12iD documentation

Data protection at 12iD

For: the organisations that issue and verify credentials with 12iD, and their privacy and legal teams. Describes: what personal data 12iD holds, where, for how long, how it is erased, and how it is protected. Every statement here describes how the platform behaves today (revised 2026-10-05). Related: how credentials expire, why they cannot be revoked, and what happens when a user loses their phone: credential-model.md.

Roles

What is stored where

Where What Personal data?
The Indy ledger (public, append-only) Your organisation’s DID, schemas (attribute names), credential definitions None. No attribute value, connection or presentation is ever written to the ledger. That is why the “blockchain versus right to erasure” conflict does not arise.
The user’s phone The wallet: keys, credentials, connections Yes, and it is under the user’s control. Removing the app, or the SDK’s reset(), deletes it.
12iD platform database For each connection, credential exchange and proof exchange: ids, state, dates, your external id; the attribute values offered; the values disclosed; the holder’s label; copies of the webhooks sent to you Yes: attribute values, disclosed values, holder label, webhook bodies
12iD agent (per-organisation encrypted storage) The protocol records of each exchange, with the same attribute and disclosed values Yes
12iD mediator Encrypted messages waiting for a phone to collect them; which wallet connects when Message contents are encrypted end to end and unreadable to 12iD. The mediator sees traffic metadata: which wallet, when, and message sizes. An open app polls every 10 seconds.
Biometric gate (optional) The reference image you send, for the duration of the check only; then scores, decisions and the vendor’s session id Face images: deleted when the check is decided or expires, never logged, never sent in a webhook. Scores and vendor session ids: yes, until erased.

Your external id (the externalId you send with commands) and your wallet ids stay with the records so you can find them. Do not put personal data in externalId; use your own opaque reference.

Retention

Personal data of a finished exchange (state done, abandoned or declined) is kept for the retention period, and then erased automatically:

The default is 90 days. Owners and admins can change it in the console (Data protection). Set 0 to keep the data until you erase it yourself. Exchanges that are still running are never touched.

After erasure the record stays, with its id, state, dates, your external id and whether it was verified. Your lists, dashboards and audit history keep adding up; the record shows Personal data erased with the date. The validity date of an issued credential (its expiresAt) is kept too: it is not personal data, and it drives the “credentials expiring” figures.

Erasing on request

When a user asks you to erase their data, erase it at 12iD from your backend or from the console:

What API Console
One credential exchange POST /v1/credentials/{id}/erase Exchanges → Credential exchanges → Erase
One proof exchange POST /v1/proofs/{id}/erase Exchanges → Proof exchanges → Erase
Everything about one person (their connection with you, and every exchange on it) POST /v1/connections/{id}/erase Exchanges → Connections → Erase

To complete the user’s request, also delete your own copies (the data you received in webhooks and in API responses) and tell the user how to remove the app or reset the wallet.

What erasure does not do

Where the data is hosted

The platform runs on a dedicated server operated by 12iD itself, with no cloud platform in between. The backup machine is at a second site.

Owner, before publishing: state the country (or countries) of the production server and the backup machine. Your customers’ data-processing agreements need it.

Sub-processors:

Security measures

What protects the data described above, in short:

Access by 12iD staff

Biometric checks

If you use the optional biometric gate, face images are special-category data (GDPR Art. 9; BIPA in Illinois).

Backups

If 12iD ever has to restore a database from a backup: