Companies could soon swap piles of paperwork for a single digital wallet valid across the EU. Before that happens, European lawmakers want to make sure the data behind it never leaves the bloc. As talks with member states approach, experts warn the demand may prove harder and costlier to meet than it sounds.

The idea behind European Business Wallets (EBWs) is simple. A company would get one secure digital tool to prove its identity, sign documents, and deal with authorities in any member state. Today, the same tasks often mean paper forms and different rules in every country. On 10 September, the European Parliament’s Industry, Research and Energy (ITRE) committee backed the plan by 64 votes to seven, with four abstentions. The committee also agreed to open talks with member states.

Lawmakers also added a condition that goes beyond the European Commission’s original proposal. Cloud providers hosting wallet data should be based in the EU, and the data should stay on EU territory “to protect from third-country interference”. They would also ban direct and indirect control of wallet providers by third-country entities or governments. The move fits the bloc’s push for so-called ‘digital sovereignty’.

Member states took a different route. Their position, agreed in the Council of the EU in June, focuses on stricter checks for wallet providers and stronger national supervision. EU leaders want a final deal by the end of the year, but tech experts warn that Parliament’s demand could prove difficult and costly to deliver in practice.

Voluntary for firms, mandatory for authorities

Businesses could choose whether to use the wallets. All public sector bodies, however, would have to accept them for identification and authentication, signing or sealing, submitting documents, and sending or receiving notifications in administrative and reporting procedures. The Commission estimates that, if widely adopted, EBWs could unlock up to €150bn in savings for businesses each year by reducing administrative processes and costs.

The rapporteur, Eero Heinäluoma (S&D/FIN), steers the file through Parliament and defends the new condition. “As a future key digital building block, the Business Wallets must be a truly European solution that help strengthen the EU’s digital sovereignty, reduce vulnerabilities and limit exposure to third-country laws,” he said. 

On paper, the requirement looks workable. Heidi Waem, a partner at the law firm DLA Piper, said that “the requirement to be established in the EU and to process data only within EU territory should, in principle, be feasible. Many cloud and other IT service providers have establishments and infrastructure in the EU, and offer solutions whereby personal data is only processed in the EU.”

“However, challenges arise, with sovereignty being a broad concept lacking a strict definition and variably comprising data sovereignty, operational independence, and technological autonomy, among others. Further, where the requirement extends to not being under the control of a non-EU entity, things may get more complicated, as many cloud and IT service providers are part of a group with establishments in the US or other non-EU countries,” she explained.

Small pool of European providers

Another question is whether fully European providers with sufficient capabilities to manage this service even exist. Jeet Pattanaik, a Berlin-based founder and chief technology officer of Glokal AI and author of Sovereign AI, says they do. Yet EU providers cannot match the depth of managed services, tooling, and ecosystem that the hyperscalers, the largest global cloud companies, offer today.

He also points to a less obvious risk. “For a wallet service that may be simpler than a general cloud workload, so it might be fine. What’s less discussed is that narrowing the eligible supplier pool concentrates risk. If most member states end up on a small number of compliant providers, you’ve reduced foreign dependency and increased single-supplier dependency, which is a different exposure rather than no exposure.” Costs are also likely to be higher at smaller EU providers, which lack the economies of scale that international rivals can unlock.

Mr Pattanaik said that while he was “broadly sympathetic” to the objective, “establishment and control are different things”. He explains why the gap matters.

Establishment versus control

“A provider established in the EU, with infrastructure on EU territory, can still be a subsidiary of a non-EU parent. That parent may be subject to legal orders in its home jurisdiction. A server in Frankfurt owned by a US company is still reachable under US law, and corporate establishment doesn’t sever that. If the intent is to prevent foreign compelled access, establishment plus data location is necessary and not sufficient. Ownership and control structure is the harder question and it’s much harder to legislate cleanly,” he said.

The drafting detail nobody will read closely is how transfers for support and maintenance are handled.
— Jeet Pattanaik, founder and chief technology officer of Glokal AI

Mr Pattanaik also sees the requirement to keep data “stored, processed and transferred exclusively on EU territory” as stronger than it looks. In his view, it could make costs pile up. “Modern cloud services depend on support functions that are inherently global: follow-the-sun engineering, incident response, threat intelligence, telemetry, and third-party sub-processors. Exclusivity either means those functions get duplicated inside the EU, which is expensive and takes years of hiring, or they’re carved out with exceptions, and every exception is where the sovereignty guarantee leaks. The drafting detail nobody will read closely is how transfers for support and maintenance are handled.”

Ultimately, the problem is not where a server is located, but whether anyone can be compelled to hand over its contents, and under whose law. Mr Pattanaik points to rules on ownership, compelled-access obligations, and sub-processor disclosure. In his view, such provisions “would do more work than territorial wording alone”. They are also “testable in a way that ‘established in the Union’ isn’t”.

The next step is three-way negotiations with the Council and the Commission, known as trilogues. The Council hopes to reach a political agreement by the end of 2026.