1. Introduction
This Privacy Policy describes how we collect, hold, use, store and disclose your personal and sensitive information when you use the LexisNexis® IDVerse® identity verification and authentication services. These services are provided by LexisNexis Risk Solutions (Europe) Limited, except in the Americas, where they are provided by LexisNexis Risk Solutions FL Inc., in the Asia-Pacific region, where they are provided by OCR Labs Pty Ltd, and in the United Kingdom, where they are provided by OCR Labs Global Limited.
2. Biometric Data Notice for Illinois, Washington, Colorado and Texas Residents
For residents of Illinois, Washington, Colorado or Texas, if our clients require you to provide us with any document that contains your photograph or if you need to verify or authenticate your identity by providing a photograph or video of yourself, the data derived from your face that we collect and process on behalf of our clients to provide the verification or authentication service may be considered biometric data. We will only use your data for the purposes of verifying or authenticating your identity and the prevention of fraud, and for no other purposes. Your biometric data will be retained as long as required for these purposes, but no longer than three (3) years from the date of your last interaction with our service unless a shorter retention period is required pursuant to applicable law or contract. We do not sell, lease, trade or otherwise profit from your biometric data and we do not share your biometric data with a third party except as set forth in this Privacy Policy.
3. What information do we collect and hold?
We may collect and hold the following types of personal and sensitive information:
4. How do we collect your information?
We may collect personal and sensitive information directly from you and from third parties when you use our verification or authentication services.
We automatically receive and record certain information from your mobile device. This may include such information as the third-party website or application into which the services are integrated, the date and time that you use the services, your IP address and domain name, your software and hardware attributes (including operating system, device model, and hashed device fingerprint information), and your general or precise geographic location.
We may receive information about you from our clients where they make use of our services. This information may include a client ID that identifies you in a database as well as the categories of information set out above.
5. How long do we retain your information?
We will retain your personal and sensitive information only for as long as necessary to provide the services requested and for other essential purposes as set out in this Privacy Policy, including to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. Our clients configure how long we store your personal and sensitive information, which will be a minimum period of one (1) week, and, for biometric data, a maximum period of three (3) years unless a shorter retention period is required pursuant to applicable law or contract.
6. Why do we collect, hold, use and disclose your information?
We may collect, hold, use and disclose your personal and sensitive information for the following purposes:
We may use de-identified, aggregated information to share insights about users of our services, such as by publishing a report on trends in the usage of such services.
7. How do we process your data?
Once we collect your information, we use automated systems, including systems that use artificial intelligence (AI) and machine-learning technologies, to assess the identity evidence you provide and generate identity-verification and fraud-risk results on behalf of our clients.
Depending on the services selected by our clients, these automated checks may include:
These automated checks may generate identity-verification results, facial-comparison results, and fraud-risk signals indicating whether our technology has detected potential issues. We provide the evidence collected and the results of these checks to our clients.
Our clients determine how these results are used and what action they take, including whether you may access their products or services. Our clients also determine whether their decision is automated or subject to human review. Contact them for further information about their decision-making process or to request human review, where applicable.
Where our systems identify indicators of suspected impersonation, synthetic identity use, stolen identity use, or other fraudulent activity, we may retain biometric representations and other fraud-prevention identifiers in our fraud-prevention database service. We use this information to help identify suspected repeat or linked fraudulent activity involving our services or clients. Please contact us if you believe information about you has been included in our fraud-prevention database incorrectly.
8. What are other circumstances for disclosure?
Business Transactions
If we are involved in a merger, acquisition or asset sale, your personal and sensitive information may be transferred. We will endeavour to provide notice before your personal and sensitive information is transferred and becomes subject to a different Privacy Policy.
Law enforcement
Under certain circumstances, we may be required to disclose your personal and sensitive information if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other legal requirements
Under certain circumstances, we may disclose your personal and sensitive information in the good faith belief that such action is necessary to:
9. Do we use your personal information for direct marketing?
We do not use personal information provided to us or collected as part of our identity verification or authentication services for marketing purposes.
