Paper 2026/867
On the (Privacy) Harms of the European Digital Identity Framework
Abstract
As digital identity frameworks (DIFs) gain traction around the world, many see privacy-enhancing technologies (PETs) as the key to prevent their potential negative societal impacts such as discrimination or surveillance. We critically examine whether PETs can achieve this goal using the European Digital Identity Framework (EUDIF) as an example. We develop a harm analysis methodology based on harm trees that illustrates how information leakage, certain design decisions, or a DIF's deployment context lead to harms. We leverage techniques from cryptographic modeling to formally capture the leakage of the core functionality of the EUDIF and its proposed applications. Our harm modeling elucidates which pathways to harm are inherent to the EUDIF's core functionality, and which pathways can be mitigated through PETs. Our analysis shows that, while PETs can reduce information flows, they fall short in actually mitigating the harms that deploying digital identity can bring to individuals and society.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- digital identityprivacy harms
- Contact author(s)
-
christian knabenhans @ epfl ch
shannon veitch @ inf ethz ch
mathilde raynal @ epfl ch
theresa stadler @ epfl ch
sylvain chatel @ cispa de
lueks @ cispa de
carmela troncoso @ mpi-sp org - History
- 2026-09-16: revised
- 2026-05-04: received
- See all versions
- Short URL
- https://ia.cr/2026/867
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/867,
author = {Christian Knabenhans and Shannon Veitch and Mathilde Raynal and Theresa Stadler and Sylvain Chatel and Wouter Lueks and Carmela Troncoso},
title = {On the (Privacy) Harms of the European Digital Identity Framework},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/867},
year = {2026},
url = {https://eprint.iacr.org/2026/867}
}