Summary
Yes - Konfir fully complies with UK GDPR and the Data Protection Act (2018). We’re registered with the Information Commissioner’s Office (ICO) (registration ZB222386), hold ISO 27001 certification, and are part of the UK Digital Identity & Attributes Trust Framework (UKDIATF).
This means your data is handled lawfully, securely, and transparently - with strict accountability built in.
Who is responsible under GDPR?
Your verifier – acts as the data controller. They decide why your data needs to be processed (for example, employment or income verification).
Konfir – acts as the data processor. We process your data only on the verifier’s instructions, keep it secure, and maintain detailed audit records.
What Konfir manages as a processor
Capturing and logging your consent
Secure handling, storage, and deletion of data
Managing approved sub-processors (e.g., hosting providers)
Maintaining audit trails and compliance checks
Data protection by design
Konfir’s platform is built with GDPR principles at its core:
Consent-driven: Nothing is accessed without your permission.
One-time, read-only access: Connections close automatically after use.
Data minimisation: Only the minimum data needed for your verification is collected.
Transparency: You’re shown clear information about what’s collected and why, throughout the journey and in our Privacy Notice.
To learn more about Konfir’s approach to GDPR compliance, please see our blog post.
Your rights as an individual
Under GDPR, you can ask to:
Request deletion of your data (ask Konfir to delete what we hold)
Request access to data (see what Konfir holds)
Request correction of inaccurate information
Restrict or object to processing in some circumstances.
Learn More: To learn about your rights under GDPR regulation, please see the ICO’s online guide for individuals.
How to make a request
Email [email protected] with your request.
Include your full name and, if possible, your verification ID to help us locate your record.
Konfir will respond regarding the data we process and coordinate with your verifier if they also hold a copy.
Requests are normally completed within 30 days.
