GDPR (General Data Protection Regulation)

Ayrıca şöyle anılır General Data Protection Regulation, Regulation (EU) 2016/679

Bir araya getirildiİnşa edilmedi

Origin: composes. The European Union wrote this law. Solidus did not draft it, holds no exemption from it, and cannot certify itself against it, no such certificate exists.

The GDPR is the EU law governing how any organization, anywhere in the world, not just inside the EU, may collect, store, use, and share the personal data of people located in the EU. It took effect on 25 May 2018 and replaced an earlier, weaker 1995 directive. Its extraterritorial reach is the detail most people miss: a company based outside the EU with no EU office is still bound by it the moment it processes an EU resident's personal data, which is why GDPR shows up in nearly every serious identity or KYC product's compliance conversation regardless of where that product's company is headquartered.

What it actually requires

A short version of the core obligations:

  • A lawful basis for every use of personal data (Article 6), consent, contract necessity, legal obligation, and a handful of others. "We wanted the data" is not one of them.
  • Data minimization and storage limitation (Article 5), collect only what's needed for the stated purpose, and don't keep it longer than that purpose requires.
  • Individual rights, access to your own data, correction, erasure ("the right to be forgotten," Article 17), portability, and the right to object to certain processing.
  • Special protection for sensitive categories (Article 9), health data, biometric data used to uniquely identify a person, and a handful of other categories require a stronger lawful basis than ordinary personal data. A face scan used for liveness matching sits squarely in this category.
  • Privacy by design and by default, and impact assessments for high-risk processing (Articles 25 and 35), large-scale biometric processing is one of the textbook examples regulators point to as needing a documented Data Protection Impact Assessment before it starts, not after.
  • Real enforcement teeth, fines up to €20 million or 4% of global annual turnover, whichever is higher, and national Data Protection Authorities with actual investigatory power.

Who actually built this

The European Parliament and Council adopted the regulation; the European Data Protection Board and each member state's national Data Protection Authority enforce it. None of this is a private-sector standard a vendor can implement partially and call done, it's binding law with statutory penalties, decided entirely outside any company's control, Solidus's included.

Solidus today

Solidus Verify's identity-verification pipeline processes exactly the kind of data GDPR takes most seriously: government ID documents and biometric liveness captures, some of it from people located in the EU. That means GDPR already applies to Solidus today: this isn't a future gate that switches on later, the way a certification target might be. What hasn't happened: no published Data Protection Impact Assessment, no named EU representative or Data Protection Officer, no public Records of Processing Activities, and no independent audit confirming any of the above. Nothing here should be read as a compliance claim, it's the honest, current gap.

See also

KYC and IDV are the processes that generate the personal and biometric data GDPR governs. AML and MiCA are the other EU compliance regimes that layer on top when identity data touches financial services.

Nereden geliyor

Bunu başkası belirtti. Solidus bir araya getiriyor.

Adopted by the European Parliament and Council as Regulation (EU) 2016/679, in force since 25 May 2018, replacing the 1995 Data Protection Directive. Enforced by each EU member state's national Data Protection Authority, coordinated through the European Data Protection Board. Solidus had no part in drafting it and holds no exemption from it, it applies to Solidus the moment Solidus processes an EU resident's personal data, by operation of law, whether or not Solidus has a formal compliance program around it.

Bunu nasıl doğrularsınız

Solidus bunu inşa etmedi. Girdi kavramı açıklıyor.

None independently checkable exists yet. Solidus's own privacy policy pages are a statement of intent, not proof of compliance, a company's word about its own practices isn't evidence, and this entry doesn't treat it as such. Said plainly rather than assumed by default, which is the honest place to be pre-audit.

İlgili

GDPR (General Data Protection Regulation) · Solidus Lexicon