Our Security, Privacy and Compliance Commitment
In any data-driven ecosystem, compliance is the cornerstone of trust. In the emerging and rapidly evolving eIDAS 2.0 landscape, getting compliance wrong could have serious consequences; undermining user privacy, lack of cross-border interoperability, and eroding trust among citizens, organizations and the 27 EU member states.
That’s why at Ver.iD, compliance stands as one of our core pillars. Every aspect of our platform is thoughtfully designed and rigorously maintained to uphold the highest standards of IT Security and regulatory compliance. Internally, we foster a strong culture of excellence, transparency, and accountability, embedding these values into every layer of our organization.
On this page we provide a clear and detailed view of our Privacy, Security and Compliance efforts. From our commitment to certification of IT Security standards to our commitment of relevant regulation. It’s our way of showing, not just telling, how we help build a secure and trusted platform within the digital identity ecosystem.
Assessments
Data Protection Impact Assessment (DPIA)
A Data Protection Impact Assessment (DPIA) identifies and reduces privacy risks. It is required when personal data processing is likely to create a high risk to people's rights and freedoms. Our internal DPIA is current and is reviewed when our processing, systems, or privacy risks materially change. See the DPIA page for more information.
Certifications
ISO 27001
The ISO 27001 certification outlines the requirements for an information security management system (ISMS), ensuring that Ver.iD systematically examines information security risks and implements a coherent and comprehensive suite of information security controls. Check out the ISO 27001 overview to get an up-to-date overview of our implementation.
NEN 7510
NEN 7510, similar to ISO 27001 but specifically designed for the Dutch healthcare sector, emphasizes the protection of patient information. While Ver.iD may not directly deal with health data, the principles of NEN 7510 highlight the importance of securing personal information in sensitive sectors and are viewed as an additional layer of security on top of the ISO 27001 standard. Check out the NEN 7510 overview to get an up-to-date overview of our implementation.
Audits
SOC 2
SOC 2 reports can provide independent assurance about controls relevant to security, availability, processing integrity, confidentiality, and privacy. Ver.iD is assessing whether to pursue a SOC 2 examination. No SOC 2 report is currently available. See the SOC 2 page for the current status.
Regulations
General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) sets requirements for data protection and privacy in the European Union. For Ver.iD, this includes data minimization, lawful processing, transparency, and respect for individuals' rights. See our Privacy Policy and GDPR page for more information.
Electronic Identification, Authentication and Trust Services (eIDAS 2.0)
eIDAS 2.0, the regulatory framework for electronic identification and trust services, expands on its predecessor to cover the increasing scope of digital identities. Ver.iD’s alignment with eIDAS 2.0 is crucial for facilitating secure and seamless identity transactions across borders within the EU. The eIDAS regulation provides a legal framework for identities within the borders of member states of the European Union. For more information, please go to our dedicated eIDAS 2.0 overview.
Digital Operational Resilience Act (DORA)
The Digital Operational Resilience Act (DORA) establishes ICT risk and resilience requirements for regulated financial entities. Financial-sector customers that use Ver.iD may require specific contractual commitments, security evidence, and operational-resilience support. Ver.iD's ISO 27001 and NEN 7510 certifications provide a certified security foundation, while a separate assessment identifies any additional DORA-related customer requirements. See the DORA page for the current status.
Qualification
Qualified Trust Service Provider (QTSP)
Qualified status under eIDAS applies to specific trust services. Subst.iD B.V. is preparing five selected services for conformity assessment and does not yet have qualified status. See the QTSP page for the selected services and roadmap.