TL;DR: European digital identity wallets depend on Apple and Google mobile security services for cryptographic operations and secure storage. UK regulators now seek to limit Apple and Google control over in-app payments as antitrust pressure intensifies across the EU.
The UK Competition and Markets Authority published findings on June 30, 2026, targeting Apple and Google over their control of in-app payment systems. Meanwhile, the European Commission continues pressing Google over data practices tied to Gemini and Android. European digital identity wallets sit at the intersection of both regulatory battles.
How Do European Digital ID Wallets Rely on Apple and Google?
European digital identity wallets run as mobile applications on iOS and Android, which together cover over 99% of the EU smartphone market. These wallets require secure hardware access for cryptographic signing, key storage, and biometric authentication. Only Apple’s Secure Enclave and Google’s StrongBox provide the certified hardware-backed security modules that eIDAS 2.0 compliance demands for qualified electronic signatures.
The dependency runs deep. Wallet developers cannot bypass these hardware security modules without losing certification. Apple controls access to the Secure Enclave through its proprietary APIs, while Google mandates StrongBox integration through the Android Ready SE framework. Both companies act as gatekeepers for any government-issued digital credential that needs hardware-level tamper resistance.
This creates a paradox. European governments want sovereign digital identity infrastructure, yet the cryptographic backbone lives inside silicon controlled by two American corporations. No European alternative exists at the hardware level. The wallets may carry EU flags, but they run on US security foundations.
Why Is the UK Regulator Targeting Apple and Google Over App Payments?
The UK Competition and Markets Authority announced on June 30, 2026, that Apple and Google wield disproportionate control over how consumers pay within mobile applications. The regulator’s provisional findings conclude that both companies restrict competing payment providers from accessing critical smartphone features, locking developers into proprietary billing systems.
Apple requires all digital purchases to use its In-App Purchase system, taking commissions up to 30%. Google mandates Google Play Billing for most apps distributed through the Play Store. The CMA argues these requirements stifle competition and inflate consumer prices. Developers have no alternative path to reach iOS or Android users at scale.
This matters for digital ID wallets because many EU member states plan to offer premium identity verification services through their wallet apps. If Apple and Google force government wallets to use their billing systems for paid features, public services would generate private revenue for two American companies. The CMA investigation could force both platforms to open payment APIs to third parties.
What Security Services Do Apple and Google Provide for Digital ID Wallets?
Apple and Google supply the hardware-backed cryptographic infrastructure that European digital ID wallets require for eIDAS 2.0 compliance. Apple’s Secure Enclave Processor handles biometric data isolation, key generation, and signature operations entirely within a dedicated coprocessor isolated from the main CPU. Google’s StrongBox, backed by the Titan M security chip on Pixel devices and equivalent hardware on other Android phones, provides similar certified execution environments.
Both platforms have achieved Common Criteria certification at EAL5+ for their secure elements. This certification level satisfies the technical requirements for qualified electronic signatures under EU regulation. Wallet applications call platform-specific APIs — CryptoKit on iOS and the Android Keystore on Google’s platform — to perform signing operations without ever exposing private keys to the application layer.
Additional security layers include:
- Secure biometric pipelines that process Face ID, Touch ID, and fingerprint authentication entirely within isolated hardware enclaves
- Attestation frameworks that let relying parties verify device integrity before accepting identity claims from a wallet
- Hardware isolation preventing malware on the main processor from extracting private keys even on compromised devices
- Certified execution environments meeting the tamper-resistance requirements specified under EU regulation 910/2014 for trust services
- Over-the-air security updates patching cryptographic vulnerabilities through Apple and Google distribution channels worldwide
- Lost-device recovery protocols that wipe wallet credentials when a phone is reported stolen or permanently deactivated
- Screen-lock enforcement requiring device authentication before any wallet can present a credential to a relying party
- Near-field communication routing through the secure element for contactless identity verification at border crossings
The table below summarizes how each platform maps to the security requirements of European digital ID wallets:
| Security Requirement | Apple Implementation | Google Implementation | eIDAS 2.0 Standard |
|---|---|---|---|
| Hardware key storage | Secure Enclave Processor | StrongBox / Titan M chip | EAL5+ or higher |
| Biometric authentication | Face ID / Touch ID pipeline | Android BiometricPrompt API | SCA-compliant |
| Device attestation | DeviceCheck and App Attest | Play Integrity API | RFC 8415 compliant |
| Signature generation | CryptoKit with Secure Enclave | Android Keystore at StrongBox | QSCD certified |
| NFC presentation | Secure Element via Core NFC | Host Card Emulation via SE | ISO 14443 compliant |
Are European Consumers Losing Trust in US Tech Giants?
