VeroPass/Legal/GDPR

GDPR Compliance.

How VeroPass processes personal data under the General Data Protection Regulation - and how we help our customers meet theirs.

Last updated15 June 2026
RegulationEU 2016/679
HostingEuropean Union

01Our commitment

VeroPass was designed in Europe, for Europe. Data protection is not a layer bolted on at the end - it is a building principle, alongside record tamper-resistance and brand ownership of data. We comply with Regulation (EU) 2016/679 (GDPR) and national implementing legislation.

Privacy by design

Data minimisation, European hosting by default and layered access are present from the very first line of code.

02Controller and processor

Our role under the GDPR depends on the context:

Controller
When we process data for our own purposes - access requests, accounts, marketing - we define the purposes and means. Those processings are in the Privacy Policy.
Processor
When we process personal data contained in passports on behalf of a customer, we act only on their documented instructions.

Note: most of a passport's data is product data, not personal. But when, for example, the first owner of an item is registered, the customer is the controller and VeroPass the processor.

03Principles we follow

  • Lawfulness and transparency - we process data only on a valid basis and in a clear way.
  • Purpose limitation - we do not reuse data for purposes incompatible with collection.
  • Minimisation - we collect only what is necessary.
  • Accuracy - we keep data correct and up to date.
  • Storage limitation - we keep data only for as long as necessary.
  • Integrity and confidentiality - we protect data proportionately to the risk.

04Legal bases

Each processing rests on one of the bases in Article 6 of the GDPR - performance of a contract, legitimate interest, consent or legal obligation. The detail per purpose is described in the Privacy Policy. When we act as a processor, the legal basis is set by the controlling customer.

05Data subject rights

We ensure the full exercise of the rights provided by the GDPR: access, rectification, erasure, restriction, objection and portability. When a data subject contacts us directly about data we process on behalf of a customer, we promptly forward the request to the controller and provide the necessary assistance.

06Security measures

We apply technical and organisational measures appropriate to the risk, under Article 32:

  • Encryption of data in transit (TLS) and at rest.
  • Access control by role, with least-privilege principle.
  • Tamper-resistant audit logs - each event signed and dated.
  • Backups and tested recovery plans.
  • Security reviews and impact assessments where applicable.

07Data processing agreement (DPA)

For business customers, we provide a Data Processing Agreement (DPA) setting out the subject matter, duration, nature and purposes of processing, the categories of data and data subjects, and the obligations of both parties - in compliance with Article 28 of the GDPR. The DPA is signed before any processing of personal data on our part.

Request the DPA

Request our DPA template at dpo@veropass.eu. We will also review yours, within reason.

08Sub-processors

We rely on a restricted set of sub-processors, all under contract with adequate safeguards and, wherever possible, with infrastructure in the European Union:

Cloud infrastructure
Hosting and compute in EU data centres.
Communication
Sending transactional and support emails.
Observability
Monitoring and error logging, with minimised data.

We give advance notice of any change to the list of sub-processors, giving the customer the opportunity to object.

09International transfers

Data is, in principle, processed and hosted in the European Union. Should a transfer outside the European Economic Area be unavoidable, we ensure adequate safeguards: an adequacy decision of the European Commission or standard contractual clauses, complemented by technical measures where necessary.

10Data breaches

We have procedures to detect, contain and assess security incidents. In the event of a personal data breach, we notify the competent supervisory authority within 72 hours, where applicable, and inform affected customers without undue delay, so they can meet their own obligations.

11Data Protection Officer

We have appointed a Data Protection Officer (DPO) responsible for overseeing compliance, responding to data subjects and serving as point of contact with the supervisory authority - in Portugal, the National Data Protection Commission (CNPD).

12How to exercise rights

To exercise any right, request the DPA or clarify a compliance question, contact our DPO directly. We respond within a maximum of one month.

V

Data Protection Officer

dpo@veropass.eu · VeroPass, Lda. · Lisbon, Portugal