Identity-vendor data due diligence
Do not accept 'GDPR compliant' as a data-flow description. Record what the identity provider receives, creates, retains and shares for the exact product, region and configuration you intend to buy.
Provider policies vary by product and deployment. Public privacy pages are a starting point, not a substitute for the contract, data-processing terms and configured service design.
For: privacy, security, procurement, legal and vendor-management teams. This is independent information, not legal, compliance or security advice.
Evidence table
| Field | Evidence to record |
|---|---|
| Roles | Controller/processor per processing operation |
| Data | Images, video, extracted fields, templates, device and fraud signals |
| Purpose | Verification, fraud, support, legal retention, model improvement |
| Location | Primary processing, storage, support and backup regions |
| Subprocessors | Name, function, location and change notice |
| Retention | Default, configurable minimum/maximum and deletion trigger |
| Evidence | Contract, DPA, policy, audit, test or architecture document |
Questions public pages rarely settle
- Whether raw captures enter model-training or fraud-network datasets.
- How deletion propagates through backups and subprocessors.
- Which support staff can access production evidence.
- What the buyer can configure versus what is globally fixed.
- How a legal hold changes normal retention.
- What happens to data at contract exit.
Validate the scope
A certification can cover an organisation, system or particular service. A data-centre statement may cover one region but not support access. Record document date, scope, exceptions and the exact offered product instead of copying a badge.
Decision outcome
Classify each field as confirmed, contract-dependent, configurable, conflicting or not publicly confirmed. Unresolved high-impact fields become contract conditions or stop conditions, not optimistic assumptions.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing