WebinarShufti x AML IntelligenceHow AMLR Extends KYC Across the Customer Lifecycle25th Sep | 02:00 PM UTCREGISTER NOW Shufti x AML IntelligenceHow AMLR Extends KYC Across the Customer Lifecycle25th Sep | 02:00 PM UTCREGISTER NOW How AMLR Extends KYC Across the LifecycleRegister Gavel on AMLR rule bookAMLR applies 10 July 2027. See your stack against every obligationBook a Demo AMLR applies 10 July 2027. See your stack against every obligationBook A Demo AMLR applies 10 July 2027 — see your stackBook Demo Globe with pKYC, Onboarding, Screening and Transactions labelsShufti’s Glocal PlatformGlobal Coverage. Local Depth. Full Compliance Lifecycle.Explore More Global Coverage. Local Depth. Full Compliance Lifecycle.Explore More Glocal Platform — Global Coverage. Local Depth.Explore Shufti x ACFEWebinarAI has changed fraud. Now we need to change how we fight it.Microphone icon for Shufti and ACFE fraud webinar5th October, 2026Register Now Shufti x ACFEAI has changed fraud. Now we need to change how we fight it.5th October, 2026Register Now AI has changed fraud — change how we fight itRegister INNOVATION DROPSUMMER
EDITION
20
26
Qualified Electronic Signature
WATCH NOW
INNOVATION DROP - Qualified Electronic SignatureWatch Now Innovation Drop — Qualified Electronic SignatureWatch
INNOVATION DROPSUMMER
EDITION
20
26
Transaction Trust Monitoring
WATCH NOW
INNOVATION DROP - Transaction Trust MonitoringWatch Now Innovation Drop — Transaction Trust MonitoringWatch
INNOVATION DROPSUMMER
EDITION
20
26
Travel Rule Compliance
WATCH NOW
INNOVATION DROP - Travel Rule ComplianceWatch Now Innovation Drop — Travel Rule ComplianceWatch
Gavel on AMLR rule bookAMLR Applies 10 July 2027. Don't Wait for the Deadline to Find the GapsBook Consultation AMLR Applies 10 July 2027. Don't Wait for the Deadline to Find the GapsBook Consultation AMLR Applies 10 July 2027 — Find the GapsConsult Bank card and cashBank Account Verification: Get Secure Payouts with Confirmed OwnershipSee How It Works Bank Account Verification: Get Secure Payouts with Confirmed OwnershipSee How It Works Bank Account Verification — Secure PayoutsSee How Geo Compliance Ties Verified Location to a Verified IdentityBook A Demo Geo Compliance Ties Verified Location to a Verified IdentityBook A Demo Geo Compliance — Verified Location, Verified IdentityBook Demo Journey Builder dot gridConfigure Verification Flows as Per Your Needs with Journey BuilderSee How It Works Configure Verification Flows as Per Your Needs with Journey BuilderSee How It Works Journey Builder — Configure Verification FlowsSee How Shufti MCP toggle with ChatGPT and ClaudeShufti MCP: Verification Tools, Ready to Use Inside Claude or ChatGPTExplore Agent Shufti MCP: Verification Tools, Ready to Use Inside Claude or ChatGPTExplore Agent Shufti MCP — Verification Tools Inside Claude or ChatGPTExplore

us

216.73.216.30

GDPR

Every data subject right is operationally supported not just written into a policy

Biometric data and identity documents are Article 9 special category personal data under GDPR, the most tightly regulated data category in EU law. Shufti processes this data under a documented legal basis, retains it only as long as you configure, and operationally supports every data subject right your users may exercise. Shufti GDPR Data Processing Agreement is included in the standard enterprise contract, not an optional add-on.

GDPR certification badge

Certification Overview

What GDPR Covers

Standard Personal Data

Name, email address, phone number, IP address, regulated under GDPR Articles 5 and 6. Requires a lawful basis for processing, reasonable security measures, and data subject rights. Most SaaS platforms operate under this category.

Article 9 Special Category Data

Biometric data used to uniquely identify a person, facial images, and identity document data, the most tightly regulated GDPR category. Requires explicit consent or legal obligation as processing basis, stricter security controls, mandatory data minimisation, full data subject rights support, and a documented Data Protection Agreement before any processing begins.

Why It Matters

Supervisory authorities, Italy's Garante, Ireland's DPC, and France's CNIL, have specifically investigated digital onboarding flows where verification providers retained biometric data beyond necessity, lacked a documented processing basis, or could not operationally support data subject rights. Enforcement actions followed against the businesses that contracted with those providers.

When a user exercises their right to erasure

Your team needs to operationally deliver it, not just acknowledge it. Shufti's API and admin console let you trigger deletion of individual verification records and receive a deletion confirmation as your audit evidence.

EUR 1.2B+

Assessed by an independent AICPA-registered auditor, not a point-in-time snapshot. All five Trust Services Criteria covered: Security, Availability, Processing Integrity, Confidentiality, Privacy.

Certification Assurance

Independently Verified Compliance Standards

Standard

Compliance framework, legal basis, or certification standard covered.

Assessed By

Independent auditor, authority, or responsible assessing party.

Scope

Systems, data flows, regions, features, or operational areas included.

Documentation

Reports, policies, registers, agreements, or evidence available.

How Shufti Maintains It

Shufti GDPR documentation package includes: the Article 28-compliant DPA, sub-processor register (updated within 30 days of any change), data retention and deletion policy, and technical documentation of how data subject rights are operationally supported. All available on request before you sign a contract.

EU-resident data is processed on EU infrastructure. UK-resident data is processed under UK GDPR. US and APAC regional deployments are available for non-EU data flows.