Openprofile
FeaturesHow It WorksUse CasesCompliance

Compliance Guide

How to use Openprofile responsibly and in compliance with data protection regulations.

This guide helps you understand the regulatory landscape for digital identity intelligence and how Openprofile is designed to support your compliance obligations.

Understanding the Legal Framework

Public Data vs. Personal Data

Openprofile exclusively processes publicly available information. However, even public data may constitute "personal data" under regulations like GDPR if it relates to an identifiable individual. This means:

  • You need a lawful basis to process this data
  • Data subjects have rights regarding their information
  • Appropriate safeguards must be in place

Your Role vs. Openprofile's Role

Your OrganizationOpenprofile
Data ControllerData Processor
Determines purpose of searchesProcesses data per your instructions
Responsible for lawful basisProvides compliant infrastructure
Handles data subject requestsAssists with fulfilling requests

GDPR Compliance

Lawful Basis for Processing

Under GDPR, you must have a lawful basis to process personal data. Common bases for Openprofile use cases include:

Legitimate Interests (Article 6(1)(f))

Most commonly applicable for:

  • Fraud prevention: Detecting and preventing fraudulent activity
  • Due diligence: Assessing business relationships and risks
  • Security: Protecting your organization from threats

Important: You must conduct a Legitimate Interests Assessment (LIA) and document your balancing test against individual rights.

Contract Performance (Article 6(1)(b))

May apply when:

  • Background checks are part of employment contracts
  • Identity verification is required for service delivery
  • Due diligence is contractually mandated

Legal Obligation (Article 6(1)(c))

Applicable for:

  • KYC/AML requirements in financial services
  • Regulatory background check mandates
  • Anti-money laundering compliance

Data Subject Rights

Individuals have rights regarding their data. Here's how to handle common requests:

RightYour ResponseOpenprofile Support
AccessProvide copy of data heldExport function available
ErasureDelete if no lawful basis to retainDeletion requests honored
RectificationCorrect inaccurate dataReport inaccuracies to us
ObjectionCease processing unless compelling groundsAccount-level blocking available

CCPA Compliance

California Consumer Rights

For California residents, additional rights apply:

  • Right to Know: What personal information is collected and how it's used
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: Prevent sale of personal information
  • Right to Non-Discrimination: Equal service regardless of privacy choices

Note: Openprofile does not sell personal information. We are a service provider under CCPA, processing data only as directed by our customers.

Industry-Specific Considerations

Financial Services (KYC/AML)

If you're using Openprofile for KYC or AML purposes:

  • Document your risk-based approach
  • Maintain records of identity verification steps
  • Use our audit logs for compliance documentation
  • Combine with official identity verification where required

Human Resources

When screening candidates or employees:

  • Obtain consent where required by local law
  • Provide adverse action notices if decisions are made based on findings
  • Ensure consistency in screening processes
  • Don't use for FCRA-regulated decisions (US credit, housing, insurance)

Investigations

For fraud or security investigations:

  • Document the legitimate interest justification
  • Maintain proportionality in scope of investigation
  • Secure findings appropriately
  • Limit access to need-to-know personnel

Best Practices

Documentation

Maintain records of:

  • Your lawful basis for each use case
  • Legitimate interests assessments
  • Data subject requests and responses
  • Data retention decisions

Data Minimization

  • Only search for information you genuinely need
  • Use our retention controls to auto-delete results
  • Don't store data longer than necessary
  • Limit who can access search results

Transparency

  • Include Openprofile usage in your privacy notices where appropriate
  • Be prepared to explain your screening processes
  • Respond promptly to data subject inquiries

Openprofile Compliance Features

We provide several features to support your compliance:

  • Audit Logs: Complete record of all searches and exports
  • Auto-Deletion: Configurable retention periods
  • Access Controls: Role-based permissions
  • Export Tools: Respond to data subject requests
  • DPA: Standard data processing agreement
  • EU Hosting: Data residency in European Union

Need Help?

For compliance questions or to request documentation:

  • 📧 Compliance Team: compliance@openprofile.io
  • 📋 DPA Requests: legal@openprofile.io

Disclaimer: This guide is for informational purposes only and does not constitute legal advice. Consult with qualified legal counsel for advice specific to your situation and jurisdiction.

Openprofile

Search 750+ platforms in seconds. The identity intelligence layer for the modern internet.

Product

  • Features
  • How It Works
  • Use Cases
  • API DocsSoon
  • PricingSoon

Company

  • About
  • Contact
  • CareersHiring
  • Status

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Security

Resources

  • BlogSoon
  • Changelog
  • Compliance Guide
  • OSINT Guide

© 2025 Openprofile Technologies. All rights reserved.

All Systems Operational