EU-Regulatorik · DSGVO · Data Governance · DatensouveränitätEU regulation · GDPR · data governance · data sovereignty

Vivodepot im europäischen Regulierungsrahmen

Vivodepot within the European regulatory framework

Bürgerdatensouveränität ist in Europa regulatorisch breit verankert — über Datenschutz-Grundlagen, sektor-übergreifende Daten-Regulierungen, sektor-spezifische Verordnungen und Identitäts- und Beschaffungs-Rahmen. Vivodepot ist auf diesen Rahmen hin gebaut: sektor-agnostisch, mit konkreten Anbindungen an offene Standards, ohne zentrale Datenhaltung. Diese Seite zeigt die Verbindungen und ordnet sie zu einer strukturellen Souveränitäts-Frage ein, die mit der aktuellen geopolitischen Lage zunehmend sichtbar wird.

Citizen data sovereignty is broadly anchored in European regulation — across data protection foundations, cross-sector data regulations, sector-specific frameworks and identity and procurement rules. Vivodepot is built for this frame: sector-agnostic, with concrete connections to open standards, without central data holdings. This page sets out the connections and places them alongside a structural sovereignty question that is becoming increasingly visible in the current geopolitical situation.

Regulatorischer RahmenRegulatory framework

Sechs Bausteine im Überblick

Six building blocks at a glance

Sechs Bausteine plus eine strukturelle Rahmenbedingung. Die sechs Bausteine sind Rechtsakte aus vier Regulierungs-Ebenen — datenschutzrechtliche Grundlagen, sektor-übergreifende und sektor-spezifische Verordnungen, Identitäts- und Beschaffungs-Rahmen. Die strukturelle Rahmenbedingung ist die einzige, die kein einzelnes Gesetz ist: extraterritoriale Zugriffsrechte.

Six building blocks plus one structural condition. The six building blocks are legal acts from four regulatory layers — data protection foundations, cross-sector and sector-specific regulations, identity and procurement frameworks. The structural condition is the only one that is not a single piece of legislation: extraterritorial access rights.

Grundlage · In KraftFoundation · In force

DSGVO — Datenschutz-Grundverordnung

Verordnung (EU) 2016/679 · Anwendbar seit Mai 2018Regulation (EU) 2016/679 · Applicable since May 2018

Die Datenschutz-Grundverordnung ist die Rechtsgrundlage für Bürgerdatensouveränität in Europa. Sie verankert das Recht der Person auf ihre Daten — auf Auskunft (Art. 15), auf Datenübertragbarkeit in maschinenlesbarer Form (Art. 20) und auf Schutz vor Übermittlung an Drittstaaten-Behörden ohne EU-Rechtsgrundlage (Art. 48). Auf dieser Grundlage bauen alle sektor-spezifischen Regulierungen auf.

The General Data Protection Regulation is the legal basis for citizen data sovereignty in Europe. It anchors the person's rights over their data — to access (Art. 15), to portability in machine-readable form (Art. 20) and to protection against transfer to third-country authorities without an EU legal basis (Art. 48). All sector-specific regulations build on this foundation.

Vivodepot setzt das Recht auf Datenübertragbarkeit operativ um: strukturierte Daten in offenen Formaten, die der Bürger selbst hält und gezielt weitergibt. Kein Vivodepot-Server, an den eine Drittstaaten-Anordnung gerichtet werden könnte — Art. 48 wird strukturell adressiert, nicht nur dokumentarisch erfüllt.Vivodepot implements the right to data portability operationally: structured data in open formats, held by the citizen and shared on their own terms. No Vivodepot server exists that could be subject to a third-country order — Art. 48 is addressed structurally, not only met on paper.
In KraftIn force

EHDS — European Health Data Space

Verordnung (EU) 2025/327 · In Kraft seit März 2025Regulation (EU) 2025/327 · In force since March 2025

Der EHDS verpflichtet Mitgliedstaaten, Bürgerinnen und Bürgern ihre Gesundheitsdaten in maschinenlesbarer Form bereitzustellen. Krankenhäuser, Praxen und Apotheken müssen den elektronischen Zugang ermöglichen. Der xShare Yellow Button ist das technische Exportinstrument für die primäre Gesundheitsdatennutzung.

The EHDS obliges Member States to make health data available to citizens in machine-readable form. Hospitals, practices and pharmacies must enable electronic access. The xShare Yellow Button is the technical export instrument for primary use of health data.

FHIR-R4/IPS-konformer Import bereits implementiert. Empfänger-Rolle für den xShare Yellow Button vorgesehen — Expression of Interest für den xShare Open Call 2026 eingereicht.FHIR-R4/IPS-compliant import already implemented. Receiver role for the xShare Yellow Button planned — Expression of Interest submitted for the xShare Open Call 2026.
Strukturelle RahmenbedingungStructural condition

Datensouveränität und Drittstaaten-Zugriff

Data sovereignty and third-country access

US Cloud Act (2018) · DSGVO Art. 48US Cloud Act (2018) · GDPR Art. 48

Europäisches Branding auf nicht-europäischer Kontrollschicht — in der EU-Debatte „Sovereignty Washing" genannt — ändert nichts daran, dass der US Cloud Act US-Unternehmen zur Datenherausgabe verpflichtet, unabhängig vom Speicherort. Ein europäischer Vertragspartner allein ist noch keine Souveränität. Sie entsteht erst, wenn kein Anbieter ungefragt auf die Daten zugreifen kann, auch Vivodepot nicht. Deshalb gibt es keinen Vivodepot-Server: Die Datei liegt beim Bürger, der Schlüssel auch.

European branding on a non-European control layer — called "sovereignty washing" in the EU debate — does not change the fact that the US Cloud Act obliges US companies to release data regardless of storage location. A European contractual partner alone is not yet sovereignty. It only arises when no provider can access the data without being asked, including Vivodepot. That is why there is no Vivodepot server: the file stays with the citizen, and so does the key.

Vivodepot GmbH ist deutsches Unternehmen mit Sitz in Berlin, vollständig europäisch gehalten und betrieben. Der App-Code ist quelloffen unter EUPL-1.2, der Template-Mechanismus zeitversetzt (BUSL-1.1 → EUPL-1.2); die Implementierung ist unabhängig prüfbar.Vivodepot GmbH is a German company headquartered in Berlin, fully European in ownership and operation. The app code is open source under EUPL-1.2, the template mechanism on a delay (BUSL-1.1 → EUPL-1.2); the implementation is independently auditable.
Kommissionsvorschlag · 27. Mai 2026Commission proposal · 27 May 2026

Cloud and AI Development Act (CADA)

Cloud and AI Development Act (CADA)

Tech Sovereignty Package · Rechtsgrundlage Art. 114 TFEU · Gesetzgebungsverfahren läuftTech Sovereignty Package · Legal basis Art. 114 TFEU · Legislative process underway

Der Cloud and AI Development Act ist das Kernelement des Tech Sovereignty Package der Europäischen Kommission. Er soll bis 2030 die EU-Rechenzentrumskapazität verdreifachen, öffentliche Beschaffung als Steuerungsinstrument nutzen und eine verbindliche Definition von „Sovereign Cloud Provider" einführen — auf zwei Ebenen: rechtliche Kontrolle (europäischer Sitz und Eigentümerschaft, Immunität gegenüber extraterritorialen Gesetzen) und operative Kontrolle (Infrastruktur und Wertschöpfung in Europa). Ein zentrales Ziel ist die Bekämpfung von „Sovereignty Washing" — oberflächlicher Compliance, die strukturelle Abhängigkeiten verdeckt.

