Jumio has a robust and transparent privacy management program, which includes controls as a “controller” and “processor” as defined by the GDPR. Jumio supports our customers' roles and responsibilities by providing identity verification solutions that take into account global privacy compliance and offer customers the opportunity to meet their regulatory requirements.
Moreover, Jumio undergoes comprehensive security reviews and is compliant with ISO 27001 and PCI DSS. This means that we’ve adopted a strict set of security standards designed to ensure that identity and personal data are encrypted, stored and maintained in a secure and vetted environment.
Statement of Compliance
Jumio applies the GDPR principles as the baseline for its privacy compliance globally. Effective February 1, 2018 all necessary steps to achieve GDPR compliance have been completed. Jumio’s privacy management program is applicable to all categories of personal data, including biometric data.