Skip to main content

Your GDPR Role: Controller vs Processor

Understand your legal responsibilities when using Konfir.

Jacob avatar
Written by Jacob
Updated over 6 months ago

When using Konfir, under the UK GDPR framework, your role is as a data controller, whereas Konfir acts as the data processor.


Responsibilities Overview

Responsibility

Konfir (Processor)

Your Organisation (Controller)

Capturing applicant consent

✅ Yes

Data security & encryption

✅ Yes

Define lawful basis

✅ Required

Notify applicants of processing

Optional

✅ Required (include Konfir in privacy docs)

Managing internal user access

✅ Required

Handling DSARs

✅ If related to our data

✅ Must notify us if request received

Refer to our Organisation Terms for full detail.

What you are responsible for

  • Ensure lawful basis for requesting a verification (e.g. consent or legitimate interest)

  • Manage access to verification results internally

  • Forward GDPR requests promptly to [email protected]

Did this answer your question?