How to meet express consent requirements before calling POST /v1/verify
You must collect an individual's express consent before verifying their identity through the Document Verification Service (DVS). This applies to all DVS business users, including VeroID developer and dashboard customers.
The IVS Framework Administrator publishes up-to-date guidance for users of identity verification services. Use these resources when designing consent flows and privacy notices for your end users:
Every verification request must include consentAttestedAt (ISO 8601 datetime when the subject gave consent) and consentVersion (version of the privacy disclosure you showed them). See API Reference and your participation agreement with VeroID for contractual requirements.
Individuals whose identity you verify may refer to veroid.com.au/consent for general information about how verification requests are handled. Your business remains responsible for the consent notice and privacy information you provide at the point of collection.