17-7-2026

Verifiable credentials: a new foundation for data exchange

Danny Greefhorst

The way organizations exchange data has remained virtually the same for decades. An organization requests data from another organization, stores it in its own records, and subsequently uses it for its own processes. This results in copies, synchronization problems, and ongoing questions regarding the origin and currency of data. How does a recipient know that received data actually originates from an authorized source and has not been altered in transit? Data at the source is a key objective for good reason. In practice, however, copies remain unavoidable.

With eIDAS 2.0 and the European Digital Identity Wallet, an important new concept is being introduced: the verifiable credential.

A verifiable credential contains not only an assertion, such as:

  • this person is an authorized director;
  • this company is subject to VAT;
  • this diploma was obtained;
  • this organization holds a specific license;

but also cryptographic evidence showing:

  • who issued the statement;
  • when it was issued;
  • that the content has not changed since issuance;
  • that the statement is still valid.

As a result, a recipient no longer needs to rely solely on the system from which the data originates; the credential carries its own proof of authenticity.

This development is perhaps even more important than the introduction of the EDI wallet. In the current situation, organizations rely primarily on connections between systems. An API mainly tells where data comes from. A verifiable credential, on the other hand, explains why a particular assertion can be trusted. Trust thus shifts from trust in a server to the ability to verify the source of the data. That seems like a subtle difference, but it has far-reaching consequences.

Many data exchanges today consist of requesting data and then performing the same checks again. With verifiable credentials, many of these checks have already been performed by the party authorized to issue the declaration. The receiving organization mainly needs to check whether the declaration is valid and whether the issuer is indeed authorized. This shifts the emphasis from administrative checks to cryptographic verification.

When organizations possess verifiable declarations, a different way of handling data also emerges. Instead of copying large amounts of data, an organization can suffice with receiving precisely the statement required for a specific process. The focus is not on data ownership, but on the ability to demonstrate that a particular assertion is true.

In discussions regarding eIDAS, the emphasis is often on the EDI wallet. That is understandable, but the development of the European Business Wallet is at least as interesting. When organizations exchange mutually verifiable credentials, business processes can be largely automated without the need for a natural person to be involved every time. Organizations then do not simply exchange data, but signed and verifiable credentials whose origin and integrity can be checked immediately. This creates an infrastructure in which trust is no longer based solely on pre-arranged agreements between organizations, but also on objectively verifiable cryptographic evidence.

Verifiable credentials are therefore much more than a new security technique or a functionality of a digital wallet. They form a new building block for digital information provision, in which data is replaced by demonstrably reliable assertions. This shifts the focus from managing copies to managing trust. Perhaps that is the most important change that eIDAS 2.0 brings: not a new way to exchange data, but a new way to determine when data is truly reliable.

Interessant? Deel het!
Illustratie stel je vraag
Meer weten over deze blog?

Neem contact op met ons, we vertellen er graag meer over!

© ArchiXL  |  Chamber of Commerce  05084421