Overview
The General Data Protection Regulation (GDPR) governs how personal data of EU/EEA residents is collected, processed, and stored. Identity verification inherently involves processing sensitive personal data — documents, biometric data, and personal identifiers. iDenfy acts as a data processor on your behalf (Art. 4(8), Art. 28 GDPR). You remain the data controller, responsible for establishing the lawful basis, ensuring transparency, and fulfilling data subject rights. iDenfy does not determine the purposes or legal bases for processing — you define these exclusively as the controller.Your Responsibilities as Data Controller
How iDenfy Supports GDPR Compliance
Data Minimization
Configure session creation to collect only the data you need:Right to Erasure (Art. 17)
Delete verification data via API when a data subject requests erasure:Data Retention
Configure automatic data retention periods in your iDenfy dashboard. iDenfy supports:- Custom retention periods per service type
- Automatic deletion after the configured period expires
- Manual deletion via API at any time
- Default retention: Up to 10 years for AML-related identification records; 60 days for expired/closed customer accounts
Data Processing Agreement
iDenfy provides a GDPR-compliant Data Processing Agreement (DPA) that covers:- Processing purpose and scope
- Sub-processor list and obligations (all sub-processors are documented and contractually bound)
- Data breach notification procedures (within 72 hours to the supervisory authority)
- Data transfer mechanisms (EU Standard Contractual Clauses where applicable)
- Technical and organizational security measures (ISO 27001, SOC 2 Type II)
Biometric Data (Art. 9)
Identity verification with liveness detection processes biometric data, which is a special category under GDPR. Your legal basis depends on your use case: For AML-regulated entities (banks, fintechs, crypto, gaming):- Art. 6(1)(c) — compliance with a legal obligation (AML law)
- Art. 9(2)(g) — substantial public interest based on Union or Member State law
- Consent is not the appropriate legal basis — per EDPB Guidelines 05/2020, consent should not replace statutory grounds
- Art. 6(1)(a) — consent of the data subject
- Art. 9(2)(a) — explicit consent for biometric processing
- Ensure consent is freely given, specific, informed, and unambiguous
On the iDenfy “Agree & continue” button: This is a transparency and acknowledgment measure, not a consent mechanism. It fulfills your transparency obligations under Art. 13 GDPR and confirms that the data subject was informed prior to biometric capture. If you rely on consent as your legal basis, you must implement your own consent mechanism separately. You may display your own legal bases in a second verification window — we recommend identifying yourself as controller, stating your legal bases, and referencing applicable legislation per Art. 13(1)(c).
Consent Logging
For accountability purposes (Art. 5(2)), iDenfy records:- Timestamp of user confirmation
- Version of the information displayed
- Whether the iDenfy policy, your policy, or both were shown
Cross-Border Data Transfers
iDenfy processes and stores all data within the EU (Dublin, Ireland). Data is not transferred outside the EEA unless:- Standard Contractual Clauses (SCCs) are in place
- A Transfer Impact Assessment has been completed
Data Subject Rights — How iDenfy Supports You
When iDenfy acts as processor, all data subject requests received directly are transferred to you as the data controller. iDenfy supports you upon request in accordance with the DPA.
Security Measures Supporting GDPR Compliance
Relevant Certifications
- ISO/IEC 27001:2022 — Continuously certified since 2020 (TUV Thuringen, DAkkS accredited)
- SOC 2 Type II — Security, availability, and confidentiality (12-month examination period)
- eIDAS Conformity — Remote ID proofing certified under EU Regulation 910/2014
Data Protection Officer: dpo@idenfy.com Security inquiries: security@idenfy.com