10. To whom do we disclose your personal information?
We may disclose personal information (but not sensitive or biometric data) for the purposes described in this Privacy Policy to:
11. Overseas transfers
We use localised instances of cloud hosting based on the location or configuration choice of our clients:
We make limited transfers of personal data within our group companies to Australia or the USA from the UK or the EU, subject to appropriate safeguards, in order to provide support and customer success services to our clients.
To send you an SMS message to start the verification journey your mobile number only is processed in the USA (other than Australian residents for whom we use an Australian supplier). To check that your address is in the right format we send your address to a supplier in the UK, the USA or Australia, subject to appropriate safeguards.
12. Security and storage
We use appropriate technical and organisational measures designed to protect your personal and sensitive information against misuse, interference, loss and unauthorised access, modification or disclosure. These measures include encryption in transit and at rest, access controls, security monitoring, vulnerability testing and business continuity and disaster recovery arrangements.
Our information security program is independently assessed against ISO/IEC 27001 and SOC 2 Type II requirements.
13. Unsolicited information
There may be circumstances where an individual provides us with the personal or sensitive information about another person. Where we receive unsolicited personal information which we do not require for the purposes we have outlined above, we will destroy or de-identify that information as soon as practicable (if it is lawful and reasonable to do so).
14. Grounds for Processing
When we are processing personal information on behalf of our clients it is up to our clients to establish the ground or legal basis of processing under applicable data protection laws, but it will likely be under one of the following conditions:
15. Your Rights
You have the right under this Privacy Policy, and by law, depending on your jurisdiction, to request, free of charge:
Please note that we may ask you to verify your identity before responding to such requests.
Where we have obtained your consent to processing, you have the right to withdraw your consent, but if you withdraw your consent, we may not be able to provide you with certain functionalities of the service.
For information on how our clients use the results of our checks in their decision-making on the verification or authentication of your identity, you will need to contact them directly.
16. UK DVS Trust Framework
LexisNexis IDVerse is certified under the rules set out in the UK Department for Science, Innovation and Technology’s UK digital identity and attributes trust framework (the “DVS trust framework”) for identity checks for the purpose of a DBS (disclosure and barring service), Right to Work and Right to Rent checks.
Under the UK DVS trust framework, the LexisNexis IDVerse registered service provider is acting as the data controller of your personal data because it must determine how your personal data is processed and must make a decision if you are correctly verified in accordance with the UK DVS trust framework rules. Once it has completed the check and sends the result of the check and your identity document information to its client, then the client becomes an independent data controller of your personal data.
Legal Basis under the UK DVS trust framework
Data Sharing under the UK DVS trust framework
UK Identity Theft Support and Signposting
If you believe your personal information has been used fraudulently in connection with a LexisNexis IDVerse identity check, contact the organization that asked you to complete the check first. That organization is normally the data controller and is responsible for investigating the transaction and providing account-specific support.
You may also contact us using the privacy contact details in this notice. We will record and assess your concern, preserve relevant information where appropriate, and assist the data controller in accordance with applicable law and our contractual obligations. We may provide transaction evidence where legally permitted.
If you believe you are a victim of identity theft or fraud, you should consider the steps set out here: https://data.actionfraud.police.uk/cms/wp-content/uploads/2023/12/Identity-theft-victims-checklist.pdf
This guidance does not replace advice from law enforcement, financial institutions or professional advisers.
How LexisNexis IDVerse is funded
LexisNexis IDVerse is funded through commercial fees paid by client organizations under contractual agreements. Individuals completing a LexisNexis IDVerse identity check are not charged any fees. Personal data collected during the check is not sold or used to train LexisNexis IDVerse models.
17. Digital ID Accredited Services (Australia)
For services provided under the Digital ID Act 2024 (Australia):
18. Changes
We will update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. If we make any material changes, we will provide notice through our services or by other means.
19. Contact us
For further information about our Privacy Policy or practices, or to make a request, inquiry or complaint, please contact us at:
Data Protection Officer, LexisNexis Risk Solutions, Global Reach, Dunleavy Drive, Cardiff CF11 0SN, United Kingdom, [email protected]
You may also lodge a complaint with the data protection authority in the applicable jurisdiction.
Version 6.6
Effective Date: 1 October 2026