Dr. Christian Lange-Hausstein’s Post

Paying with EU Digital Identity Wallet could look like this. Our new technical discussion paper with lots of facts is linked in the comments (+ many more sequence diagrams as a Christmas present for my law peers). If you are wondering why we worry about this, check Recitals 28, 31 eIDAS2, 111 PSR, Explanatory memorandum page 5 of digital euro proposal. Happy to discuss! #eidas2 #digitaleuro #digitalidentity #IDWallet #EUDIW Oliver Lauer Nina Groß Florian Andreae Ronny Khan Frank Weigand Tim Kremer Mirka Lehrer

  • No alternative text description for this image
Vincent Jansen

Vice President at INNOPAY, a business of Oliver Wyman - Data sharing, Digital Identity & Payments - Strategy, Product Development & Execution

1y

Please help me... what do I miss? Recital 31 states nothing else than "Secure electronic identification and the provision of attestation of attributes should offer additional flexibility and solutions ... to support the fulfilment of strong customer authentication requirements for account login and initiation of transactions in the field of payment services." To me this would only mean that the "ID" wallet, as a generic tool, adds value to a specific process that is payment authorisation. And I'm sure it will offer tremendous value, just as it will to other processes. But it doesn't mean that every "ID" wallet should be offering payment screens. Just as they won't be obliged to offer any other specific authorisation flow for energy, health or any of the other mandatory sectors.

David Birch

International keynote speaker, author, advisor, commentator on and investor in digital financial services. Recognised thought leader whose books on digital identity, money & assets have been widely praised.

1y

surely a much better idea is... Present ID to merchant. Merchant sends request-to-pay (including the invoice) to the ID. Customer sees request-to-pay and authorises it. Errrr... that's it. That way the merchant doesn't have to handle the customer's chosen payment instrument at all, they just get a confirmation from their bank that the money has been paid, there's no need for them to know how it was paid.

Anders Rundgren

🚀 "French Tech" Inventor, Consultant and Entrepreneur

1y

Christian Lange-Hausstein Apple Pay does not use this flow and I don't think EPI will either.

Alex Tweeddale

Product Manager & Identity Standards Architect at cheqd | Steering Committee Member at Trust over IP (ToIP) | National Expert at British Standards Institute (BSI)

1y

Christian Lange-Hausstein in the New Year I'd love to show you our work on payments for verifying Credential Status. It could layer in here very nicely!

Marten Voulon

Digitisation & Data Protection Lawyer at ABN AMRO Bank N.V.

1y

Thanks for sharing! I wonder if the ASPSP is able to match the PID with the customer data the ASPSP is holding. And is it proportional to share the whole set of PID?

Vincent Jansen

Vice President at INNOPAY, a business of Oliver Wyman - Data sharing, Digital Identity & Payments - Strategy, Product Development & Execution

1y

If this is the setup, can you please elaborate a bit on the liability the issuer of the wallet will assume towards the ASPSP for mistakes in displaying payment details and dynamic linking and/or Payee fraud? I see this as the hurdle that cannot be overcome.

Mark Bennett

CEO Sentry Enterprises 🚀 Technology trailblazer and futurist. Leading companies into an abundant future of possibilities.

1y

I'm not trying to be pedantic, but where is "Identity" in this flow? In other words, where does proof of identity actually occur? Or is the assumption that the devices, on which the wallet presides, provide that service?

Stephan Engberg

Specialist in trustworthy identity, security and data sharing

1y

Payment should always be cash payment - not assuming a cheque (signed transfer request). Banks and governments have no business knowing what citizens do with whom. Adding contextual security such as age credentials, AML or contractual accountability are secondary issues. If the citizen do not have cash, she can get the money in-process with data minimized means. One or more of the later steps may require identity and credential verification according to the assurance level required.

See more comments

To view or add a comment, sign in

Explore content categories