Product
POPULAR CHECKS
MOM education verification
Reference
Civil background
Employment history
Social media
Criminal record
Right to work
Adverse financial history
Identity
Instant employment
All background checks
How we compare?
KEY FEATURES
Continuous screening
Compliance
Verepass
Global services
API
Whistleblowing
POPULAR INTEGRATIONS
All integrations
Industries
KEY INDUSTRIES
Finance
Energy
Software & Tech
BPO
Defence
Gaming
Healthcare
Country-specific packages
UK
Singapore
Philippines
New Zealand
Australia
USA
All countries
Business-sized solutions
Growth
Enterprise
Resources
Blog
Knowledge and insights from the world of hiring and HR
Webinars
Discover our upcoming and on-demand webinars
Reports
Data-driven, investigative long reads from industry experts
Case studies
Discover the ways we help customers all over the world
HR glossary
Get to grips with all the HR terms, jargon and lingo you need to know
ROI calculator
Calculate the return on investment of background checks
Help centre
Knowledge and insights from the world of hiring and HR
Contact support
Chat, phone and email support available globally

Outsource or manage background checks in-house: which delivers better ROI?

Get your own copy!
PartnersPricing
LoginSpeak to an expert
LoginSpeak to an expert

Data protection policy

Last updated September 2026.

1. Introduction & Overview

Veremark Ltd (“us”, “our”, “we”, “Veremark”) acts primarily as the processor of your personal data collected on behalf of third-party organisations using the Veremark service. This Data Protection Policy (the “Policy”) explains who we are, why and how we process personal data collected through your use of the Veremark platform, web portals, APIs, and website, and—if you are the subject of any of the personal data concerned—what statutory rights you have and how to get in touch with us.

When you supply any personal data to us, we have legal obligations towards you in the way we use and protect that data.

1.1 Document Structure & Index

For ease of reading, reference, and governance, this Policy is structured into the following sections:

  1. Introduction & Overview
  2. What Information We Collect
  3. How Your Personal Information Is Collected
  4. How and Why We Use and Share Your Personal Information
  5. Data Retention & Erasure
  6. Information Security & Technical Safeguards
  7. International Data Transfers
  8. Your Rights & Subject Access Requests (SARs)
  9. Contact Details & Regulatory Complaints

1.2 Relationship to Other Notices

It is important that you read this Policy together with any other privacy notice or fair processing notices that we may provide on the Service at or around the time that we collect or process personal data about you (for example, fair processing notices that we display to you at the time that you consent to us collecting or processing specific types of data, or Candidate Consent forms). This Policy supplements other notices on the Service and our website and is not intended to override or replace them.

1.3 Changes to This Policy

We reserve the right to revise or amend this Policy at any time to reflect changes to our business, platform capabilities, or applicable laws. Where these changes are significant, we will endeavour to let users of the Service know (most likely by email if a registered individual account is available, or via in-app notification).

1.4 Protection of Minors

Please note that the Service is not directed at children under the age of 13 (each a "Child" or "Children") and we do not knowingly collect personal data about Children. If you believe we have collected personal data about your Child, you may contact us using the contact details set out in Section 9 below.

‍

2. What Information We Collect

2.1 Definition of Personal Data

Where this Policy refers to ‘personal data’, it refers to any information relating to an identified or identifiable natural person from which you could be identified—such as your name, date of birth, contact details, identification numbers, and digital identifiers such as IP addresses.

2.2 Data Categories

Depending on the specific background checks requested by the client organisation, the personal data we collect and process may include:

  • Identity Data: Full legal name, previous/maiden names, date of birth, and gender.
  • Contact Data: Personal and professional email address, telephone number, residential address, billing address, and delivery address.
  • Historical Data: Details of your previous employment history (job titles, dates of employment, responsibilities, reasons for leaving), residential history, and academic/educational achievements.
  • Document Data: Legible copies of official documents that you provide to us, or which an organisation provides to us for verification purposes (such as Passports, National Identity Cards, Driving Licences, Right to Work documents, Visa/Immigration documents, and academic degree certificates/transcripts).
  • Verification Data: The structured outcomes and results of verification checks performed in relation to you (such as verified employment references, educational validations, outcomes of criminal history background checks from authorised agencies, directorship checks, or visa/right-to-work status checks).
  • Technical & Usage Data: Internet Protocol (IP) addresses, browser type and version, time zone setting, operating system, and platform audit logs recorded when accessing our candidate portal or web verification tools.