Research indicates that European consumers increasingly distrust American technology companies with their personal data. A survey highlighted by iTardware.pl found that European customers are scrutinizing where their data flows and which US-based services process it. This erosion of trust directly affects adoption prospects for digital identity wallets built on Apple and Google security infrastructure.
The survey revealed that a significant percentage of European respondents would prefer domestic alternatives for sensitive services like digital identity. Concerns center on US government surveillance authorities under the CLOUD Act, which can compel American companies to surrender data stored on servers located in the EU. European courts have repeatedly ruled that this extraterritorial reach violates GDPR protections.
For digital ID wallets, this trust deficit creates a real adoption barrier. Citizens who already doubt Google’s data practices may resist storing their national identity credentials inside an Android secure element that Google’s software stack can access. Apple markets stronger privacy commitments, yet the CMA investigation frames Apple as a monopolist restricting consumer choice.
How Does the EU Commission Pressure Google Over Data Practices?
The European Commission escalated its scrutiny of Google’s data handling practices in June 2026, focusing on how the company processes user information collected through Gemini, Android, and its search engine. According to Spiders Web reporting, the Commission challenged Google’s argument that European firms would mishandle consumer data if regulatory barriers forced Google to localize its AI operations.
Google told European officials that local competitors lack the security infrastructure to protect sensitive user information at the same scale. The Commission rejected this framing. Regulators see Google’s position as a self-serving attempt to maintain data advantages rather than a genuine consumer protection argument. The dispute centers on whether Google can continue training Gemini on behavioral data collected through Android and Search without explicit user consent.
This regulatory pressure connects directly to digital identity wallets. If the Commission forces Google to restructure how Android handles user data, the security APIs that eID wallets depend on could face changes too. Regulators want stronger separation between Google’s commercial data operations and the platform’s security functions. That separation could redefine how European digital ID wallets interact with Android’s hardware security modules, potentially requiring new certification cycles and architectural changes to wallet implementations across every EU member state.
What Antitrust Allegations Has Apple Faced From European Regulators?
Apple has accused European regulators of operating on a “copy-paste” basis, claiming that officials responsible for antitrust proceedings simply replicated competitors’ allegations. According to Apple, regulators took investigation results “from the ceiling” rather than conducting independent analysis. These claims emerged as part of Apple’s defense strategy against ongoing antitrust pressure.
The company argues that officials copied claims directly from rival complaints. This undermines the credibility of the proceedings, Apple contends. The allegations span multiple jurisdictions and touch on various aspects of Apple’s App Store practices, payment systems, and platform control mechanisms that affect digital identity infrastructure.
European regulators have pursued several cases against Apple over App Store fees, NFC chip access restrictions, and the requirement that developers use Apple’s payment infrastructure. These cases directly impact how European digital ID wallets operate on iOS devices. The outcomes could reshape the relationship between platform owners and identity service providers across the European market.
Can Europe Build Digital Identity Without US Platform Dependencies?
Building digital identity infrastructure without US platform dependencies requires addressing the fundamental reality that European digital ID wallets run on operating systems controlled by Apple and Google. These platforms provide the security services, hardware-backed keystores, and biometric authentication mechanisms that make digital identity possible on mobile devices.
Europe lacks a widely adopted mobile operating system. This creates a structural dependency. The European Union has attempted to reduce reliance through initiatives like GAIA-X for cloud infrastructure and various open-source projects. None have produced a viable mobile platform alternative.
European consumers are increasingly concerned about where their data ends up. New research indicates that many customers are reconsidering whether to do business with companies that rely on US-based services. For some consumers, this concern has already translated into switching providers. This shift could cost US technology companies European clients as data sovereignty concerns grow.
The challenge extends beyond consumer sentiment. European digital ID wallets require integration with platform-level security APIs that only Apple and Google currently provide at the necessary scale and certification level.
What Are the Technical Risks of Relying on Two Mobile Platforms?
Relying on two mobile platforms for digital identity infrastructure concentrates risk in ways that affect millions of European citizens. Both Apple’s iOS and Google’s Android control the security enclaves, biometric sensors, and certification processes that digital ID wallets depend on for operation.
