LexisNexis IDVerse

Privacy Policy

 

1. Introduction

This Privacy Policy describes how we collect, hold, use, store and disclose your personal and sensitive information when you use the LexisNexis® IDVerse® identity verification and authentication services. These services are provided by LexisNexis Risk Solutions (Europe) Limited, except in the Americas, where they are provided by LexisNexis Risk Solutions FL Inc., in the Asia-Pacific region, where they are provided by OCR Labs Pty Ltd, and in the United Kingdom, where they are provided by OCR Labs Global Limited.

2. Biometric Data Notice for Illinois, Washington, Colorado and Texas Residents

For residents of Illinois, Washington, Colorado or Texas, if our clients require you to provide us with any document that contains your photograph or if you need to verify or authenticate your identity by providing a photograph or video of yourself, the data derived from your face that we collect and process on behalf of our clients to provide the verification or authentication service may be considered biometric data. We will only use your data for the purposes of verifying or authenticating your identity and the prevention of fraud, and for no other purposes. Your biometric data will be retained as long as required for these purposes, but no longer than three (3) years from the date of your last interaction with our service unless a shorter retention period is required pursuant to applicable law or contract. We do not sell, lease, trade or otherwise profit from your biometric data and we do not share your biometric data with a third party except as set forth in this Privacy Policy.

3. What information do we collect and hold?

We may collect and hold the following types of personal and sensitive information:

  • name;
  • mailing or street address;
  • mobile telephone number;
  • email address;
  • age or date of birth;
  • gender;
  • nationality;
  • government-issued identifiers, such as your driver’s licence number and class, Medicare number, state or national ID card number, passport number, and birth or marriage certificate number;
  • video footage or photographs of a face (e.g. “selfie”);
  • other information identifiable from scanned documents you provide, such as your organ donor status, health information or other sensitive data on the document;
  • biometric data derived from the image of your face from your identity document or a video of your face captured during a liveness check;
  • information obtained from fraud-prevention services and document verification services;
  • fraud risk signals and indicators of suspected fraudulent activity generated through our services;
  • your device ID, device type, geolocation information (including precise geolocation), computer and connection information, IP address and standard web log information; and
  • any other personal information that may be required in order to provide our services to our clients.

4. How do we collect your information?

We may collect personal and sensitive information directly from you and from third parties when you use our verification or authentication services.

We automatically receive and record certain information from your mobile device. This may include such information as the third-party website or application into which the services are integrated, the date and time that you use the services, your IP address and domain name, your software and hardware attributes (including operating system, device model, and hashed device fingerprint information), and your general or precise geographic location.

We may receive information about you from our clients where they make use of our services. This information may include a client ID that identifies you in a database as well as the categories of information set out above.

5. How long do we retain your information?

We will retain your personal and sensitive information only for as long as necessary to provide the services requested and for other essential purposes as set out in this Privacy Policy, including to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. Our clients configure how long we store your personal and sensitive information, which will be a minimum period of one (1) week, and, for biometric data, a maximum period of three (3) years unless a shorter retention period is required pursuant to applicable law or contract.

6. Why do we collect, hold, use and disclose your information?

We may collect, hold, use and disclose your personal and sensitive information for the following purposes:

  • to provide verification or authentication services, where you are seeking to access one of our clients’ products or services (or the products or services of third parties, where our clients act as brokers, resellers, referrers or representatives of such parties); and
  • to detect, investigate and help prevent fraudulent behaviour being undertaken on our products for any of our clients or any other security or technical issues,
  • We do not use your personal information, including any biometric data, to develop, improve, or train our algorithms or models.

We may use de-identified, aggregated information to share insights about users of our services, such as by publishing a report on trends in the usage of such services.

7. How do we process your data?

Once we collect your information, we use automated systems, including systems that use artificial intelligence (AI) and machine-learning technologies, to assess the identity evidence you provide and generate identity-verification and fraud-risk results on behalf of our clients.

Depending on the services selected by our clients, these automated checks may include:

  • extracting information from images of your identity documents using optical character recognition (OCR);
  • assessing identity documents for authenticity and signs of fraud, including tampering, photocopying, manipulated or synthetic imagery, and altered or replaced photographs;
  • assessing whether video captured during a liveness check shows a real person and whether the capture is genuine, including detecting photographs, screens, masks, replayed or injected media, manipulated video and deepfakes;
  • performing a biometric facial comparison between the biometric data derived from your identity document and from the video captured during the liveness check; and
  • assessing device, network, capture and transaction information, together with information obtained from fraud prevention and document verification services, to identify fraud risk signals and suspected repeat or linked activity.

