Data Processing & GDPR
DKAM is designed with GDPR principles in mind. Formal certifications and independent audits are part of our compliance roadmap rather than completed milestones today, and we say so openly.
Principles we follow
- Lawful basis: consent for capability data, contract for paid services, legitimate interest for platform security.
- Data minimisation: we collect only what the relevant flow needs.
- Purpose limitation: data is used for the purpose it was collected for, and consent is purpose-bound.
- Transparency: verification level and access events are visible to the individual.
- Individual rights: access, rectification, erasure, restriction, portability and objection.
Controller vs processor
For individual users, DKAM acts as data controller for the account and the platform-provided record. Where DKAM is engaged by an organisation or institution to support verification or issuance flows on their behalf, DKAM acts as data processor under a data processing agreement with that party.
International transfers
Where data is processed across jurisdictions, DKAM relies on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms. Specifics will be set out in the relevant data processing agreement.
Exercising your rights
Use the Contact page with the Privacy / Data Request option. See also Data Correction & Disputes and Deletion & Consent Withdrawal.
Status
Designed principle. GDPR-aligned controls are built into the platform and reviewed as features ship. Independent certification is a roadmap item.