The European Digital Identity Wallet (EUDI Wallet) is, in simple terms, an official app that allows every European citizen to store all their pre-authenticated digital identity documents on their mobile phone, share them (for example, with a hotel before check-in) and sign digitally with speed and ease, all with full legal validity.
The acronym EUDI stands for European Digital Identity. The digital documentation contained in the EUDI Wallet is a set of electronic attribute attestations which, within the European ecosystem, are issued under common rules and have legal validity throughout the Union. What does this mean for tourism operators? Less friction in online interactions, less time spent at reception, fewer data entry errors and greater legal certainty in data verification. The framework is already approved and being rolled out, with rules defining what a wallet must do, how its security is certified and how these attestations are issued and verified.
What this means at reception: real pre-check-in and quality data
With the EUDI Wallet, check‑in begins before the guest arrives. From their mobile, the guest authorises which data to share and presents only what is necessary for registration. At the front desk, verification takes seconds and the mandatory fields are completed with data that has already been verified. Moreover, the same wallet can facilitate the use of a qualified electronic signature on admission documents or consent forms, with the evidentiary value required in the tourism environment. For the operations team, the effect is tangible: shorter queues, fewer corrections and a more reliable guest record for audit and reporting purposes. All of this is supported by European specifications that establish minimum functions, integrity and certification of the wallets, reducing technological uncertainty.
What we learnt from the Benidorm pilot
Benidorm has been the most visible tourism use case within the European pilots (carried out by the European Digital Wallet Consortium, or EWC). The objective was simple yet ambitious: to use the EUDI Wallet to enable guests to present verifiable credentials that would automatically and securely populate the required data in the hotel register. The first tests were conducted in a laboratory environment; subsequent iterations were progressively aligned with the European reference architecture to approach real-world conditions. The operational outcome points in the expected direction: more agile processes, reduction of manual errors and an improved guest experience, whilst also strengthening the traceability of consent and verifications.
The outstanding issues that tourism operators should bear in mind
The pilot also shed light on two key issues for Spain. The first is the requirement for a ‘document with photograph’ that many authorities request within the traveller registration framework (a legal obligation under Spanish law for hotels to report guest data to the police). The basic wallet identifier — the personal identification dataset, or PID – is not designed as a ‘document with photograph’ and, on its own, does not meet this operational need. The practical solution involves incorporating an additional attribute attestation of the PhotoID type or a digital travel credential, issued by a trusted source or by a qualified trust service provider, so that the hotel has a functional equivalent to the physical identity document with photograph. The second issue is the formal acceptance of the evidence package. Although the technology allows all required fields to be populated and proof of verification and consent to be retained, the final validation of this ‘equivalent proof’ requires an operational agreement with the competent authority. The good news is that the European framework already details how the PID and attestations are structured, and how wallets must operate; the next step is to confirm, country by country, the evidential equivalence through a controlled pilot with a contingency plan.
Security and compliance: European standards, risks under control
In a sector where identity, payments, mobile keys and personal data all coexist, security is not an afterthought. Europe has established certification requirements for wallets that cover functionality, cybersecurity and data protection; furthermore, NIS2 raises the bar for digital suppliers and supply chains. For a hotel group, this translates into requesting clear evidence of risk management, proof of compliance and business continuity measures from its integrators and issuers, and into aligning its own internal controls with that standard. The objective is straightforward: to ensure that the new check-in experience is faster without sacrificing security or compliance.
Who are the incumbent operators that will ensure success
Although it may seem that hotels and regulated accommodation providers, or tourism operators in general, are the ones most likely to be affected by the adoption of the EUDI Wallet, this is not the case. There are more stakeholders who must collaborate to ensure successful adoption, given that the combined approach of compliance, legal certainty and technology requires a multidisciplinary effort. Starting with the sector itself, the actions of travel agencies, tour operators or major digital platforms will be key, so that from the very outset of booking a holiday package, identity and contracting are properly addressed. All of this is aimed at enabling service providers to deliver the best customer experience with enhanced operational efficiency and legal safeguards. For this reason, all technology suppliers in the sector must also be part of the equation; they will need to integrate these standards into their processes, which will have to coexist with the needs of non-EU guests. And outside the sector, there is one player in particular that takes on special relevance: the QTSP. This figure, also known as a Qualified Trust Service Provider, acts as the guarantor of the trust scheme, enabling the issuance and verification of both identities and electronic attribute attestations of travellers for all ‘relying parties’ (as defined by eIDAS, the European regulation on digital trust). The relying parties are all the tourism operators we have just listed. And finally, all implications regarding privacy, compliance or legal certainty in general must be supported by appropriate legal advice to complete the multidisciplinary approach mentioned at the beginning of this post.
What steps make the most sense now
The most prudent recommendation is to engage with this opportunity from the outset, following the regulatory and operational rollout of the entire ecosystem, especially regarding the ‘outstanding issues’ for the sector. Once the timeline for achieving viability is clear, the time will come to design a contained pilot in one or two properties, with clear success metrics: processing times, error rates, guest satisfaction and evidential quality. And from there, if viability is confirmed, the next step is to integrate the wallet with the PMS, the payment gateway and, where applicable, mobile keys, so that the experience is seamless from end to end. The entire process should be approached with a multinational focus, since despite the universality of the EUDI Wallet within the European context, the non-wallet process will continue to exist for non-EU citizens from countries where local regulations on identification and traveller registration do not align with the wallet.
Hugo Alonso
Digital Product and Strategy Manager at g-digital