These automated checks may generate identity-verification results, facial-comparison results, and fraud-risk signals indicating whether our technology has detected potential issues. We provide the evidence collected and the results of these checks to our clients.

Our clients determine how these results are used and what action they take, including whether you may access their products or services. Our clients also determine whether their decision is automated or subject to human review. Contact them for further information about their decision-making process or to request human review, where applicable.

Where our systems identify indicators of suspected impersonation, synthetic identity use, stolen identity use, or other fraudulent activity, we may retain biometric representations and other fraud-prevention identifiers in our fraud-prevention database service. We use this information to help identify suspected repeat or linked fraudulent activity involving our services or clients. Please contact us if you believe information about you has been included in our fraud-prevention database incorrectly.

8. What are other circumstances for disclosure?

Business Transactions

If we are involved in a merger, acquisition or asset sale, your personal and sensitive information may be transferred. We will endeavour to provide notice before your personal and sensitive information is transferred and becomes subject to a different Privacy Policy.

Law enforcement

Under certain circumstances, we may be required to disclose your personal and sensitive information if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Other legal requirements

Under certain circumstances, we may disclose your personal and sensitive information in the good faith belief that such action is necessary to:

  • comply with a legal obligation;
  • protect and defend the rights or property of the Company;
  • prevent or investigate possible wrongdoing in connection with our services;
  • protect the personal safety of users of the services or the public; and
  • protect against legal liability.

9. Do we use your personal information for direct marketing?

We do not use personal information provided to us or collected as part of our identity verification or authentication services for marketing purposes. 

10. To whom do we disclose your personal information?

We may disclose personal information (but not sensitive or biometric data) for the purposes described in this Privacy Policy to:

  • companies within the LexisNexis Risk Solutions group where necessary to provide our services to our clients;
  • our clients and third parties (where our clients act as resellers or representatives of such parties), where you are seeking to access their products and/or services and are required to verify your identity in order to do so;
  • our employees and contractors, for the purposes of managing our products and systems and providing our services;
  • third party suppliers and service providers (including providers of document verification services to help us verify the validity of identity documents you disclose to us, and other providers for the operation of our websites and/or our business or in connection with providing our products and services to you);
  • specific third parties authorised by you to receive information held by us;
  • other persons, including government agencies, regulatory bodies and law enforcement agencies, or as required, authorised or permitted by law; and
  • as otherwise required or permitted by law.

11. Overseas transfers

We use localised instances of cloud hosting based on the location or configuration choice of our clients:

  • Europe, UK, Middle East and Africa – data is stored in the EEA or the UK
  • Americas – data is stored in the USA, Brazil, or Canada
  • Asia-Pacific – data is stored in Australia or Singapore

We make limited transfers of personal data within our group companies to Australia or the USA from the UK or the EU, subject to appropriate safeguards, in order to provide support and customer success services to our clients.

To send you an SMS message to start the verification journey your mobile number only is processed in the USA (other than Australian residents for whom we use an Australian supplier). To check that your address is in the right format we send your address to a supplier in the UK, the USA or Australia, subject to appropriate safeguards. 

12. Security and storage

We use appropriate technical and organisational measures designed to protect your personal and sensitive information against misuse, interference, loss and unauthorised access, modification or disclosure. These measures include encryption in transit and at rest, access controls, security monitoring, vulnerability testing and business continuity and disaster recovery arrangements.

Our information security program is independently assessed against ISO/IEC 27001 and SOC 2 Type II requirements.

13. Unsolicited information

There may be circumstances where an individual provides us with the personal or sensitive information about another person. Where we receive unsolicited personal information which we do not require for the purposes we have outlined above, we will destroy or de-identify that information as soon as practicable (if it is lawful and reasonable to do so).

14. Grounds for Processing

When we are processing personal information on behalf of our clients it is up to our clients to establish the ground or legal basis of processing under applicable data protection laws, but it will likely be under one of the following conditions:

  • Consent: You have given your consent for processing biometric data for identification or authentication purposes and also for the automatic processing of your personal data. This is the only ground under which we will process your biometric data unless another ground is available under applicable law.
  • Performance of a contract: Processing is necessary for the performance of an agreement between you and our clients.
  • Public task: Processing is necessary for the performance of a task carried out in the public interest.
  • Legitimate interests: Processing is necessary for the purposes of the legitimate interests pursued by our clients which does not unduly prejudice you.
  • Fraud prevention: Processing is indispensable for the prevention of fraud and for your security in identification and authentication processes.

