Paper 2026/867

On the (Privacy) Harms of the European Digital Identity Framework

Christian Knabenhans, École Polytechnique Fédérale de Lausanne
Shannon Veitch, ETH Zurich
Mathilde Raynal, École Polytechnique Fédérale de Lausanne
Theresa Stadler, Swiss Data Science Center
Sylvain Chatel, Helmholtz Center for Information Security
Wouter Lueks, Helmholtz Center for Information Security
Carmela Troncoso, École Polytechnique Fédérale de Lausanne, Max Planck Institute for Security and Privacy
Abstract

As digital identity systems gain traction around the world, many see privacy-enhancing technologies (PETs) as the key to ensuring safe deployment. We critically examine whether this is the case using the European Digital Identity Framework (EUDIF) as an example. We leverage techniques from cryptographic modeling to formally capture the necessary leakage of the functionality of the EUDIF and its proposed applications. Then, we develop a harm analysis methodology that illustrates, using harm trees, how this leakage — and other constraints stemming from design decisions or the context of deployment — lead to harms. Moreover, our harm modeling enables us to distinguish between which pathways to harm are inherent to the core functionality, and which pathways can be prevented with PETs. Our analysis shows that, while PETs can reduce information flows, they fall short in mitigating the harms that deploying digital identity can bring to individuals and society.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
digital identityprivacy harms
Contact author(s)
christian knabenhans @ epfl ch
shannon veitch @ inf ethz ch
mathilde raynal @ epfl ch
theresa stadler @ epfl ch
sylvain chatel @ cispa de
lueks @ cispa de
carmela troncoso @ mpi-sp org
History
2026-05-08: approved
2026-05-04: received
See all versions
Short URL
https://ia.cr/2026/867
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/867,
      author = {Christian Knabenhans and Shannon Veitch and Mathilde Raynal and Theresa Stadler and Sylvain Chatel and Wouter Lueks and Carmela Troncoso},
      title = {On the (Privacy) Harms of the European Digital Identity Framework},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/867},
      year = {2026},
      url = {https://eprint.iacr.org/2026/867}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.