‍

3. How Your Personal Information Is Collected

We collect personal data through fair, lawful, and transparent means using the following channels:

3.1 From Third Parties (Client Organisations)

Where an organisation (such as a prospective employer, current employer, or contracting entity) wishes to use the Service to verify your identity or other details about you, it supplies us with your Identity Data and basic Contact Data. We use that data to contact you (typically via secure automated email invitation) and ask you to engage with the verification process requested.

Once you indicate that you are willing to engage with the process, that organisation may provide us with further Historical Data, Document Data, and Identity Data for us to verify.

3.2 Directly From You

Where you choose to engage with a verification process, you provide us directly with a range of Identity Data, Historical Data, and Document Data through our secure digital onboarding workflow.

Where you do so, you also provide us with your explicit digital authorisation/consent to make contact with designated third parties (such as previous academic institutions, credential issuers, or former employers) and to seek additional verification data from them.

3.3 From Independent Verifiers & Official Repositories

When you respond to a request for specific background checks, we make contact with relevant external verification authorities and data sources to obtain official verification records. Examples include:

  • Official criminal record checking authorities and statutory registries (e.g., the Disclosure and Barring Service (DBS) in the UK or equivalent national agencies).
  • Educational and academic institutions, awarding bodies, and qualification registries.
  • Previous employers and authorised referee contacts.
  • Government immigration, right-to-work, and identity validation agencies.

‍

4. How and Why We Use and Share Your Personal Data

4.1 Lawful Basis for Processing Your Information

Veremark only uses your Personal Data for the purpose of conducting identity verification, credential checks, and authenticity assessments requested by our clients.

  • Initial Contact & Communication: We make initial contact with you to communicate the commencement of a background screening request on the basis of the client organisation’s lawful basis (typically legitimate interests or pre-contractual steps) and our agreement with them.
  • Consent & Candidate Engagement: Thereafter, processing of your verification details is conducted on the basis that you have actively engaged with the process and provided your explicit consent and authorisation for specific checks to be executed.
  • Contractual Necessity (Direct Candidate Services): In certain circumstances, you may also use our Service to enter into a direct contract with us (such as digital career passport services or credential storage where you ask us to hold historic results of verification processes performed in relation to you). Where that is the case, we store and process the Personal Data you direct us to hold for the duration of that contract.
  • Legal and Regulatory Compliance: Where required by applicable law, statutory enactments, court orders, or law enforcement mandates.

4.2 Data Sharing & Disclosure

We do not sell, rent, or trade your Personal Data. We share your Personal Data strictly with:

  1. The Requesting Organisation: The prospective or current employer who initiated the verification request. They receive the verified results and vetting report.
  2. Designated Third-Party Verifiers: The specific employers, academic bodies, and official checking authorities required to obtain authentication.
  3. Authorised Technical Sub-Processors: Cloud infrastructure providers, secure communication vendors, and technical service providers bound by strict contractual confidentiality and data processing terms complying with GDPR/applicable privacy legislation.

‍

5. Data Retention & Erasure

We hold your personal information on our systems only for as long as required to perform verification on it in response to requests made by our customers, and for those customers to access, review, and evaluate the results.

  • Controller-Defined Retention: The precise length of data retention is defined by the organisation using the Veremark service as the Data Controller.
  • Statutory Exceptions: The only exception to the above position is where applicable statutory law compels us to retain particular Personal Data for a specified period (such as tax, accounting, or regulatory compliance mandates).

6. Information Security & Technical Safeguards

Veremark implements comprehensive organisational, physical, and technical measures designed to protect your personal data against accidental loss, unauthorised access, destruction, misuse, or alteration:

  • Encryption Standards: Personal data is encrypted in transit using industry-standard Transport Layer Security (TLS 1.2 and TLS 1.3) and encrypted at rest across all databases and file stores using Advanced Encryption Standard (AES-256).
  • Access Controls & Multi-Factor Authentication: Platform access is governed strictly by the principles of Least Privilege and Role-Based Access Control (RBAC). Mandatory Multi-Factor Authentication (MFA) is enforced for all administrative and operational staff.
  • Operational Audits & Certifications: Our internal controls, infrastructure, and operating procedures are regularly audited against international information security frameworks, including ISO/IEC 27001, SOC 2 Type II, FSQS and Cyber Essentials. 
  • Integrity and Audit Trails: System interactions, check updates, and report access actions are systematically logged within immutable audit trails to guarantee integrity.

