Paper Type: Statements / Open Letters

  • Memo to Lawyer-Linguist Staff Reviewing Final Trilogue Version of eIDAS Recital (32) and Article 45

    Precision matters, particularly in the final stages of legislation. Following the conclusion of the eIDAS 2.0 trilogue, ESD identifies a potential inconsistency between the definition of Qualified Website Authentication Certificates (QWACs) in Article 3 and the wording of Recital 32. While Article 3 expressly recognises website authentication as a function of these certificates, the recital refers only to their role in linking a website to the person or organisation behind it. ESD proposes a targeted linguistic adjustment to ensure that the final text consistently reflects both functions and avoids uncertainty for the Commission, QTSPs, browsers and website owners.

  • Concerns Regarding eIDAS Review and Recent Compromise on Article 45 and Related Recital 32 – Contradictory Wording

    As the eIDAS 2.0 trilogue moves into its final technical negotiations, ESD identifies contradictory wording in Recital 32 that risks undermining the intended function of Qualified Website Authentication Certificates (QWACs). ESD calls for the legislation to preserve their core purpose — authenticating websites and reliably identifying the entities behind them — and proposes concrete drafting changes to ensure that this objective is reflected consistently in Recital 32 and Article 45. The intervention also seeks clear wording requiring browsers to provide a user-friendly display of certified identity information.

  • Google Returns to Anti-Competitive Behavior.

    ESD brings its concerns about Google's proposed 90-day certificate policy directly to the European Commission. In a meeting with the Cabinet of Executive Vice-President Margrethe Vestager, ESD highlights the potential consequences for QWACs, competition and user choice, and places the issue in the wider context of the ongoing eIDAS 2.0 negotiations. ESD stresses that technical requirements set unilaterally by dominant market actors should not be able to circumvent or undermine the European regulatory framework. The discussion therefore connects the immediate 90-day certificate issue with the broader objective of Article 45: ensuring that EU-regulated trust services are governed by European law and transparent standard-setting rather than proprietary rules alone.