Opinion No. 1/2018 of the Cooperation Network on the Italian eID scheme
Having regard to Article 12(5) and (6) of Regulation (EU) 910/2014 ("the eIDAS Regulation").
Having regard to Article 14(i) of Commission Implementing Decision (EU) 2015/296.
Having regard to Article 4 of the Rules of Procedure of the Cooperation Network.
Whereas:
Article 12 of the eIDAS Regulation obliges Member States to cooperate with regard to the interoperability and security of notified electronic identification schemes.
Article 14(i) of Commission Implementing Decision (EU) 2015/296 on cooperation mandates the Cooperation Network to adopt opinions on how an electronic identification scheme to be notified meets the requirements of the eIDAS Regulation.
The Italian Republic, with a view to notify its electronic identification scheme (SPID – Public System of Digital Identity, hereinafter referred to as "Italian eID scheme") in line with Article 7 (g) of the eIDAS Regulation provided the following information to the Member States on 29 November 2017 (hereinafter referred to as: "prenotifications"):
On 11 April 2018 the Cooperation Network
- agreed to peer review the Italian eID scheme according to Article 12(6) (c) of the eIDAS Regulation and Chapter III of Commission Implementing Decision (EU) 2015/296;
- formed a "Peer Review Group" and
- agreed which topics the peer review process would cover and how it would be organized according to the provisions of Chapter III of Commission Implementing Decision (EU) 2015/296.
The Peer Review Group submitted its report according to Article 11 of Commission Implementing Decision (EU) 2015/296 to the Cooperation Network on 10 July 2018.
The Cooperation Network has examined and discussed the Peer Review Report today, which highlighted the need to clearly differentiate which eID means correspond to which level of assurance.
Taking into account the intention of Italian Republic to remove the following elements identified in the peer review report:
- automatic reactivation after suspension and
- video identification and OTP via SMS concerning the eID means with assurance level high,
the Cooperation Network adopted the following opinion:
Opinion
Based on the examination of the pre-notification documents provided by the Italian Republic, the findings of the Peer Review Report, and the information provided at the Cooperation Network meeting today the Cooperation Network is of the opinion that the pre-notification documents and additional information provided by the Italian Republic demonstrate sufficiently how the Italian eID scheme to be notified meets the requirements of Article 7, Articles 8(1)-(2) for assurance level “high”, “substantial” and “low” respectively and 12(1) of the eIDAS Regulation and Commission Implementing Regulation (EU) 2015/1502.
According to Article 4(6) of the Rules of Procedure the Cooperation Network agrees to publish this opinion.
Brussels, 11 July 2018