This links 'a person' to 'a piece of health information'. Imagine what you or any data platform could do with that (big) data.
Imagine that you are only allowed to visit certain countries based on your vaccination status. Advertising agents of tourist and traveling agents would love to get their hands on that information, to create a better profile of you. Maybe Google could even make a FLoC of 'COVID-19 vaccinated people'.
Imagine that one year from now, one of the vaccines is known to cause health issue X, which would require over-the-counter medication Y. Advertising companies would love to know exactly what vaccines you have received, to add to their 'profile'. and would go to great lengths to get this information (create their own 'reader app' and supply this to events).
Here we hide personal health information in a QR code and are expected to give random strangers 'consent' to this personal data to gain 'access' to a venue or 'service'.
Sounds awfully lot like a cookie consent-popup, which the EU is so actively trying to prevent through legislation.
Do you really need to link 'a person' to 'a vaccine profile'? Isn't it enough to link 'a person' to 'can access this service/venue according to local laws?'.
In software development, you separate authentication and authorization. The authentication part is 'are you who you say you are', the authorization part is 'are you allowed to access this resource'. For authorization, you don't send the full list of all roles/permissions of this user for all authorized applications, you send a true/false based on the question canAccess(resource)? Otherwise a 'hacker' might find he has no permissions using the current authenticated account to resource A, but conveniently has full permissions to resource B.
You wouldn't give a random webshop access to your Bank Balance and history, would you? Your bank should only tell them 'transfer of X dollar is approved'.