InfoTrack Limited - Privacy Notice: Consent for Digital Identity Verification

Read our full eCOS consumer privacy notice outlined below.

InfoTrack Limited - Privacy Notice: Consent for Digital Identity Verification

1. About this notice

1.1 This is the Privacy Notice for InfoTrack Limited (we, us) in relation to managing Consent for the eCOS® Digital Identity Verification and the Processing of Special Categories of Data in order to electronically verify the identity of a Data Subject.  

1.2 This Privacy Notice supports InfoTrack Limited’s General Privacy Policy and adopts its definitions.  

1.3 This document meets the requirements of the Data Protection Act 2018 that an appropriate policy document be in place where Processing Special Categories of Personal Data in certain circumstances. 

2. Definitions

Controller: the person or organisation that determines when, why and how to Process Personal Data.

Data Retention Policy: explains how the organisation classifies and manages the retention and disposal of its information.

Data Subject: a living, identified or identifiable individual about whom we hold Personal Data. Data Subjects may be nationals or residents of any country and may have legal rights regarding their Personal Data.

Data Privacy Impact Assessment (DPIA): tools and assessments used to identify and reduce risks of a data processing activity. A DPIA can be carried out as part of Privacy by Design and should be conducted for all major system or business change programmes involving the Processing of Personal Data.

DPA 2018: the Data Protection Act 2018.

Data Protection Officer (DPO): the person required to be appointed in specific circumstances under the UK GDPR. Where a mandatory DPO has not been appointed, this term means a data protection manager or other voluntary appointment of a DPO or refers to the organisation's data privacy team with responsibility for data protection compliance.

Personal Data: any information identifying a Data Subject or information relating to a Data Subject that we can identify (directly or indirectly) from that data alone or in combination with other identifiers we possess or can reasonably possess. Personal Data includes Special Categories of Personal Data.

Processing or Process: any activity that involves the use of Personal Data. It includes obtaining, recording or holding the data, or carrying out any operation or set of operations on the data, including organising, amending, retrieving, using, disclosing, erasing or destroying it. Processing also includes transmitting or transferring Personal Data to third parties.

Special Categories of Personal Data: information revealing racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health conditions, sexual life, sexual orientation, biometric or genetic data.

UK GDPR: the retained EU version of the General Data Protection Regulation ((EU) 2016/679).

3. Why We Process Special Categories of Personal Data

3.1 As part of our services, we offer Digital Identity Verification checks. As part of the Digital Identity Verification service, your Personal Data will be subject to cross referencing checks to establish your identity.

3.2 An element of this service involves ‘biometric’ data, which shall include processing an image of you next to other key identifiers – like your name – as shown on the identity information you provide to us.

3.3 The use of biometric data is necessary for the provision of the Digital Identity Verification and as this involves Special Categories of Personal Data, we need your express consent to engage in this processing.

3.4 It is only envisaged that we will process biometric data, not any other kind of Special Category data.

3.5 To enable us to process Special Categories of Personal Data, we need your consent.

4. Consent

4.1 The Information Commissioner's Office has produced Consent Guidance, which states that Consent to processing should be "freely given" and this means that you have "genuine choice and control" over the use of your data.

4.2 When you agree to the use of your data as part of a Digital Identity Verification via eCOS® check, you will be expressly consenting to the use of your data for this purpose.

4.3 If you choose to consent to a Digital Identity Verification via eCOS®, we will process the data you provide to us in accordance with this Privacy Notice.

4.4 You will provide us with your identity documents containing such information as your address, date of birth and your physical image. This will allow us to seek the electronic verification of your identity. This will involve the transfer of your data as set out in this Privacy Notice and the processing of this information for this purpose.

4.5 You do not have to consent to providing your personal data to InfoTrack but please be advised that failure to do so will mean that InfoTrack Limited cannot provide the Verification of Identity service to you. Please contact your solicitors for more information.

4.6 You may withdraw your consent to processing at any time. This can be undertaken by informing your solicitor of your withdrawal request.

5. Transfer of Data

5.1 In order to perform the Digital Identity Verification check we share your personal data with GBG Group Plc (GBG), The Foundation, Herons Way, Chester Business Park, Chester, United Kingdom, CH4 9GB. GBG will perform the identity check on request and following receipt of your Personal Data and the results of this check will be provided back to us.

5.2 Data Subjects based in EEA: GBG is based in the United Kingdom which is outside of the European Economic Area (EEA). As at the date of this notice the European Commission has adopted an adequacy decision for the United Kingdom which confirms that the UK provides adequate protection for data transfers from the EU to the UK under UK GDPR.

5.3 We have engaged in a review of the data security measures of GBG and have ensured that binding contractual agreements are in place and they have provided us with comprehensive information confirming the security of their systems and the protection of your data.

5.4 GBG uses sub processors to process your data for this purpose also. These sub-processors are third-party technology providers based within the EEA and GBG have contractually confirmed to us that all sub-processors are bound by the principles of the UK GDPR in the same manner as GBG.

5.5 Your data will also be stored with Amazon Web Services and this is inside the EEA.

6. Personal Data Protection Principles

6.1 We comply with the principles relating to Processing of Personal Data set out in the UK GDPR which require Personal Data to be:

6.1.1 processed lawfully, fairly and in a transparent manner (Lawfulness, Fairness and Transparency)

6.1.2 collected only for specified, explicit and legitimate purposes (Purpose Limitation);

6.1.3 adequate, relevant and limited to what is necessary in relation to the purposes for which it is Processed (Data Minimisation);

6.1.4 accurate and where necessary kept up to date (Accuracy);

6.1.5 not kept in a form which permits identification of Data Subjects for longer than is necessary for the purposes for which the data is Processed (Storage Limitation); and

6.1.6 Processed in a manner that ensures its security using appropriate technical and organisational measures to protect against unauthorised or unlawful Processing and against accidental loss, destruction or damage (Security, Integrity and Confidentiality).

