When using Konfir, under the UK GDPR framework, your role is as a data controller, whereas Konfir acts as the data processor.
Responsibilities Overview
Responsibility | Konfir (Processor) | Your Organisation (Controller) |
Capturing applicant consent | ✅ Yes | ❌ |
Data security & encryption | ✅ Yes | ❌ |
Define lawful basis | ❌ | ✅ Required |
Notify applicants of processing | Optional | ✅ Required (include Konfir in privacy docs) |
Managing internal user access | ❌ | ✅ Required |
Handling DSARs | ✅ If related to our data | ✅ Must notify us if request received |
Refer to our Organisation Terms for full detail.
What you are responsible for
Ensure lawful basis for requesting a verification (e.g. consent or legitimate interest)
Manage access to verification results internally
Forward GDPR requests promptly to [email protected]
