Turkcell signs international B2B contracts with biometric-verified qualified signatures, live on WeVerify. See the Turkcell case β†’

Frequently asked questions.

Everything compliance teams, procurement officers, and technical evaluators ask us before going live.

Identity & technology

What is NFC passport verification and how does it differ from a photo check? +
A photo check compares an image of an ID document against a selfie. A high-quality print, a deepfake video or a forged document carrying a real person's photo can defeat it. NFC verification instead reads a government-signed cryptographic proof straight from the chip in the passport. Only the issuing government's private key can generate that proof, so it cannot be forged. Combined with biometric liveness, a fraudster would need both the physical passport and a synthetic biometric match, which rules out the vast majority of attacks.
Does WeVerify store biometric data? +
No. WeVerify's architecture is built specifically to avoid storing raw biometric data. The NFC chip reading and biometric selfie processing happen on the user's device. WeVerify receives only a cryptographic proof of the result, not the biometric image, not the chip data. This is structural compliance with GDPR Article 9, which governs special category biometric data. It is an architectural decision, not a policy statement.
Which documents are supported? +
WeVerify supports every ICAO 9303-compliant biometric passport issued since 2006, from 190+ countries. It also reads NFC-enabled national ID cards, including EU national IDs and the German Personalausweis, and biometric residence permits from EU member states and the UK. The document list grows continuously, and we can confirm coverage for your countries during a demo.
Does the user need to download an app? +
For identity verification, yes. Reading the NFC chip in a passport or ID card requires the WeVerify Identity Wallet app, free for iOS and Android. The app doubles as a reusable identity wallet: verify once, then reuse that verified identity across other services without repeating the check. Age estimation is the exception. It runs entirely in the browser, with no app, no account and no document.
How long does verification take? +
A full identity verification, NFC chip reading, biometric liveness, and face match, completes in under 5 minutes for most users. NFC chip reading itself takes under 3 seconds. The biometric selfie and liveness check take under 4 seconds. The total flow from link opening to result is typically 2–4 minutes. The WeVerify platform processes 99.9% of verifications automatically without manual review.

Legal & compliance

What is a Qualified Trust Service Provider (QTSP)? +
A Qualified Trust Service Provider holds qualified status granted by a member state supervisory authority under eIDAS 2.0. WeVerify is an eIDAS 2.0 compliant trust service and appears on the EU Trusted List. Its qualified signatures and seals therefore carry the same legal force as a handwritten signature in all 27 EU member states, not merely an advanced electronic signature.
Is a qualified biometric signature legally equivalent to a handwritten signature? +
Yes. Under eIDAS 2.0, a Qualified Electronic Signature has the same legal effect as a handwritten signature in all EU member states. This is established in Article 25(2) of the eIDAS Regulation and has equivalent legal standing to a handwritten signature under national law across all 27 member states. WeVerify is a eIDAS 2.0 compliant, EU, UK, US & CH, meaning our qualified signatures carry this legal equivalence.
Does WeVerify satisfy WMO benefit fraud prevention requirements? +
Yes. WeVerify is currently the only provider delivering a fully qualified, cryptographically audited WMO verification workflow in the Netherlands. At the Municipality of Den Haag the application is live and rollout is underway. The platform meets the legal obligation to verify a care recipient's identity under the Wet Maatschappelijke Ondersteuning. The same framework is open to all 342 Dutch municipalities without new procurement.
Does WeVerify satisfy EU DSA and UK Online Safety Act age verification requirements? +
WeVerify's age verification product is designed to satisfy the age assurance requirements of the EU Digital Services Act and UK Online Safety Act. The biometric estimation mode provides technically reliable age assurance appropriate for most DSA and OSA obligations. The NFC-verified mode provides the highest level of age certainty for platforms where regulators require maximum assurance. In both cases, no personal data is retained after the check, addressing data protection concerns alongside age assurance obligations.
How does WeVerify handle GDPR for biometric data? +
Biometric data is a special category under GDPR Article 9. WeVerify's architecture ensures that raw biometric data, the selfie image, the NFC chip biometric template, never leaves the user's device and is never stored by WeVerify. We process only cryptographic proofs of the verification result. This means GDPR Article 9 obligations for the controller (your organisation) are dramatically simplified, you are not processing or storing special category biometric data. A DPIA template is available on request.

More questions? Talk to us.