Frequently asked questions.
Everything compliance teams, procurement officers, and technical evaluators ask us before going live.
Identity & technology
What is NFC passport verification and how does it differ from a photo check? +
A photo check compares an image of an ID document against a selfie. It can be defeated by high-quality printed photos, deepfake videos, or forged documents with a real person's photo replaced. NFC verification reads a government-signed cryptographic proof directly from the biometric chip embedded in the passport. This proof can only be generated by the issuing government's private key, it cannot be forged. The combination of NFC chip verification and biometric liveness means a fraudster would need both the physical passport and a synthetic biometric match, which eliminates the vast majority of attack vectors.
Does WeVerify store biometric data? +
No. WeVerify's architecture is built specifically to avoid storing raw biometric data. The NFC chip reading and biometric selfie processing happen on the user's device. WeVerify receives only a cryptographic proof of the result, not the biometric image, not the chip data. This is structural compliance with GDPR Article 9, which governs special category biometric data. It is an architectural decision, not a policy statement.
Which documents are supported? +
WeVerify supports all ICAO 9303-compliant biometric passports (issued since 2006) from 190+ countries, NFC-enabled national ID cards including EU national IDs and German Personalausweis, and biometric residence permits issued in EU member states and the UK. The document list is continuously updated. Specific country or document type coverage can be confirmed for your use case during a demo.
Does the user need to download an app? +
No. The entire verification flow runs in the browser. Users receive a link, open it on their smartphone, and complete verification without installing anything. NFC passport reading is supported natively in the browser on Android 8.0+ and iPhone 7 and later. This significantly reduces drop-off compared to app-based verification flows.
How long does verification take? +
A full identity verification, NFC chip reading, biometric liveness, and face match, completes in under 5 minutes for most users. NFC chip reading itself takes under 3 seconds. The biometric selfie and liveness check take under 4 seconds. The total flow from link opening to result is typically 2β4 minutes. The WeVerify platform processes 99.9% of verifications automatically without manual review.
Legal & compliance
What is a Qualified Trust Service Provider (QTSP)? +
A Qualified Trust Service Provider is an organisation that has been granted qualified status under eIDAS 2.0 by a member state supervisory authority. WeVerify is a eIDAS 2.0 compliant trust service and listed on the EU Trusted List. This means the qualified signatures and seals WeVerify produces are legally equivalent to handwritten signatures across all 27 EU member states, not just technically advanced electronic signatures, but legally certain qualified signatures.
Is a qualified biometric signature legally equivalent to a handwritten signature? +
Yes. Under eIDAS 2.0, a Qualified Electronic Signature has the same legal effect as a handwritten signature in all EU member states. This is established in Article 25(2) of the eIDAS Regulation and has equivalent legal standing to a handwritten signature under national law across all 27 member states. WeVerify is a eIDAS 2.0 compliant, EU, UK, US & CH, meaning our qualified signatures carry this legal equivalence.
Does WeVerify satisfy WMO benefit fraud prevention requirements? +
Yes. WeVerify is the only provider currently delivering a fully qualified, cryptographically audited WMO verification workflow in the Netherlands, and is live in production at the Municipality of Den Haag. The platform satisfies the legal obligation to verify care recipient identity under the Wet Maatschappelijke Ondersteuning. The same framework is available to all 342 Dutch municipalities without new procurement.
Does WeVerify satisfy EU DSA and UK Online Safety Act age verification requirements? +
WeVerify's age verification product is designed to satisfy the age assurance requirements of the EU Digital Services Act and UK Online Safety Act. The biometric estimation mode provides technically reliable age assurance appropriate for most DSA and OSA obligations. The NFC-verified mode provides the highest level of age certainty for platforms where regulators require maximum assurance. In both cases, no personal data is retained after the check, addressing data protection concerns alongside age assurance obligations.
How does WeVerify handle GDPR for biometric data? +
Biometric data is a special category under GDPR Article 9. WeVerify's architecture ensures that raw biometric data, the selfie image, the NFC chip biometric template, never leaves the user's device and is never stored by WeVerify. We process only cryptographic proofs of the verification result. This means GDPR Article 9 obligations for the controller (your organisation) are dramatically simplified, you are not processing or storing special category biometric data. A DPIA template is available on request.