The Cloud and AI Development Act is the central element of the European Commission's Tech Sovereignty Package. It aims to triple EU data centre capacity by 2030, use public procurement as a policy instrument, and introduce a binding definition of "sovereign cloud provider" — on two levels: legal control (European headquarters and ownership, immunity to extraterritorial laws) and operational control (infrastructure and value creation in Europe). A central objective is combating "sovereignty washing" — superficial compliance that conceals structural dependencies.

Vivodepot ist kein Cloud-Provider und fällt nicht in den Anwendungsbereich des CADA. Aber das Souveränitätsprinzip, das der CADA rechtlich zu verankern versucht, setzt Vivodepot auf einer anderen Ebene um: nicht durch die Wahl des richtigen Providers, sondern durch eine Architektur, die keine Cloud-Infrastruktur braucht und bei der kein Anbieter zwischen dem Bürger und seinen Daten steht.Vivodepot is not a cloud provider and does not fall within the scope of the CADA. But the sovereignty principle the CADA seeks to enshrine in law is what Vivodepot implements at a different level: not by choosing the right provider, but through an architecture that requires no cloud infrastructure and in which no provider stands between the citizen and their data.
Ab 2026/2027From 2026/2027

EU Digital Identity Wallet (EUDIW)

Verordnung (EU) 2024/1183 — eIDAS 2.0 · Verpflichtend ab Ende 2026Regulation (EU) 2024/1183 — eIDAS 2.0 · Mandatory from end of 2026

Jeder EU-Mitgliedstaat muss ab Ende 2026 eine staatlich ausgestellte, bürger-kontrollierte digitale Brieftasche anbieten. Sie enthält verifizierten Identitätsnachweis (PID), Führerschein, Diplome und weitere Attribute — kryptographisch gesichert, ohne zentralen Datenspeicher.

From the end of 2026, every EU Member State must offer a state-issued, citizen-controlled digital wallet. It holds verified identity (PID), driving licence, diplomas and other attributes — cryptographically secured, without a central data store.

Mit der finalen Fassung der Payment Services Regulation (April 2026) ist die EBA damit beauftragt, die technischen Standards für die EUDIW-Nutzung bei Zahlungsauthentifizierung zu entwickeln. Ab Dezember 2027 müssen Banken die EUDIW für Customer Due Diligence und Strong Customer Authentication unterstützen. Damit wird die EUDIW neben ihrer Funktion als Identitätsnachweis auch zur Authentifizierungs-Infrastruktur im Banking- und Zahlungsverkehr.

With the final text of the Payment Services Regulation (April 2026), the EBA is mandated to develop the technical standards for EUDIW use in payment authentication. From December 2027, banks must support EUDIW for customer due diligence and strong customer authentication. Alongside its function as an identity credential, the EUDIW thereby also becomes an authentication infrastructure for banking and payments.

Vivodepot exportiert im SD-JWT-VC-Format. Eine Verankerung im EUDIW findet nicht statt: Das PID verlässt die Wallet nicht als Datei, sondern wird per OpenID4VP über das Netz vorgezeigt. Eine offline-Anwendung ist in diesem Modell nicht vorgesehen. Die beiden Werkzeuge ergänzen sich funktional: Die EUDIW hält formale Nachweise und Authentifizierungs-Tokens, Vivodepot hält strukturierte Lebensdaten wie Vorsorge-Dokumente, Pflege-Stammdaten oder biografische Übersichten.Vivodepot exports in SD-JWT-VC format. There is no anchoring in the EUDIW: the PID does not leave the wallet as a file but is presented over the network via OpenID4VP. An offline application is not envisaged in this model. The two tools complement each other functionally: the EUDIW carries formal credentials and authentication tokens, Vivodepot carries structured life data such as advance care documents, nursing records or biographical overviews.
Deutschland · In Kraft ab 1. Juli 2026Germany · In force from 1 July 2026

Vergabebeschleunigungsgesetz

German Public Procurement Acceleration Act

Bundestag 23. April 2026 · Bundesrat 8. Mai 2026 · In Kraft ab 1. Juli 2026Bundestag 23 April 2026 · Bundesrat 8 May 2026 · In force from 1 July 2026

Digitale Souveränität wird als qualitatives Zuschlagskriterium bei öffentlichen IT-Beschaffungen verankert — offene Standards, Datenkontrolle, Datenlokalisierung. Damit können öffentliche Auftraggeber erstmals aktiv auf souveräne, quelloffene Lösungen vergeben, ohne den günstigsten Preis automatisch zu wählen.

