Germany's state digital identity wallet 'd-you' drew heavy criticism on Tuesday at a hearing in the Bundestag's Digital Committee. The session was formally about the Digital Identities Act — the national law Berlin must pass to anchor the EU's revised digital identity regulation — but it quickly became an audit of the German wallet's security and privacy design. Even experts nominated by the governing parties saw significant gaps.

Andreas Hartl, a senior official at the Federal Data Protection Commissioner's office, said a trustworthy public system was welcome in principle, but warned that the first version's capabilities and its delivery timeline must be communicated clearly, and called the lack of pseudonymous use a problem. Lina Ehrig of the Federation of German Consumer Organisations (vzbv) argued that because pseudonymous use will not be ready for the January launch, personal identification data derived from the national ID card should only be released where identification is legally required — opening a bank account or signing a telecom contract. Otherwise, usage events can be linked into detailed profiles, she warned.

The technical criticism was sharper still. Smartphone security researcher Jiska Classen said large parts of the wallet's security architecture remain unpublished and that many phones are not kept up to date — and that with an identity wallet, a compromised device lets an attacker impersonate its owner, book hotels or take out loans in their name. She demanded clear liability rules in the law and a way to block a wallet that also works retroactively. Thomas Lohninger of Epicenter.works said the ecosystem has no way to exclude bad actors: unlike in other EU states, providers are not yet required to justify their query permissions before a supervisory authority, and registration fees are not standard. Bianca Kastl of InÖG flagged the strongly centralised German architecture and a longer-term risk — a wallet is a bundle of cryptographic signatures, and if the integrity of those signatures is broken, for instance by progress in quantum computing, all signed data before and after becomes worthless because undetectable forgeries become possible. She also criticised thin transparency: a bug bounty tied to an unreleased product and a test environment buried behind non-disclosure agreements.

Not everyone was unhappy. Torsten Lodderstedt, a managing director of d-you's operating company Common Codes, defended the design as the 'best balance' of privacy, security and usability, argued that pseudonymity depends on which attributes a proof releases, and said only a cloud security anchor is currently viable because user devices are not secure enough — a view he said the Federal Office for Information Security shares. A direct in-app channel for reporting suspected misuse was not feasible right now, he said, because it would be a 'huge integration project' across many data protection authorities.

What remains unresolved is the clock. A ministry official, Hagen Saxowski, said he could not yet say when d-you will be notified to the European Commission as an eIDAS-compliant wallet, which is only possible at 'feature completed' status, and that the law allows only a national connection for now. The Digital Identities Act must pass in the coming weeks to complete its formal passage through the institutions in time, while Germany's municipal associations said the preconditions for a citizen- and administration-friendly rollout have still not been met.