Credentials
Person Identification Data (PID)
Person Identification Data, or PID, is the core identity credential in the EU Digital Identity Wallet: the attested set of attributes that establish who someone is, issued by a member state designated PID provider. It is the wallet's identity document, and it carries a name and a date of birth.
Also called: PID, person identification data, PID provider
At a glance
- What it is
- The wallet's core identity credential
- Issued by
- A member state designated PID provider
- Contains
- Identity attributes including name and date of birth
- Right for
- Knowing who someone is
- Wrong for
- Knowing only whether they are old enough
What it is for
PID is the foundation credential. It is what a member state issues to establish identity in the wallet, and what other attestations are anchored to. Where a service genuinely needs to know who someone is, opening a bank account, signing a contract, accessing their own records, PID is the right credential to ask for.
PID providers are designated at member state level and appear on the ecosystem's trusted entity lists, which is how a verifier decides whether a PID it receives came from an authority rather than from someone convincing.
Why it is usually the wrong credential for an age check
PID contains a date of birth. You can compute whether someone is over 18 from it, and doing so means you received their date of birth, and usually their name with it. You have then answered a yes-or-no question by collecting identity data, which is the exact trade the wallet was designed to avoid, and which brings retention, breach and subject-access obligations with it.
The alternative is a purpose built attestation carrying age booleans and nothing else. Asking for PID when a narrower credential would answer the question is the wallet-era version of photocopying a passport to check someone is an adult, and under the DSA in particular, collecting more personal data than the check requires is the thing Article 28(3) pushes back on.
Check one yourself
Reading about it only gets you so far. These are free validators in Tessio Labs, no signup, and nothing you paste is stored.
Why it matters
Choosing which credential to request is a data protection decision, not a technical one. Asking for PID to answer an age question means holding identity data you did not need.
If a vendor's age-check flow reads a birth date out of a PID, they're handling personal data about your users whatever their retention policy says. Ask which credential and which attribute they request.
Frequently asked
Can I ask for just the date of birth from a PID?
Selective disclosure lets you request fewer attributes, but a date of birth is still identity data and still more than a yes-or-no answer about age. If the question is "is this person over 18", a credential that answers exactly that's the proportionate request.
Who issues PID?
Providers designated by each member state. Which entity that's varies by country, and a verifier checks the provider against the ecosystem's trusted entity lists rather than by name.
Is PID the same as the wallet itself?
No. The wallet is the app holding credentials; PID is the identity credential inside it. A wallet can hold PID plus any number of other attestations.
Primary sources
This is a plain language explanation, not legal advice. Specifications and dates in this area move, so check anything you are going to rely on against the primary sources.
Keep reading
Age verification API
Or skip the theory and build against it
Tessio proves someone is over 18 from their EU Digital Identity Wallet and stores no personal data. Access is invite only while we onboard design partners. Tell us what you're building.