Skip to content
Trust center

Security and privacy

Secure data exchange requires checks on the organisations and wallets taking part. Read how Ver.iD assesses them, reviews privacy risks and receives vulnerability reports.

Assessment before and after admission

Clients and the data they request

Before admission, we assess the organisation, its role as an issuer or relying party and the attributes it intends to process. We consider internal controls, privacy responsibilities and whether the requested data fits the purpose of the service.

For sensitive data, such as the Dutch citizen service number (BSN), we assess the authority to process it. Clients are reassessed annually. This assessment does not take over their own legal responsibilities.

Wallets before production use

A wallet undergoes assessment before integration into our production environment. We examine cryptography, interoperability, its ecosystem, available attributes and business model.

Data control and data minimisation are also part of the assessment. Wallets are reassessed annually. A listing in a wallet directory is not, by itself, evidence of admission.

Privacy risks and the DPIA

Our internal Data Protection Impact Assessment was completed in 2024 and is reviewed annually. Material changes to processing, systems or privacy risks also trigger reassessment.

The DPIA supports our assessment of privacy risks. Clients determine whether a DPIA is required for their own processing. The internal report is not a public certificate.

Responsibilities for data processing

When Ver.iD processes data on behalf of a client, it follows the agreement and the client’s lawful instructions. Where Ver.iD determines the purpose and means of processing, it acts as the data controller.

The client remains responsible for the purpose and legal basis of its processing and for informing its users. The privacy policy describes processing for customers, representatives and website visitors.

Privacy policy

Report a vulnerability

Send a technical security finding to the address below. Include the affected component, potential impact and steps that allow us to reproduce the issue.

security@ver.id

Share only the information needed to understand the finding. Do not include passwords, private keys or unnecessary personal data.