives across thirty or more jurisdictions all encounter the same wall.

The evidence is already on the record. The OECD’s 2024 G7 mapping found no international standard shared across all G7 members, and only six shared between any two. The United Kingdom’s February 2026 survey of digital verification providers found that 79% cited regulatory diversity as a barrier to international operation, and 62% called for cross-border regulatory or political agreement. Surface-level alignment sits on top of deep technical and institutional fragmentation.

Harmonisation is therefore not the open question. The terms on which it happens are. We, the undersigned, intend to work together on those terms.

2. Scope

We use “pan-European” in its full sense: the European Union and the EEA, Switzerland, the United Kingdom, Ukraine and the other candidate and accession states, and in principle the 46 member states of the Council of Europe. A framework which would also regulate the relations between Europe and third countries. The common ground across this perimeter is not a single regulation. It is a shared rights architecture, principally the European Convention on Human Rights and the data protection standards developed under the Council of Europe, which binds jurisdictions inside and outside the Union alike.

3. What we intend to do

We are establishing a standing PETF Collaboration Group: an open, multi-stakeholder working group that will develop a shared reference for a Pan-European Trust Framework, grounded in mutual recognition, and designed from the outset to be interoperable beyond Europe.

The Collaboration Group is a convening mechanism, not a standards body and not a regulator. It will feed into the institutions holding the relevant mandates, including the European standardisation organisations, ISO, W3C, UN/CEFACT, the European Commission, national authorities in participating jurisdictions, the Council of Europe, and the OECD’s work under the Recommendation on the Governance of Digital Identity, which already calls on adherents to establish trust frameworks and to align with them.

4. The design principles we intend to work from

Digital subsidiarity. Functions sit at the lowest competent level. Credentials sit with holders, issuance with the authorities closest to them, verification within the limits of the transaction, and only the minimum necessary governance above that. Subsidiarity is a constitutional requirement under Article 5 TEU and a foundational principle of Swiss federalism. It should also be an architectural requirement.

Mutual recognition over centralisation. Interoperability should be achieved through shared conformance criteria and recognition between jurisdictions and sectors, not through a single registry, a single provider, or a single technical platform. Recognition must work across legal orders, not only within one. This is the specific problem the Pan-Canadian Trust Framework was built to solve inside a federation, and Europe’s version of it spans sovereign states.

Unlinkability by default. Two distinct verifications should not, by default, be correlatable to the same person or entity, whether by one verifier observing repeat interactions, by verifiers colluding, or through issuance and revocation infrastructure acting as a correlation surface. Re-linking should be possible only through a defined judicial procedure with due-process safeguards. This is a binding architectural requirement, not a later addition, and it follows from Article 8 ECHR obligations that apply well beyond the Union.

Open standards and technology neutrality. The framework should be implementable by any conforming system, should not create proprietary lock-in in infrastructure procured with public funds, and should not require any jurisdiction to abandon a technically sound national architecture as the price of recognition.

Accountable change control. Changes to root trust infrastructure should pass through a transparent, time-limited, multi-stakeholder review, with standing for data protection authorities. Switzerland’s 2021 referendum defeat and its subsequent successful vote demonstrate that these safeguards are not procedural friction. They are the source of public consent.

Inclusion by design. Non-digital pathways, delegation mechanisms for those who cannot act alone, and accessible issuance and revocation are conditions of legitimacy, not optional features.

Built for global interoperability. The framework should be an exportable governance model rather than a closed regional system. The Pan-Canadian Trust Framework, the EU-Japan Memorandum of Cooperation, and the OECD Recommendation each show that alignment across jurisdictions is achievable where governance is designed for it.

5. First work programme

Within twelve months of this statement, the Collaboration Group intends to:

  1. Publish a shared vocabulary and a mapping of trust registry, verifier and conformance practice across the EU and EEA, Switzerland, the United Kingdom, Ukraine, and interested candidate and Council of Europe states.
  2. Identify the specific legal and technical gaps that prevent cross-border reliance today, including the recognition of credentials issued outside Union law, grounded in live implementations: business wallets, KYC and KYB, digital product passports, supply-chain traceability, and regulated professions.
  3. Set out candidate architectural requirements for unlinkability, mutual recognition and change control that can be handed to the bodies holding formal mandates.
  4. Report publicly on progress at the Global Digital Collaboration Conference 2027.

6. Basis of participation

This statement is an expression of intent. It is not legally binding, creates no financial or contractual obligation, and does not commit any signatory organisation to a policy position, a procurement decision, or a standardisation outcome.

Individuals may sign in a personal capacity where their institution’s rules require it.

Participation is open to public authorities, standards bodies, international organisations, industry, research institutions and civil society. The Collaboration Group will operate transparently and will publish its outputs openly.

This field is required.
This field is required.