You're talking about potential implementations. EFF is talking about issues in current implementation. As I said in my very first comment, I'm sure it can be done properly. The EFF is worried that if the current implementation is rolled out now, the system will stay unfixed for years and make privacy even worse.
But anyways, since you seem knowledgeable about the EUDI implementation and I'm too lazy to look it up, do you know if the current implementation allows a website to collude with the issuer to get the identity of a user?