6.2 We are responsible for and must be able to demonstrate compliance with the data protection principles listed above (Accountability).

7. Compliance with Data Protection principles

7.1 Lawfulness, fairness and transparency

Personal Data must be processed lawfully, fairly and in a transparent manner in relation to the Data Subject.

We will only Process Personal Data fairly and lawfully and for specified purposes. The UK GDPR restricts our actions regarding Personal Data to specified lawful purposes. We can Process Special Categories of Personal Data if we have a legal ground for Processing or you expressly consent to the same.

When collecting Special Categories of Personal Data from Data Subjects, either directly from Data Subjects or indirectly (for example from a third party or publicly available source), we are required to provide Data Subjects with confirmation of all the information required by the UK GDPR in a privacy notice which is concise, transparent, intelligible, easily accessible and in clear plain language which can be easily understood.

This is what we have endeavoured to undertake in this Privacy Notice. Further clarification of this is set out below:  

Lawful Processing basis Data concerning biometric data Article 9(2) of the UK GDPR requires one of several special conditions to be met for the Processing of Special Categories of Personal Data, such as racial or ethnic origin, health data or biometric data. Obtaining “explicit consent” is one such condition. 

7.2 Purpose limitation

Personal Data must be collected only for specified, explicit and legitimate purposes. They must not be further Processed in any manner incompatible with those purposes.

We will only collect Personal Data for specified purposes and will inform Data Subjects what those purposes are in this published Privacy Notice. 

We will not use Personal Data for new, different or incompatible purposes from those disclosed when it was first obtained unless we have informed the Data Subject of the new purposes and they have consented where necessary.

7.3 Data Minimisation

Personal Data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.

We will only collect or disclose the minimum Personal Data required for the purpose for which the data is collected or disclosed. We will ensure that we do not collect excessive data and that the Personal Data collected is adequate and relevant for the intended purposes.

7.4 Accuracy

Personal Data must be accurate and, where necessary, kept up to date. It must be corrected or deleted without delay when inaccurate.

We will ensure that the Personal Data we hold and use is accurate, complete, kept up to date and relevant to the purpose for which it is collected by us. We check the accuracy of any Personal Data at the point of collection and at regular intervals afterwards. We take all reasonable steps to destroy or amend inaccurate or out-of-date Personal Data.

7.5 Storage Limitation

We only keep Personal Data in an identifiable form for as long as is necessary for the purposes for which it was collected, or where we have a legal obligation to do so. Once we no longer need Personal Data it shall be deleted or rendered permanently anonymous.

We maintain a Data Retention Policy and related procedures to ensure Personal Data is deleted after a reasonable time has elapsed for the purposes for which it was being held, unless we are legally required to retain that data for longer. 

The information you provide to us is stored in line with our Data Retention Policy which can be provided to you on request to our DPO. 

7.6 Security, integrity and confidentiality

Personal Data shall be Processed in a manner that ensures appropriate security of the Personal Data, including protection against unauthorised or unlawful Processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

We will implement and maintain reasonable and appropriate security measures against unlawful or unauthorised Processing of Personal Data and against the accidental loss of or damage to Personal Data.

7.7 Accountability Principle

We are responsible for and able to demonstrate compliance with these principles. Our DPO is responsible for ensuring that we are compliant with these principles. Any questions about this policy should be submitted to the DPO.

We will:

(a) Ensure that records are kept of all Personal Data Processing activities, and that these are provided to the Information Commissioner on request.

(b) Carry out a DPIA for any high risk Personal Data Processing to understand how Processing may affect Data Subjects and consult the Information Commissioner if appropriate.

(c) Ensure that a DPO is appointed to provide independent advice and monitoring of Personal Data handling, and that the DPO has access to report to the highest management level.

(d) Have internal processes to ensure that Personal Data is only collected, used or handled in a way that is compliant with data protection law.

8. Retention and erasure of Personal Data

8.1 We take the security of Special Categories of Personal Data very seriously. We have administrative, physical and technical safeguards in place to protect Personal Data against unlawful or unauthorised Processing, or accidental loss or damage. We will ensure, where Special Categories of Personal Data are Processed that:

8.1.1 The Processing is recorded, and the record sets out, where possible, a suitable time period for the safe and permanent erasure of the different categories of data in accordance with our Data Retention Policy.

8.1.2 Where we no longer require Special Categories of Personal Data for the purpose for which it was collected, we will delete it or render it permanently anonymous as soon as possible.

8.1.3 Where records are destroyed, we will ensure that they are safely and permanently disposed of.

9. Review

9.1 This Privacy Notice on Processing Special Categories of Personal Data will be reviewed by our DPO periodically.

9.2 This Privacy Notice will be retained where we process Special Categories of Personal Data and for a period of at least six months after we stop carrying out such processing.

9.3 If you have any questions about this Privacy Notice or if you wish to make a complaint about the way we have collected, disclosed or used your Personal Data, please contact:

(a) InfoTrack Data Privacy Officer via e-mail at DPO@infotrack.co.uk or;

(b) Write to us – Data Protection Officer, InfoTrack Limited, Level 11, 91Waterloo Road, London, SE1 8RT

0 Brochures Selected
Download Brochures