Join our Newsletter — 33% off our NHI Course

Who is accountable for privacy and adoption decisions in a digital identity wallet programme?

Accountability should sit with both the identity programme owner and the organisations that choose to accept wallet-based identity. The wallet model affects consent, assurance, deletion, and data minimisation. Governance teams must define who approves attribute use, who controls lifecycle changes, and which controls apply when private-sector adoption expands beyond a public-sector pilot.

Why This Matters for Security Teams

digital identity wallet programmes blur a line that many governance models assume is fixed: who controls the identity data, and who decides when it can be used. Once a wallet is accepted by multiple relying parties, privacy obligations, consent handling, and attribute minimisation stop being only programme design questions and become live operational controls. That means accountability has to be explicit across the identity owner, the wallet operator, and every organisation that chooses to trust the wallet for access decisions.

The risk is not abstract. A wallet can concentrate high-value attributes in one place, creating a stronger privacy impact if approvals, retention, or sharing boundaries are unclear. Guidance from eIDAS 2.0 — EU Digital Identity Framework and the privacy control expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls both point toward clear decision ownership, but current practice is still uneven. NHIMG research shows that governance gaps are common in identity programmes, including weak visibility and poor lifecycle discipline, as covered in the Ultimate Guide to NHIs. In practice, many security teams encounter weak wallet accountability only after a pilot is expanded and attribute-sharing decisions have already been made informally.

How It Works in Practice

Accountability should be split by decision type, not by technology ownership alone. The identity programme owner typically governs wallet design, assurance rules, attribute schema, lifecycle events, and privacy controls. The relying organisation that accepts the wallet must own its own acceptance criteria, access policy, and whether the wallet assertion is sufficient for the business purpose. That division matters because the same wallet can be used across very different contexts, each with its own legal basis, retention limit, and assurance threshold.

Practitioners usually make this concrete with a decision register that names the approver for each of the following: attribute release, consent withdrawal, dispute handling, deletion requests, and expansion from pilot to production. The register should also define who changes policy when the wallet model moves from public-sector issuance to private-sector adoption. This is where privacy engineering and identity governance meet. The acceptance decision is not just “can this wallet authenticate a person?” It is also “is the data minimised, is the purpose specific, and is the relying party authorised to receive it?”

For controls, teams often map wallet governance to privacy and access baselines in NIST SP 800-53 Rev 5 Security and Privacy Controls, then align operational ownership with obligations under EU General Data Protection Regulation (GDPR). NHIMG’s Top 10 NHI Issues is useful here because it reinforces the same operational lesson: identity trust breaks down when lifecycle controls and ownership are not enforced end to end. A practical model also separates issuance governance from relying-party governance so that a privacy decision made for one use case does not silently expand to another. These controls tend to break down when a wallet pilot becomes a cross-border or cross-sector deployment because legal basis, attribute scope, and acceptance criteria diverge faster than the programme charter does.

Common Variations and Edge Cases

Tighter accountability often increases coordination overhead, requiring organisations to balance privacy assurance against adoption speed. That tradeoff becomes visible when a wallet programme is asked to support both government services and private-sector onboarding, because each party may want different claims, different retention rules, and different revocation triggers.

There is no universal standard for this yet, so best practice is evolving. Some programmes centralise most decisions in the issuer, while others assign shared accountability through contracts and joint governance boards. The more interoperable the wallet becomes, the more important it is to document who can approve new attribute categories, who can override defaults, and who is responsible when a relying party misuses an accepted credential. That is especially important where an organisation wants to reuse one wallet for multiple purposes without fresh consent.

One common edge case is delegated administration. If a third party helps operate the wallet platform, that party may process personal data without owning the adoption decision. Another is attribute portability, where a user presents the same wallet across contexts but each relying party still needs its own privacy review. NHIMG’s Ultimate Guide to NHIs is relevant because it shows how identity systems fail when lifecycle ownership is assumed rather than documented. The practical rule is simple: the issuer governs the wallet, the adopter governs its acceptance, and both must be able to prove who decided what, when, and under which policy.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV-01 Governance oversight fits cross-party accountability for wallet adoption decisions.
NIST AI RMF GOVERN AI RMF governance patterns help structure decision ownership and accountability.
OWASP Non-Human Identity Top 10 NHI-07 Wallet acceptance depends on identity lifecycle and trust boundary discipline.
CSA MAESTRO GOV-02 MAESTRO addresses governance for agentic and federated identity decision paths.
NIST Zero Trust (SP 800-207) PL-4 Zero Trust requires explicit trust evaluation for each relying party and transaction.

Assign named owners for wallet privacy, acceptance, and lifecycle decisions under governance oversight.