Codility identity verification: data handling reference

Identity verification_

How Codility’s identity verification works, what it captures, where that data lives, and how long it is kept. Written for security and compliance reviewers evaluating Codility.

Document type
Data handling reference
Audience
Security and compliance reviewers
Scope
Codility Integrity: identity verification

Summary

The short answer, before the detail below.

Codility’s identity verification runs on a dedicated verification partner’s platform. The partner captures the ID document image, performs the face match, and holds the identity fields. Codility receives the verification result only: a pass or fail status, with a reason when a candidate does not pass. No ID images, biometric templates, or identity field data are transmitted to or stored on Codility’s infrastructure.

What is captured

Two different parties hold two different sets of data. The table below separates what the verification partner captures from what Codility receives.

Data captured, by party
Data element Held by Detail
ID document image Partner An image of the candidate’s ID document, captured during verification.
Face match Partner A biometric match of the candidate’s face against the ID document photo.
Identity fields Partner Standard ID fields: name, date of birth, document number, expiration date, and country of issue.
Verification result Codility A pass or fail status. When a candidate does not pass, a description of why is included.

Codility does not receive or store the ID image, the biometric face match, or the identity field data at any point in this flow.

How verification works

Three steps, all driven by the candidate, with the same data flow every time.

  1. Notified

    The candidate is introduced to the verification step in the default invitation email and on a dedicated intro page before the assessment. The page lists what the candidate needs, the available verification options, and links to the verification partner’s terms of service.

  2. Verified

    The candidate completes verification on the partner’s platform, using one of three paths: a QR code or a text-message link to verify on mobile, or a link to verify inside the desktop assessment environment. Verification is automated by default. The face match and document check are performed by the partner’s system, not by a live proctor.

  3. Result returned

    Codility receives the verification result. The ID image, the face match, and the identity fields remain on the verification partner’s infrastructure and are not passed to Codility.

Sub-processor model

The identity verification partner operates as a sub-processor under a standard sub-processor agreement. Codility does not operate the verification step directly. The partner runs the document check and face match, and Codility receives only the result.

Where data is processed and stored

Processing location and storage location, by data element.

ID image, face match, identity fields
Processed and stored on the identity verification partner’s infrastructure. Not transmitted to Codility at any point.
Verification result
Stored on Codility’s infrastructure as a pass or fail status, with a reason recorded on failure.

The source material reviewed for this document does not name the verification partner or specify the partner’s data hosting region. If your review requires a named sub-processor and its processing region, request the current sub-processor list from your Codility account team.

How long data is retained

Default retention at the verification partner, and how it can be changed.

Default retention schedule
Stage Window What happens
Review 90 days Data is available for review at the verification partner.
Archive 3 years Data moves to archive at the verification partner following the review window.
Deletion After archive Data is permanently deleted following the archive period.

Retention is customizable. The verification partner can be instructed to align retention with your organization’s data policy, including shorter review and archive windows, through the standard sub-processor agreement.

The 90-day review and 3-year archive figures are carried forward from Codility’s April 2026 product one-pager on identity verification. This reference does not have a more recent source to re-verify those figures against. Confirm current retention defaults with your Codility account team before citing them in a signed security questionnaire response.

Who data is shared with

Parties in the identity verification flow.

Identity verification partner
Sub-processor. Captures the ID image, performs the face match, and holds identity fields. Operates independently of Codility’s infrastructure.
Codility
Receives the verification result only. Does not receive or store ID images, biometric templates, or identity field data.

No other party receives identity verification data as part of this flow.

Compliance credentials

Credentials that apply to Codility as a platform. Identity verification data itself is governed primarily by the verification partner’s sub-processor agreement.

  • SOC 2 Audited.
  • ISO 27001 Certified.
  • GDPR Compliant. A Data Protection Impact Assessment is available on request.
  • CCPA Compliant.

Requesting more detail

What a reviewer can ask for beyond this document.

  • Data Protection Impact Assessment Available on request through your Codility account team.
  • Sub-processor list Request the current list, including the named identity verification partner and its processing region.
  • Custom retention terms Ask your account team to align verification partner retention with your organization’s data policy.
  • Security questionnaire responses Your Codility account team can provide a completed standard questionnaire or respond to a custom one.