Trust & Privacy

Legal, privacy and compliance

These pages describe how DKAM handles identity, credential and capability data, what controls are in place today, and what is on the compliance roadmap. They are maintained by the DKAM team and updated as the platform matures.

Organisation & Verifier Responsibilities

Organisations, employers, universities, training providers and partner bodies that confirm or issue records on DKAM take on specific responsibilities. These exist to protect the individual and to keep the trust layer credible.

Accuracy

  • Confirm only what you can substantiate from your own records.
  • Use a named, authorised individual when confirming or issuing on behalf of your organisation.
  • Issue source-credentials only for programmes, roles or certifications you are entitled to issue.

Timeliness

  • Respond to verification, confirmation and correction requests within a reasonable timeframe.
  • Update, revoke or expire credentials when the underlying situation changes.

Respect for consent

  • Use access granted by an individual only for the stated purpose and within the stated time window.
  • Do not export, copy or retain individual data beyond what the access grant permits.
  • Do not attempt to re-identify individuals discovered through anonymised search outside of consented unlocks.

Security

  • Protect the verifier accounts you operate. Limit them to authorised staff.
  • Report suspected compromise or misuse promptly through the Contact page.

Disputes

If an individual challenges a record you issued, follow the process in Data Correction & Disputes. Update, withdraw or reissue records where appropriate. Where you disagree, the record remains as-issued with the individual's counter-statement attached.

Status

These responsibilities are set out in the verifier agreement that accompanies organisation onboarding.