15. Your Rights

You have the right under this Privacy Policy, and by law, depending on your jurisdiction, to request, free of charge:

  • to access, update or delete the information we have on you;
  • to correct any incomplete or inaccurate information we hold about you and to amend incorrectly captured data as part of the identity verification journey;
  • to restrict or object to our processing of your personal data;
  • portability of your personal data.

Please note that we may ask you to verify your identity before responding to such requests.

Where we have obtained your consent to processing, you have the right to withdraw your consent, but if you withdraw your consent, we may not be able to provide you with certain functionalities of the service.

For information on how our clients use the results of our checks in their decision-making on the verification or authentication of your identity, you will need to contact them directly.

16. UK DVS Trust Framework

LexisNexis IDVerse is certified under the rules set out in the UK Department for Science, Innovation and Technology’s UK digital identity and attributes trust framework (the “DVS trust framework”) for identity checks for the purpose of a DBS (disclosure and barring service), Right to Work and Right to Rent checks.

Under the UK DVS trust framework, the LexisNexis IDVerse registered service provider is acting as the data controller of your personal data because it must determine how your personal data is processed and must make a decision if you are correctly verified in accordance with the UK DVS trust framework rules. Once it has completed the check and sends the result of the check and your identity document information to its client, then the client becomes an independent data controller of your personal data.

Legal Basis under the UK DVS trust framework

  • Consent: for the processing of biometric data (your face for matching and liveness checks) and the automated decision making; and
  • Legitimate interests: the processing of your non-biometric personal data.

Data Sharing under the UK DVS trust framework

All personal data collected from you is shared with our clients and with our service providers to check for indicators of fraud and the accuracy of the data provided:

  • Synectics: We check your information against National SIRA and NFI databases. You can read more about Synectics here: https://www.synectics-solutions.com/privacy-policy.
  • Loqate, a GBG Group plc company: We check that your provided address meets the expected structure and format by sending just your address to Loqate.
  • Experian Australia Pty Limited: We check that your provided address meets the expected structure and format by sending just your address to Experian.
  • Twilio: We send just your mobile number to Twilio so that they can send an SMS link to your mobile.
  • Known Pty Ltd trading as Kudosity: We send just your mobile number to Kudosity so that they can send an SMS link to your mobile.

UK Identity Theft Support and Signposting

If you believe your personal information has been used fraudulently in connection with a LexisNexis IDVerse identity check, contact the organization that asked you to complete the check first. That organization is normally the data controller and is responsible for investigating the transaction and providing account-specific support.

You may also contact us using the privacy contact details in this notice. We will record and assess your concern, preserve relevant information where appropriate, and assist the data controller in accordance with applicable law and our contractual obligations. We may provide transaction evidence where legally permitted.

If you believe you are a victim of identity theft or fraud, you should consider the steps set out here: https://data.actionfraud.police.uk/cms/wp-content/uploads/2023/12/Identity-theft-victims-checklist.pdf

This guidance does not replace advice from law enforcement, financial institutions or professional advisers.

How LexisNexis IDVerse is funded

LexisNexis IDVerse is funded through commercial fees paid by client organizations under contractual agreements. Individuals completing a LexisNexis IDVerse identity check are not charged any fees. Personal data collected during the check is not sold or used to train LexisNexis IDVerse models.

17. Digital ID Accredited Services (Australia)

For services provided under the Digital ID Act 2024 (Australia):

  • Biometric data is not retained after verification, except where permitted under the Act for fraud prevention and system security.
  • Any such retention is limited, controlled, and automatically deleted within defined timeframes.
  • Data handling controls are fixed and not configurable by clients.

18. Changes

We will update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. If we make any material changes, we will provide notice through our services or by other means.

19. Contact us

For further information about our Privacy Policy or practices, or to make a request, inquiry or complaint, please contact us at:

Data Protection Officer, LexisNexis Risk Solutions, Global Reach, Dunleavy Drive, Cardiff CF11 0SN, United Kingdom, [email protected]

You may also lodge a complaint with the data protection authority in the applicable jurisdiction. 

 

Version 6.6

Effective Date: 1 October 2026