Digital sovereignty becomes a qualitative award criterion in public IT procurement — open standards, data control, data localisation. Public contracting authorities can, for the first time, actively award contracts to sovereign, open-source solutions, without being forced to choose the lowest price.

Vivodepot ist auf diese drei Kriterien hin angelegt: offene Standards (FHIR, SD-JWT), Datenkontrolle (AES-256-GCM, keine Cloud) und Datenlokalisierung (kein Server). Vivodepot verdient nur am Werkzeug — über Hardware, Whitelabel-Lizenzen, Servicevertrag, Vorlagen-Integration und Trust-Authority-Zertifikate. Versicherungs-Provisionen oder Finanzprodukt-Vermittlung gehören nicht zum Geschäftsmodell. Für öffentliche Beschaffungsstellen bedeutet das: ein Anbieter ohne nachgelagerte Interessen am Verhalten der Endnutzer.Vivodepot is designed around these three criteria: open standards (FHIR, SD-JWT), data control (AES-256-GCM, no cloud) and data localisation (no server). Vivodepot earns only from the tool — through hardware, white-label licences, service agreements, template integration and trust authority certificates. Insurance commissions or financial product brokerage are not part of the business model. For public procurement bodies, this means: a provider with no downstream interests in the behaviour of end users.
In KraftIn force

Data Governance Act und Data Act

Data Governance Act and Data Act

Verordnung (EU) 2022/868 · Anwendbar seit September 2023 · Verordnung (EU) 2023/2854 · Anwendbar seit September 2025Regulation (EU) 2022/868 · Applicable since September 2023 · Regulation (EU) 2023/2854 · Applicable since September 2025

Beide Verordnungen regeln sektor-übergreifend, wie Daten zwischen Akteuren bewegt werden. Der Data Governance Act schafft den Rahmen für Datenintermediäre und vertrauenswürdige Daten-Teilung. Der Data Act räumt Bürgerinnen und Bürgern wie Unternehmen Zugriff auf die Daten ein, die durch ihre Nutzung vernetzter Produkte und Dienste entstehen — und das Recht, sie weiterzugeben.

Both regulations govern, across sectors, how data flows between actors. The Data Governance Act establishes the framework for data intermediaries and trusted data sharing. The Data Act grants citizens and businesses access to the data generated through their use of connected products and services — and the right to share that data.

Vivodepot setzt diesen Ansatz auf der Bürger-Seite um: ein bürgerseitiges Werkzeug, kein Datenvermittlungsdienst im Sinne des DGA — kein Server, keine zentrale Speicherung, kein Vermittlungs-Interesse. Strukturierte Daten in offenen Formaten, kontrolliert durch die Person, weitergegeben durch sie. Ein Werkzeug, mit dem sich die Portabilitätsrechte aus DSGVO und Data Act im Alltag ausüben lassen.Vivodepot applies this approach on the citizen side: a citizen-held tool, not a data intermediation service within the meaning of the DGA — no server, no central storage, no brokerage interest. Structured data in open formats, controlled by the person, shared by them. A tool for exercising the portability rights under the GDPR and the Data Act in everyday life.

Internationale Einordnung. Der Global Digital Compact der UN (verabschiedet September 2024) verankert Digital Public Infrastructure und Datensouveränität als internationale Ziele. Vivodepot ist bei der Digital Public Goods Alliance zur Aufnahme als Digital Public Good eingereicht (GID0093612) und der Quellcode bei OpenCode (ZenDiS) zur Aufnahme hochgeladen — die Prüf- und Aufnahme-Verfahren laufen.

