GDPR and CCPA compliance
Real ID stores government ID photos, selfies and personal details on your behalf, so both you and Verdict have obligations under privacy regulations like the GDPR and the CCPA.
This page covers what each side is responsible for, the tools you have for answering customer data requests, and how to get a Data Processing Agreement.
For the full legal statement, see Security and privacy and the Verdict Privacy Policy.
Who's responsible for what
Under the GDPR, you're the data controller and Verdict is the data processor:
- You decide what gets collected, which customers are asked to verify, how long you need the data, and how you respond to your customers' requests
- We process that data on your instructions, keep it secure, and give you the tools to export or delete it
The same split applies under the CCPA. Because you're the controller, data requests from your customers are yours to answer — we provide the tools and will help, but we can't decide on your behalf.
Requesting a Data Processing Agreement
Data Processing Agreements (DPAs) are available on request. Email [email protected] and we'll send one over.
Answering a customer data request
Access and export requests
When a customer asks for a copy of the data you hold on them:
- Find their ID check in your dashboard
- Download their photos and any documents they submitted
- The check details page shows the extracted personal data — name, date of birth, document number and expiry
You can also retrieve checks and photos programmatically through the REST API.
Once you download a customer's photos, you're responsible for storing them securely and deleting them when the customer asks. See Downloading customer photos for the full list of responsibilities.
Deletion requests
To erase a customer's data, delete the ID check data from the check's action menu. This permanently scrubs the photos and personally identifiable data from Real ID's vaults and databases.
Deleting the data doesn't unverify the customer, so they won't be asked to verify again on future orders. The deletion is recorded on the check timeline with a timestamp, which you can use as evidence that you honored the request.
Data retention
The GDPR expects you to keep personal data no longer than you need it. By default Real ID retains ID check data until you delete it, so you stay in control of the timing.
If you'd rather have data aged out automatically, custom retention periods can be configured on request — email [email protected] with the retention window you need.
Pick your window with your own obligations in mind. A shorter window limits your exposure, but it also removes evidence you may still need — that an age-restricted sale was verified, that a chargeback window has passed, or that you met your compliance requirements.
Requests your customers send to us
Customers can request deletion directly, either from their ID check or by emailing [email protected].
When a customer requests deletion from their check, Real ID:
- Records the request
- Emails the customer to confirm we received it
- Emails you so you can review and action it
The request stays open until you delete the data. We notify you rather than deleting automatically, because as the controller you may have a legal reason to retain the record — for example, proving an age-restricted sale was verified.
Shopify data requests
Real ID is subscribed to Shopify's mandatory GDPR webhooks. When a customer submits a data request or redaction request through Shopify, or when you uninstall the app, Shopify notifies us.
Every request is verified and recorded on arrival, then reviewed and actioned by our privacy team.
If you need written confirmation that a specific Shopify request has been completed, email [email protected] with the customer's email address or the request date.
Verdict's published policy is to delete merchant and customer data within 30 business days of uninstalling Real ID.
Opting out of automated decisions
The GDPR gives customers the right not to be subject to solely automated decisions. You can override any result the verification AI returns by manually approving or rejecting an ID check.
Limiting who can see customer data
Access to ID photos and personal data is part of your own compliance posture. Use staff permissions to restrict which staff can view, download and delete ID checks.
Frequently asked questions
Do you have a DPA I can sign?
Yes. Email [email protected] to request one.
Where is customer data stored?
See Security and privacy for current details on storage, encryption and sub-processors.
Does archiving an ID check delete the data?
No. Archiving only filters the check out of your default view — it has no effect on the stored data. To erase the personal data, use Delete Customer Photos as described in Deleting ID check data.
Can I delete data for a customer who verified on a different store?
No. Each ID check belongs to the store that requested it, and you can only delete data for your own store's checks.
How do I prove to a regulator that I verified a customer's age?
Open the ID check. The timeline shows what was collected, when it was verified and who approved it, and you can download the photos and documents the customer submitted. See Interpreting results for what each field means.
Keep in mind that deleting a customer's data removes this evidence, so check your own retention obligations before you action a deletion request.