TL;DR: Conflicting interpretations of how biometric verification should be regulated are creating uncertainty for EUDI Wallet rollout, after Spain’s data protection authority said biometrics cannot be the sole authentication method in some cases, according to SumSub. The debate shows that digital identity programmes now need clearer assurance models, not just stronger identity checks.
Editorial analysis by NHI Mgmt Group, based on content published by SumSub: “Industry Groups Warn Biometrics Rules Could Complicate EUDI Wallet Adoption”.
Key questions
Q: What breaks when biometrics cannot be used as the sole factor in digital identity wallets?
A: Wallet programmes break when they assume one biometric check can cover both identity binding and access assurance.
Q: Why do biometric rules create problems for EUDI Wallet rollout?
A: Biometric rules create problems when they are treated as the only acceptable way to authenticate a wallet holder.
Q: How should teams design fallback paths when biometrics are restricted?
A: Teams should design fallback paths that preserve the assurance level required for the use case, not just user convenience.
Practitioner guidance
- Separate binding from authentication Document which wallet controls establish holder binding, which controls perform authentication, and which controls support step-up or recovery so the design can be evaluated against local rules.
- Build jurisdiction-specific assurance matrices Maintain a country-by-country matrix showing where biometrics are permitted as supplementary evidence, where they are restricted, and which fallback factors are required.
- Test non-biometric fallback journeys Run enrolment, recovery, and high-risk access scenarios using PIN and device-based alternatives so the wallet still functions when biometric use is constrained.
Bottom line: The article highlights a regulatory split, not a technical failure, but the practical result is the same: EUDI Wallet rollouts may need different assurance paths across member states.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Biometric-only authentication is too narrow a control model for cross-border identity wallets. The article shows that regulators are already questioning whether one biometric factor can carry the full burden of assurance in digital identity flows. That is not a usability issue alone, it is a governance limitation because assurance must survive policy variation, device failure, and jurisdictional disagreement. Practitioners should treat sole-factor biometric design as structurally incomplete for EUDI-scale deployments.
A few things that frame the scale:
- Under current rules, EU member states are expected to provide digital identity wallets to citizens by the end of 2026, according to the Ultimate Guide to NHIs.
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
A question worth separating out:
Q: Who is accountable when biometric authentication is not allowed as the only method?
A: Accountability sits with the programme owner and the relying party as much as with the regulator, because they must prove that identity assurance is still adequate. The control question is whether the wallet design can withstand local restrictions without losing trust, auditability, or recovery capability.
👉 Read our full editorial: Biometric rules could complicate EUDI Wallet adoption in Europe
Biometric governance, not biometric technology, is the real bottleneck here: the article shows that the same wallet control can be acceptable in one jurisdiction and constrained in another depending on how regulators interpret biometric use. That means EUDI Wallet adoption is being shaped by assurance policy, not just by implementation maturity. For practitioners, the immediate lesson is that cross-border identity programmes need a jurisdiction-aware control model, not a single biometric assumption.
A question worth separating out:
Q: Should identity programmes treat biometric binding and authentication as the same control?
A: No. Biometric binding helps connect a credential to its legitimate holder, while authentication confirms that the holder is controlling the wallet at the moment of use. Treating them as the same control hides assurance gaps and makes it harder to meet different national interpretations or higher-risk use cases.
👉 Read our full editorial: Biometric rules could complicate EUDI Wallet adoption in Europe