International context. The UN Global Digital Compact (adopted September 2024) establishes Digital Public Infrastructure and data sovereignty as international goals. Vivodepot has been submitted to the Digital Public Goods Alliance for recognition as a Digital Public Good (GID0093612) and the source code uploaded to OpenCode (ZenDiS) for inclusion — review and inclusion processes are underway.

Marius Badstuber
Nationale EinordnungNational positioning

Vivodepot und die Deutschland-App

Vivodepot and the Deutschland-App

Das Bundesministerium für Digitales und Staatsmodernisierung entwickelt unter Karsten Wildberger eine bundesweite Bürger-App, mit der Bürgerinnen und Bürger Behördenleistungen digital erledigen können. Da beides konzeptuell und zeitlich Berührungspunkte hat, klärt dieser Abschnitt die Komplementarität.

The German Federal Ministry for Digital and State Modernisation is developing a nationwide citizen app under Karsten Wildberger that lets citizens handle administrative procedures digitally. Since this overlaps with Vivodepot in concept and timing, this section sets out the complementarity.

Der Kanal und der Inhalt

The channel and the content

Die Deutschland-App ist eine zentrale Cloud-Anwendung mit zentralem Konto. Sie ist der Bürger-zu-Behörde-Kanal: Anträge stellen, Termine buchen, Bescheide empfangen. Die EUDI-Wallet dient als Authentifizierungs-Schicht. Erster Prototyp läuft in fünf Pilotkommunen seit April 2026, breite Funktionalität bis 2027 geplant.

The Deutschland-App is a central cloud application with a central account. It is the citizen-to-administration channel: submit applications, book appointments, receive notices. The EUDI Wallet serves as the authentication layer. A first prototype has been running in five pilot municipalities since April 2026, with broader functionality planned by 2027.

Vivodepot ist keine Bürger-App im Sinne der Deutschland-App. Vivodepot ist der Bürger-eigene Daten-Container: kein Konto, kein Server, keine Cloud, sondern eine Einzeldatei-HTML auf einem Stick. Sie hält die persönlichen Inhalte vor — Vorsorgevollmacht, Befunde, Patientenverfügung, Vermögensübersicht, Kontakte —, die in Behörden-Anträge eingehen.

Vivodepot is not a citizen app in the sense of the Deutschland-App. Vivodepot is the citizen-owned data container: no account, no server, no cloud, but a single-file HTML on a USB stick. It holds the personal records — power of attorney, medical findings, advance directive, asset overview, contacts — that feed into administrative applications.

Komplementäre Architekturen

Complementary architectures

Beide Architekturen lösen unterschiedliche Probleme. Die Deutschland-App löst das Transaktions-Problem: Wie kommt ein Antrag effizient von der Bürgerin zur Behörde. Vivodepot löst das Souveränitäts-Problem: Wo liegen die persönlichen Daten, wenn gerade kein Antrag gestellt wird. Konkret hält Vivodepot die Daten strukturiert vor, die in solche Anträge eingehen — als FHIR-IPS-konforme Bundles und als eigener, dokumentierter Datensatz mit an FIM angelehnter Feldbenennung —, und gibt sie maschinenlesbar heraus. Die Deutschland-App ist die Plattform, Vivodepot ist das persönliche Werkzeug — beide gemeinsam ergeben bürgerseitige Daten-Souveränität vollständig.

