Regulations

General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) protects the personal data and privacy rights of people in the European Union and European Economic Area. It sets requirements for collecting, using, sharing, and storing personal data.

Depending on the activity, Ver.iD acts as a data controller or a data processor. When Ver.iD processes personal data for a client, we follow our agreement with that client and their lawful instructions. When Ver.iD determines why and how personal data is processed, Ver.iD acts as the data controller.

Status

GDPR is an ongoing legal and operational responsibility. It does not require a certification audit or a separate implementation roadmap. Our privacy policies are regularly reviewed and updated on the Ver.iD website.

Read our Privacy Policy for information about how Ver.iD handles personal data. We also maintain an internal Data Protection Impact Assessment (DPIA) for processing that may create a high risk to people's rights and freedoms.

Last reviewed: August 2026.

On this page