GDPR
FaceSign operates as a data processor under the General Data Protection Regulation. Your organization is the data controller.Biometric data is classified as special category data under GDPR Article 9. Your organization must establish a lawful basis for processing special category data (typically explicit consent or substantial public interest) before initiating verification sessions.
CCPA
FaceSign operates as a service provider under the California Consumer Privacy Act and CPRA amendments.BIPA
The Illinois Biometric Information Privacy Act imposes specific requirements on the collection, storage, and use of biometric identifiers.SOC 2 Type II
FaceSign is pursuing SOC 2 Type II certification.ISO 27001
FaceSign is built to ISO 27001 security standards following secure-by-design and privacy-by-design principles.PSD3 Strong Customer Authentication
The revised Payment Services Directive (PSD3) introduces stricter requirements for Strong Customer Authentication (SCA) and shifts liability for coached transfer fraud to payment service providers.Coercion detection as a PSD3 compliance tool
Under PSD3, a payment provider that processes a coached transfer may be liable for the loss. Traditional SCA (OTP + password) cannot detect coaching. FaceSign’s coercion detection creates an auditable record that the user was — or was not — acting freely at the moment of authorization. This gives providers:- Evidence of due diligence — The provider took steps beyond standard SCA to verify the user’s state of mind
- A decision point — High coercion risk scores can trigger manual review or transaction hold before funds are released
- Regulatory documentation — Timestamped, structured data suitable for regulator requests
Available documentation
Next steps
Security Architecture
Technical details on encryption, HSM tokenization, and data flow.
Biometric Data Handling
Retention periods, deletion rights, and data subject access.
Coercion Detection
How FaceSign detects duress and supports PSD3 compliance.