Each architecture solves a different problem. The Deutschland-App solves the transaction problem: how to move applications efficiently from citizen to administration. Vivodepot solves the sovereignty problem: where the personal records live when no application is pending. Concretely, Vivodepot holds the data structured that flows into such applications — as FHIR/IPS-compliant bundles and as its own, documented record with field naming aligned to FIM — and makes it available in machine-readable form. The Deutschland-App is the platform, Vivodepot is the personal tool — together, they make citizen data sovereignty tangible.

xShare · Datenmobilität für BürgerxShare · Data mobility for citizens

Der xShare Yellow Button

The xShare Yellow Button

Der xShare Yellow Button ist das technische Exportinstrument des EHDS für die primäre Datennutzung durch Bürgerinnen und Bürger. Er beginnt mit Gesundheitsdaten — ist aber konzeptionell der Ausgangspunkt für eine breitere Datenmobilität: Was heute für Krankenhäuser gilt, wird schrittweise auf weitere institutionelle Datenquellen ausgeweitet. Vivodepot ist als Empfänger für diesen Kanal vorgesehen.

The xShare Yellow Button is the technical export instrument of the EHDS for primary data use by citizens. It begins with health data, but is conceptually the starting point for broader data mobility: what applies to hospitals today will gradually extend to further institutional data sources. Vivodepot is designed as a receiver for this channel.

1

Authentifizierung beim Leistungserbringer

Authentication with the provider

Die Person authentifiziert sich beim Krankenhaus, der Praxis oder der Apotheke — per EUDIW, eID oder bestehendem Zugang.

The person authenticates with the hospital, practice or pharmacy — via EUDIW, eID or an existing login.

2

Yellow Button — Export auslösen

Yellow Button — trigger the export

Mit einem Klick auf den Yellow Button löst die Person den Datenexport aus. Der Leistungserbringer stellt das FHIR-Bundle bereit.

With one click on the Yellow Button, the person triggers the data export. The provider supplies the FHIR bundle.

3

Import in Vivodepot

Import into Vivodepot

Das FHIR-R4/IPS-konforme Bundle wird in Vivodepot importiert. Vivodepot validiert die Struktur, zeigt die Daten zur Bestätigung an und speichert sie verschlüsselt lokal.

The FHIR-R4/IPS-compliant bundle is imported into Vivodepot. Vivodepot validates the structure, displays the data for confirmation and stores it encrypted on the local device.

4

Portabilität in alle Richtungen

Portability in all directions

Die importierten Gesundheitsdaten können — zusammen mit allen anderen Depot-Daten — strukturiert an andere Institutionen übergeben werden. Die Person entscheidet, was sie teilt.

The imported health data can — together with all other depot data — be handed over to other institutions in a structured way. The person decides what to share.

Vivodepot und xShare

Vivodepot and xShare

Vivodepot hat im Mai 2026 eine Expression of Interest für den xShare Open Call 2026 eingereicht — als Empfänger des Yellow Button auf Bürgerseite.

In May 2026, Vivodepot submitted an Expression of Interest for the xShare Open Call 2026 — as the receiver of the Yellow Button on the citizen side.

Die FHIR-R4/IPS-Grundlage für den Empfänger-Container ist bereits implementiert. Über die Aufnahme entscheidet das xShare-Konsortium. Bei Aufnahme bauen wir die xShare-spezifische Integration, sobald die Spezifikation steht.

The FHIR-R4/IPS foundation for the receiver container is already implemented. Acceptance is decided by the xShare consortium. If accepted, we will build the xShare-specific integration once the specification is in place.

Mehr zur xShare-Initiative: More about the xShare initiative: xshare-project.eu

Vitaly Gariev
Offene StandardsOpen standards

Wo Standards offen sind, kann jeder integrieren

Where standards are open, anyone can integrate

Ohne Anfrage, ohne Lizenzgebühr, ohne Wartezeit. Offene Standards sind keine Eigenschaft eines Anbieters, sondern eine Eigenschaft des Codes.

No request, no licence fee, no wait. Open standards are not a property of a vendor — they are a property of the code.

Für Entwickler und IntegratorenFor developers and integrators

Technische Schnittstellen

Technical interfaces

Vivodepot stellt keine API bereit. Die Schnittstellen sind die Daten selbst: in offenen, standardisierten Formaten, die kompatible Systeme direkt lesen können. Die Person bringt das Format mit, nicht Vivodepot.

