Do the verification apps do an online validation? If yes then where is there any PII in there at all, and if no then why isn’t it signed?…
It is indeed signed, according to the blog post and to the spec linked in the blog post https://github.com/ehn-dcc-development/hcert-spec/blob/main/...
How are the codes generated to begin with? Is there some central database that hands them out, or can any clinic generate one (having access to a copy of the private key?)
Infrastructure for code generation and signing is probably country-specific, though I imagine most countries will establish centralized systems dealing with this and integrate with other systems that track vaccination or test records on various levels (some countries delegate vaccination efforts to their states, others handle it nationally, etc.)