UK Digital Verification Services Trust Framework (DVSTF)
UK Digital Verification Services Trust Framework (DVSTF)
The following Additional Terms apply where Customer purchases or uses the Service and the Service is certified under the UK Digital Verification Services Trust Framework ("Trust Framework"). These Additional Terms set out Customer’s responsibilities as a relying party and the allocation of responsibility between Customer and GBG in connection with Customer’s use of the Service.
Scope and Certification
1. GBG makes the Service available as a service certified under the Trust Framework. Certification applies only to the Service and does not apply to Customer, Customer’s systems, products, integrations, customer journeys or use cases, or any other service or product, unless GBG expressly confirms otherwise in writing.
2. Customer acknowledges that, when it uses or relies on the Service or any Results, Customer acts as a relying party for the purposes of the Trust Framework.
3. Customer shall use the Service in a manner which supports, and does not undermine, GBG’s compliance with the Trust Framework and any certification, surveillance, audit or assessment relating to the Service.
Customer Responsibilities and Use Restrictions
1. Customer may use the Service and Results only for lawful and authorised purposes and in accordance with the Agreement, these Additional Terms and any reasonable instructions, policies or guidance notified by GBG in relation to the Trust Framework.
2. Customer is responsible for its own systems, integrations, customer journeys, decisioning, legal compliance, notices, consents, lawful bases, policies, records, controls, personnel, access management and use of the Service and Results.
3. Customer shall maintain appropriate policies, procedures and controls to support its use of the Service, including fraud management, information security, data retention, personal data processing, data minimisation, data accuracy and repair, identity repair and recourse, incident and complaint handling and, where applicable, reverification of identities and attributes. Such policies, procedures and controls should be clearly documented and where appropriate should follow relevant industry standards such as ISO/IEC 27001 and comply with UK data protection legislation. In respect of fraud management, the Customer should follow best practice guidance based on the Customer’s sector or regulatory environment.
4. Customer shall maintain appropriate technical and organisational measures to protect access to the Service, Customer Data, Results and any identity or attribute information processed through or received from the Service, and shall ensure that access is limited to authorised users with a legitimate business need.
5. Customer shall only submit Customer Data to the Service where Customer has all rights, notices, consents, lawful bases, authorisations and purposes required for GBG to process Customer Data in accordance with the Agreement, these Additional Terms, the DPA and applicable law.
6. Customer shall ensure that Customer Data submitted to the Service is accurate, complete, up to date, adequate, relevant and limited to what is necessary for Customer’s lawful use of the Service, and shall not submit excessive, unnecessary or irrelevant data.
7. Customer is responsible for determining and applying retention periods for Results and any identity or attribute information received from, or generated through, the Service and shall not retain, use or disclose such information for longer than is necessary for Customer’s lawful purposes or in a manner inconsistent with the Agreement, these Additional Terms, the DPA or applicable law.
8. Customer remains solely responsible for determining whether a Result is suitable for Customer’s intended purpose, making any decision based on a Result and managing any fraud, risk, eligibility, onboarding, access or other decision arising from Customer’s use of the Service or Results.
9. Customer shall not alter, manipulate or misrepresent any Result, represent any Result as providing a greater level of assurance than is expressly stated by GBG, or state, imply or represent that Customer, Customer’s systems, products or use cases are certified under the Trust Framework as a result of Customer’s use of the Service.
10. Customer shall maintain appropriate routes for individuals to raise queries, complaints, challenges or requests for correction, repair or recourse in relation to Customer’s use of the Service and any decision made by Customer using Results, and shall maintain processes to review, correct, update, repair or remediate inaccurate or incomplete information within Customer’s own systems, records, journeys or decisioning processes.
11. Where Customer uses the Service in connection with any holder service provider functionality, reusable identity, reusable attribute or similar process, Customer is responsible for determining whether and when reverification of an identity or attribute is required for Customer’s use case, shall not continue to rely on any identity, attribute or Result where Customer knows or reasonably suspects that it is inaccurate, outdated, compromised, no longer suitable for Customer’s purpose or otherwise requires reverification, and shall follow any reasonable instructions, policies or guidance notified by GBG regarding reverification.
Allocation of Responsibility and Liability
1. GBG is responsible for providing the Service in accordance with the Agreement and for maintaining certification of the Service under the Trust Framework, subject to Customer complying with the Agreement and these Additional Terms.
2. Customer is responsible for Customer’s use of the Service and Results, including Customer’s relying party obligations, systems, customer journeys, decisions, records, notices, consents, lawful bases, policies, controls, complaints, support processes and regulatory compliance.
3. GBG is not responsible for any act, omission, decision, use case, customer journey, system, integration, notice, consent, legal basis, policy, record, complaint, support process or regulatory obligation of Customer.
4. Nothing in these Additional Terms increases GBG’s liability beyond the liability expressly accepted by GBG under the Agreement, and Customer remains responsible for any loss, claim, complaint, regulatory action or third-party claim arising from Customer’s breach of these Additional Terms or Customer’s use of the Service or Results outside the Agreement.
Cooperation, Notifications and Complaints
1. Customer shall promptly provide such information and assistance as GBG may reasonably require in connection with any audit, assessment, certification, surveillance activity, regulatory enquiry, investigation, incident, complaint, dispute or support request relating to the Service, Results or GBG’s compliance with the Trust Framework.
2. Customer shall notify GBG without undue delay upon becoming aware of any actual or suspected fraud, misuse, manipulation, compromise or security incident afecting the Service, Customer Data, Results or any identity or attribute information, or any complaint, dispute, regulatory enquiry or investigation relating to Customer’s use of the Service or Results.
Suspension
1. GBG may suspend all or part of the Service where GBG reasonably believes that Customer is in breach of these Additional Terms or that suspension is required to maintain, protect or support GBG’s certification, accreditation, regulatory obligations or compliance with the Trust Framework.