Vivodepot exposes no API. The interface is the data itself — in open, standardised formats that compatible systems can read directly. The person brings the format with them, not Vivodepot.

Insgesamt bildet Vivodepot zahlreiche offene Standards aus vier Domänen ab: medizinische Codierungen (SNOMED-CT, ICD-10-GM, ATC, LOINC), Identitäts- und Signaturformate (EUDIW, SD-JWT, JWS, W3C Verifiable Credentials), Verwaltungs- und Bürger-Formate (FHIR R4/IPS, vCard 4.0 — dazu ein eigener Behördendatensatz mit an FIM angelehnter Feldbenennung) sowie Kryptographie (AES-256-GCM, PBKDF2, HKDF). Vollständige Liste mit Versionen, Quellen und Implementations-Stand: STANDARDS.md.

Across four domains, Vivodepot implements numerous open standards: medical coding systems (SNOMED-CT, ICD-10-GM, ATC, LOINC), identity and signature formats (EUDIW, SD-JWT, JWS, W3C Verifiable Credentials), administrative and citizen-facing formats (FHIR R4/IPS, vCard 4.0 — plus Vivodepot's own public-authority record with field naming aligned to FIM), and cryptography (AES-256-GCM, PBKDF2, HKDF). Full list with versions, sources and implementation status: STANDARDS.md.

Trust Authority auf offenen Standards. Vivodepot ist nicht nur Empfänger offener Standards, sondern selbst ein offener Standards-Implementierer in einer Rolle, in der sonst proprietäre Lösungen dominieren. Die Trust-Authority-Funktion — Provider-Zertifikate und Template-Signaturen für die institutionelle Bürger-Daten-Übergabe — baut auf W3C Verifiable Credentials, JWS RFC 7515, Ed25519 plus ES256 auf. Die Spezifikation ist offen, der Mechanismus konvertiert nach vier Jahren vollständig zu EUPL-1.2. Damit wird eine Vertrauensschicht, die in vergleichbaren Architekturen meist einem einzelnen Konzern gehört, als europäisches Open-Source-Gemeinschaftsgut realisiert.

Trust authority on open standards. Vivodepot is not only a recipient of open standards but itself an open-standards implementer in a role normally dominated by proprietary solutions. The trust authority function — provider certificates and template signatures for institutional citizen data handover — is built on W3C Verifiable Credentials, JWS RFC 7515, Ed25519 plus ES256. The specification is open, and the mechanism converts fully to EUPL-1.2 after four years. A trust layer that, in comparable architectures, usually belongs to a single corporation is here built as a European open-source common good.

Aufbauend auf amtlichen Werken. Die vier in jeder Vivodepot-Anwendung vorinstallierten Standard-Vorlagen übernehmen den Wortlaut amtlicher Muster — Bundesministerium der Justiz für Patientenverfügung, Vorsorgevollmacht und Betreuungsverfügung, Bundeszentrale für gesundheitliche Aufklärung für den Organspendeausweis. Die Quelle ist jeweils genannt.

Building on official works. The four official standard templates pre-installed in every Vivodepot application are based on public-domain official works under §5 of the German Copyright Act — the Federal Ministry of Justice for advance directive, power of attorney and care directive, the Federal Centre for Health Education for the organ donation card. Vivodepot builds on public-law material, not on private custom constructions.

FHIR R4 · IPS

Gesundheitsdaten

Health data

HL7 FHIR Release 4, International Patient Summary. Import aus EHDS-Quellen (xShare Yellow Button), Export in IPS-konformes Bundle. Validierung gegen HL7-Validator als CI-Schritt.

HL7 FHIR Release 4, International Patient Summary. Import from EHDS sources (xShare Yellow Button), export to IPS-compliant bundle. Validation against the HL7 validator as a CI step.

