Summary
Yes - Konfir complies fully with UK GDPR and the Data Protection Act (2018). We are registered with the Information Commissioner’s Office (ICO) (registration ZB222386), hold ISO 27001 certification, and are part of the UK Digital Identity & Attributes Trust Framework (UKDIATF).
This means your data is handled in line with strict UK data protection laws, with transparency and accountability built in.
Who is responsible under GDPR?
Your verifier - Acts as the data controller - they decide why your data needs to be processed.
Konfir - Acts as the data processor - we process your data only on the verifier’s instructions, keep it secure, and maintain audit records.
What Konfir manages as a processor
Capturing and logging your consent
Secure handling, storage, and deletion of data
Managing approved sub-processors (third parties we may use, e.g. for hosting)
Maintaining audit trails and compliance checks
Data protection by design
Konfir’s platform is built with GDPR principles at its core:
Consent-driven — nothing is accessed without your permission.
One-time, read-only access — connections close automatically after use.
Data minimisation — we only collect the minimum needed for your verification.
Transparency — clear information is shown during the journey and in our privacy notice.
To learn more about Konfir’s approach to GDPR compliance, please see our blog post.
Your rights as an individual
Under GDPR, you can ask to:
Access your data (see what Konfir holds about you).
Erase your data (ask Konfir to delete what we hold).
Correct inaccurate data.
Restrict or object to processing in some circumstances.
Learn More: To learn about your rights under GDPR regulation, please see the ICO’s online guide for individuals.
How to make a request
Email [email protected] with your request.
Include your full name and (if possible) your verification ID to help us find your record.
Konfir will act on data we process and coordinate with your verifier if they also hold a copy.
Requests are normally completed within 30 days.
👉 In short: Konfir is GDPR compliant, independently certified, and designed with privacy and user rights at its core. You always know who is responsible, and you always have control over your data.
