Digital Identity Framework: Framing the Triple Identity
See Digital Identity M2M and Digital Identity H2M
1. Introduction
The Triple Identity model is a key concept in the Digital Identity building block. As can be seen in the triangle in the figure bellow, this model consists of 3 elements. Each one of these elements is required in order to verify a digital identity.

BDI does not introduce a strict “triple identity model” as a universal rule. Instead, it describes three types of entities that appear in real-world interactions and clarifies how their relationships can be authenticated using established trust frameworks. The goal is to emulate real-world business practice in a digital ecosystem: legal entities transact, individuals and systems carry out the actions, and trust derives from verifiable relationships anchored in authoritative sources.
2. Purpose
BDI requires a reliable way to identify who or what is acting, on whose behalf, and in which context. The aim isn’t to create a new identity model, but to clearly describe the relationships that enable trustworthy digital interactions between organizations.
BDI adopts established international identity and trust frameworks (ISO/IEC 29115, ISO/IEC 18013, ISO/IEC 29146, eIDAS ARF) and expresses their relevant components in a form usable by non-specialists.
BDI interactions take place between legal entities. In practice, the actions underpinning these interactions are performed by natural persons and systems. Trustworthy digital exchange requires clarity about these relationship
3. Concepts
BDI identifies three entities that appear in most real-world interactions:
Legal Entity
Natural Person
Applications
4. Core Design Principles
As shown in the triangle above BDI recognizes three verifiable relationships.
4. Interlinkages with other building blocks
5. Future Work
For future work, the nuance in the relationship between a natural person and a legal entity will be considered. In some cases, the natural person acts as a representative of the legal entity. In other cases, the natural person is only granted access to its resources.
The European Business Wallet proposal (COM(2025) 838 final) already distinguishes between these situations. It defines technical mandates, where a natural person acts as an authorized representative of the legal entity and uses systems on its behalf. It also defines administrative mandates, where a user is assigned roles and responsibilities that enable access to the legal entity’s resources.
Last updated