SD-JWT · W3C VC

Identität und Credentials

Identity and credentials

Selective Disclosure JWT als Export-Format nach dem Stand der eIDAS-2.0-Implementierungsakte — kein PID-Import. W3C Verifiable Credentials für Provider-Zertifikate und signierte Template-Übergaben.

Selective Disclosure JWT as export format, following the current state of the eIDAS-2.0 implementing acts — no PID import. W3C Verifiable Credentials for provider certificates and signed template handovers.

JWS RFC 7515 · Ed25519

Signaturen und Vollmachten

Signatures and powers of attorney

JSON Web Signatures für Template-Übergaben: Ed25519 primär, ES256 als Fallback. Vivodepot als Trust Authority. 18 Monate Gültigkeit, optionale Revozierungsliste (CRL).

JSON Web Signatures for template handovers: Ed25519 as primary, ES256 as fallback. Vivodepot as trust authority. 18 months validity, optional revocation list (CRL).

CAMT · ISO 20022

Finanzdaten

Financial data

Import von Kontoauszügen im CAMT.053-Format. Konto-IBAN, strukturiert in den Finanzbereich des Depots.

Import of bank statements in CAMT.053 format. Account IBAN, structured into the financial section of the depot.

XMeld · OSCI

Meldedaten

Registration data

Import aus Einwohnermeldeamt-Schnittstellen im XMeld-Format. Adressdaten, Familienstand, amtliche Ausweisdaten.

Import from civil registration office interfaces in XMeld format. Address data, marital status, official identification data.

EDCI · Eigenformat

Bildung und Steuern

Education and taxes

EDCI/Europass für Bildungsnachweise und Qualifikationen. Ein eigenes, dokumentiertes Format zum Einlesen von Steuerdaten und Bescheiden.

EDCI/Europass for educational records and qualifications. An own, documented format for importing tax data and assessments.

Der Quellcode liegt öffentlich auf GitHub, gespiegelt auf OpenCode — heute als Beta 16, mit dem v1.0-Release im Freigabestand. Die Implementierungsdetails der Import-Export-Kanäle sind dort nachlesbar: gitlab.opencode.de/oc000142426528/vivodepot

The source code is public on GitHub, mirrored on OpenCode — currently as Beta 16, with the release version following at v1.0. The implementation details of the import-export channels can be read there: gitlab.opencode.de/oc000142426528/vivodepot

KontaktContact

Für Regulatoren, Standardisierungsgremien und Entwickler

For regulators, standardisation bodies and developers

Fragen zur technischen Integration, zur regulatorischen Einbettung, zu Kooperationsmöglichkeiten — wir beantworten sie persönlich.

Questions on technical integration, on regulatory embedding, on cooperation — we answer them personally.

ImpressumLegal notice

AnbieterProviderVivodepot GmbH
Körnerstraße 7-10
10785 Berlin
Germany

Vertretung und VerantwortlichkeitRepresentation and responsibilityVertretungsberechtigte Geschäftsführerin und verantwortlich nach §18 Abs. 2 MStV: Carola Klessen, Anschrift wie oben.Managing director and responsible for content under §18 para. 2 MStV: Carola Klessen, address as above.

KontaktContacteu@vivodepot.de
Tel.: +49 30 200 092 24

RegistereintragRegistrationAmtsgericht Charlottenburg (Berlin)
HRB 289273 B
EUID: DEF1103R.HRB289273B
Charlottenburg Local Court (Berlin)
HRB 289273 B
EUID: DEF1103R.HRB289273B

Umsatzsteuer-IdentifikationsnummerVAT identification numberUSt-IdNr. gemäß §27a UStG: DE463929000VAT ID under §27a German VAT Act: DE463929000

LizenzenLicencesAnwendung: EUPL-1.2. Template-Übergabe-Mechanismus: BUSL-1.1 mit Konversion zu EUPL-1.2 nach vier Jahren. Details: LICENSING.md.Application: EUPL-1.2. Template handover mechanism: BUSL-1.1 with conversion to EUPL-1.2 after four years. Details: LICENSING.md.