The organisation requesting verification is responsible for deciding why it is needed, which checks to request, the lawful basis and how to use the results, including obtaining consent where required. RegScreener arranges the request and manages assessment records on its instructions. Contact that organisation about the purpose of your check, its lawful basis and your rights. Contact contact@rrcompliance.com for help directing your request.
Version 23 September 2026
Privacy Notice
Identity, address and liveness verification
This supplements the RR Compliance and RegScreener Privacy Notice. It applies to identity-document, proof-of-address, liveness and face-matching checks.
Who requests the check
Documents and camera capture
Didit supplies the secure verification interface. Original identity documents, proof of address and any requested selfie, video or liveness capture go directly from that interface to Didit. Depending on the selected checks, Didit processes extracted identity and address details, facial characteristics, device information and fraud indicators. The individual must complete the live camera step personally and review any consent presented before capture.
Read Didit’s Verification Privacy Notice and its end-user terms and other policies. Didit describes processing on customer instructions and limited independent purposes, including security, fraud prevention and legal compliance.
What RegScreener keeps
RegScreener retains selected assessment data, outcomes and flags, provider references, supplied comparison details, credit records, review notes and audit history. Its assessment database does not retain original document images, selfies, liveness recordings or biometric templates. The requesting organisation controls its use of the assessment; its retention instructions and our main Privacy Notice govern the records we hold.
Original reports
Where enabled, an authorised user can download the provider’s original report, which may contain document images and selfies. A separate restricted service transfers that report through memory to the user’s device without storing a server copy. Copies saved on the user’s device are under their organisation’s control. Downloading the RegScreener assessment instead provides a report without those original images.
Provider retention and transfers
Didit holds originals according to the application’s retention settings and applicable deletion instructions. Our live verification application is configured for one-year retention, with biometric templates deleted with their sessions rather than retained separately. Applicable legal retention and deletion instructions may affect this period; contact the requesting organisation about your record. Provider deletion can make the original report unavailable while permitted RegScreener assessment records remain.
Our core application and primary database are hosted in the UK. This does not mean every provider operation or access remains in the UK. Didit’s notice describes international processing and applicable transfer safeguards. We do not use your verification data for AI model training, and our Didit organisation is configured to exclude it from future model training. Automated verification technology is used to perform the checks requested.
Review and rights
Automated results support staff review. A match, warning or decline is not by itself a final customer decision. Contact the requesting organisation to raise an error or exercise rights relating to its use of your information. Our main notice and Didit’s notice explain additional contacts and complaint routes.
Questions and complaints
For privacy questions or complaints, email contact@rrcompliance.com or write to R&R Compliance Consultants Ltd, 51 Lime Street, London, EC3M 7DQ, marked “Privacy”. We acknowledge data-protection complaints within 30 days, investigate and communicate the outcome without undue delay, keeping you informed of progress.
Where your concern relates to why a check was requested or how its results are used, the requesting organisation is responsible for those decisions. We can help direct your complaint and remain responsible for our own handling of your information.
You may also complain to the Information Commissioner’s Office (ICO) or call 0303 123 1113. Where applicable, you may complain to the data-protection authority where you live or work in the EEA.