The technical risks include several specific areas of concern:
- Single points of failure: If either platform introduces a security vulnerability, it affects every wallet running on that operating system
- API changes: Platform owners can modify security APIs with minimal notice, potentially breaking wallet functionality
- Certificate revocation: Apple and Google can remotely disable applications through their app store mechanisms
- Geopolitical pressure: US government regulations could restrict platform features available to European users
- Data access ambiguity: Unclear boundaries exist around what platform owners can access from identity-related processes
- Update delays: Security patches depend on platform update cycles rather than wallet provider schedules
- Biometric data handling: While stored locally, the interfaces managing biometric authentication remain platform-controlled
- NFC access restrictions: Platforms can limit which applications access NFC hardware needed for identity verification
| Risk Category | Apple iOS Impact | Google Android Impact | Mitigation Difficulty |
|---|---|---|---|
| API Deprecation | High | Medium | Hard |
| Remote Disable | High | High | Very Hard |
| Security Delays | Medium | High | Medium |
| NFC Restrictions | High | Low | Hard |
| Certificate Issues | Medium | Medium | Medium |
How Do Alternative App Stores and Wallet Solutions Fit In?
Alternative app stores and wallet solutions represent a partial response to platform dependency, but they face significant limitations. The UK regulatory action targeting Apple and Google payment control illustrates how regulators are attempting to open these ecosystems to competition.
The UK regulator wants to limit the control that Apple and Google exercise over in-app payments. This move could allow third-party payment processors and alternative identity verification systems to operate more freely. However, alternative app stores still depend on the underlying operating system security services.
Even sideloaded applications require access to platform security APIs. Alternative distribution channels do not eliminate the dependency. The European Union’s Digital Markets Act has forced Apple to allow third-party app stores in the EU, but these stores operate within Apple’s framework and security requirements.
Google has argued against European data sovereignty rules by claiming that local companies would steal or misuse data. This argument suggests that European firms cannot be trusted with data management, a position that has drawn sharp criticism from European policymakers and privacy advocates.
What Comes Next for European Digital Sovereignty?
European digital sovereignty efforts face a paradox. The continent wants independence from US technology platforms while simultaneously relying on those platforms for critical security infrastructure. The tension between these goals will define European tech policy for years.
Several developments will shape the trajectory. Regulatory pressure on Apple and Google continues increasing through mechanisms like the Digital Markets Act, the Digital Services Act, and UK payment regulations. European consumers are voting with their attention, becoming more selective about which US services they use.
The research showing European consumer concern about data practices suggests market forces may complement regulatory action. Companies relying on US-based services risk losing European customers. However, replacing the technical infrastructure that Apple and Google provide requires sustained investment and political will that has yet to materialize at sufficient scale.
European digital ID wallets will likely continue depending on US platform security services for the foreseeable future. The question is whether that dependency comes with adequate safeguards.
Frequently Asked Questions
Can European digital ID wallets function without Apple and Google security services?
Currently, European digital ID wallets cannot function without accessing security services provided by Apple’s iOS and Google’s Android platforms. Both operating systems control the hardware-backed keystores, biometric authentication interfaces, and secure enclaves that digital identity verification requires. No European alternative mobile operating system exists at sufficient scale to replace these dependencies.
What specific UK regulatory action targets Apple and Google payment control?
The UK regulator is pursuing action to limit Apple and Google control over in-app payments, according to Euronews reporting from June 30, 2026. The regulatory initiative aims to open payment processing within applications to third-party competitors. This action directly challenges the commission structures and payment restrictions that both platforms maintain.
How are European consumers responding to US tech dependency concerns?
New research shows European consumers are increasingly scrutinizing where their data ends up, and for some customers this concern has already translated into switching providers. The study indicates that companies relying on US-based services risk losing European clients over data sovereignty worries. This consumer behavior shift could accelerate as awareness of platform dependencies grows.
What is Google’s argument against European data sovereignty rules?
Google has argued to European regulators that local European companies would steal or misuse data if given control through data sovereignty rules. This position essentially claims that European firms cannot be trusted with data management as much as Google itself. European policymakers and privacy advocates have sharply criticized this reasoning as self-serving and dismissive of European regulatory capacity.
Summary
- Structural dependency persists: European digital ID wallets rely on Apple and Google security services with no viable European mobile OS alternative available at scale
- Regulatory pressure is mounting: UK regulators are targeting Apple and Google payment control, while EU antitrust proceedings continue despite Apple’s accusations of regulator bias
- Consumer sentiment is shifting: Research shows European consumers increasingly concerned about US tech dependency, with some already switching providers
- Technical alternatives remain limited: Alternative app stores and sideloading do not eliminate platform-level security dependencies
- Sovereignty requires investment: Achieving genuine digital sovereignty would require sustained European investment in mobile platform development that has not yet materialized