7. International Data Transfers

Some of our service providers, verifiers, or client entities may be based outside of the European Economic Area (the “EEA”) or the United Kingdom. These service providers may work for us or for one of our suppliers and may be engaged in, among other things, the fulfillment of your verification request and the provision of technical support services.

  • Authorised Global Verifications: On most occasions where an international transfer of your data is made, you will be aware of the transfer and will be asked to give specific authorisation for it (such as where you explicitly authorise us to approach an overseas academic institution, former employer, or national vetting registry to verify your records).
  • Transfer Safeguards: Where we transfer your data to a service provider that is outside of the EEA/UK in circumstances where we have not received your specific approval in advance, we ensure appropriate safeguards are implemented in accordance with applicable data protection laws. Transfers are executed:
    • To a country or territory recognised by the European Commission or UK Government as providing an adequate level of data protection; or
    • Governed by Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Addendum (IDTA), or other legally valid cross-border transfer mechanisms.

8. Your Rights & Subject Access Requests (SARs)

As a data subject, you have statutory rights in relation to your personal data under the UK GDPR, EU GDPR, and equivalent data protection regulations:

  • Right of Access: You have the right to request a copy of the personal data held about you.
  • Right to Rectification: You have the right to request the correction of inaccurate or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): You have the right to request that your personal data be erased where it is no longer necessary for the purpose it was gathered.
  • Right to Restrict or Object: You have the right to request the restriction of processing or object to certain processing activities.
  • Right to Data Portability: You have the right to obtain and reuse your personal data across different services.

Important Notes on Exercising Rights via Veremark:

  1. Processor Role & Forwarding Requests: We act as a processor of your data on behalf of the organisation requesting verification. Accordingly, if you make a subject access request (SAR) to Veremark, we will identify and forward that request to the relevant data controller (your prospective/current employer) for formal consideration and action.
  2. Confidential References Exemption: Please note that making a subject access request will not entitle you to receive copies of confidential references supplied by previous employers (or other referee organisations) to a prospective employer. In accordance with applicable data protection legislation (including Schedule 2 of the UK Data Protection Act 2018), such confidential employment references are legally exempt from subject access disclosures and will not be provided.
  3. Third-Party Background Check Methodology: We do not hold or process full raw investigative records of background checks performed by third-party government bodies or agencies; we receive only the outcomes and status reports. Accordingly, making a subject access request to Veremark will not disclose internal methodologies or third-party proprietary agency operations.

9. Contact Details & Regulatory Complaints

9.1 Contacting Veremark

If you have any queries regarding this Policy, if you wish to exercise any of your data rights, or if you believe this Policy has not been adhered to, please contact our privacy team:

  • Email: privacy@veremark.com
  • Mailing Addresses:
    Veremark Ltd
    167-169 Great Portland Street
    London, W1W 7LT
    United Kingdom

Penthouse B, GMA Lou-Bel Plaza

7514 Bagtikan Street corner 

Chino Roces Avenue, Barangay San Antonio

1203 City of Makati, Fourth District

Philippines

‍

188D Park Avenue, 

Suite L-5, Amityville

NY 11701

United States

‍

160 Robinson Road, 

#14-04

Singapore 068914

‍

Level 54, 

Almas Tower, DMCC, Dubai

UAE

‍

9.2 Supervisory Authority

You also have the right to lodge a complaint with your local data protection supervisory authority regarding the way your personal data is handled.

  • In the United Kingdom, the supervisory authority is the Information Commissioner’s Office (ICO) (Website: https://ico.org.uk).

We would, however, appreciate the chance to address your concerns directly before you approach a supervisory authority, and welcome you contacting us in the first instance.

‍

follow us
Company
AboutPartnersCareersContact
Resources
BlogReports & whitepapersCase studiesWebinarsVideosGlobal servicesSubscribe
Service
Candidate supportVerify PassportHelp centerFAQs
Legal
Customer data protection policyGeneral information security policyTerms of serviceCode of conduct and ethics policyWebsite Privacy policyWebsite Cookie policy
ISO27001 certified
Copyright © 2024 Veremark. All rights reserved