Identity Verification with PID
Person Identification Data (PID) presented from an EUDI Wallet can be used as an identity input for banking processes such as digital onboarding, KYC/AML processes, user identity verification, and access management for existing users.
DIW Gateway supports requesting PID from a Wallet Unit, technically validating the resulting Verifiable Presentation and the presented PID, and mapping the validated data into a structure defined by the integrating organization.
The result of this process is technically validated identity data. Matching the presented identity to a customer record and making the resulting KYC, AML, authentication, or other business decision remain the responsibility of the integrating organization.
Requesting PID from a Wallet Unit
PID is obtained from a Wallet Unit through a Verifiable Presentation using OpenID4VP.
The integrating system initiates a verification transaction and specifies the data required for the particular use case. DIW Gateway prepares the corresponding Authorization Request and provides the information required to initiate communication with the Wallet Unit.
The Wallet Unit presents the requested PID data after confirmation by the user.
Core Scenario Steps
- Client system requests data from a Wallet Unit for a specific scenario.
- DIW Verifier prepares an authorization request for the scenario, includes transactional data, and signs the request using the access key.
- Communication with the Wallet Unit is initiated using the data returned by DIW Gateway.
- The user reviews and approves the requested presentation in the Wallet Unit.
- The Wallet Unit creates and returns the Verifiable Presentation.
- DIW Connector receives the response and passes the presented data to DIW Verifier.
- DIW Verifier performs the technical validation of the presentation and the contained attestations.
- DIW Verifier applies the configured mappings to the validated data.
- The validation result and mapped data are made available to the integrating system.
Local Integration
The local integration scenario supports in-person verification, for example at a branch using a tablet or another client device integrated with DIW Gateway.
The client application initiates a verification transaction and starts the Wallet Unit interaction using a supported local interaction mechanism, such as NFC, Bluetooth or a QR code.
The Wallet Unit presents the requested attestations, which are subsequently processed and verified by DIW Gateway.

Remote Integration
The remote integration scenario supports verification through digital channels, such as mobile banking or internet banking.
The client application initiates a verification transaction and starts the Wallet Unit interaction using a supported remote interaction mechanism, such as the Digital Credentials API (DC API), a deep link, or QR code.
The Wallet Unit presents the requested attestations, which are subsequently processed and verified by DIW Gateway.

PID Verification
After receiving the Verifiable Presentation, DIW Verifier performs the technical verification of the presentation and the presented PID.
The verification includes cryptographic validation and validation against the relevant EUDIW trust sources.
The technical validation result and the validated PID data are subsequently made available to the integrating system.
PID Mapping
DIW Gateway helps interpret and standardize Person Identification Data (PID) received from different countries and providers, enabling consistent use of identity data within business processes.
Information contained within PID can differ significantly across different user nationalities and PID providers.
The PID data model defines a common set of mandatory and optional attributes. According to the PID Rulebook, the mandatory PID attributes are:
family_name- current family name or surname,given_name- current given name, including middle names where applicable,birth_date- date of birth,birth_place- place of birth,nationality- one or more nationalities,portrait- facial image of the user, subject to the conditions defined by the PID Rulebook.
The PID also defines the following mandatory metadata:
issuing_authority- authority that issued the PID,issuing_country- country of the PID Provider.
Mandatory PID attributes define the information that forms part of the PID data model. A Relying Party is not required to request all mandatory PID attributes, and the user may refuse to present a requested mandatory attribute.
The exact requirements, including optional attributes and the specific conditions applicable to portrait, are defined by the official PID Rulebook.
DIW Gateway maps PID attributes into a data structure configured for the integrating organization. This allows PID data received from different PID Providers to be normalized into the structure expected by the organization’s onboarding and identity processes.
The mapping can also indicate requested information that was not provided by the Wallet Unit.
Profile Concept
PID alone may not provide sufficient information for a particular identity verification or onboarding use case.
DIW Gateway supports verification profiles that allow the integrating organization to request PID together with additional attestations and claims required for the corresponding use case.
A profile defines the credentials and claims requested from the Wallet Unit.
- For example, during customer onboarding, PID can provide the core identity data while additional attestations can be requested to obtain information required by the onboarding process, such as tax residency or tax identification number.
This allows the integrating organization to combine identity data from PID with additional information available through attestations in the EUDI Wallet within a single verification scenario.
For details about verification profiles and requesting multiple attestations, see Verifying Attestation from Wallet Unit.