Compliance & accountability

Privacy & GDPR — Accountability

CVR processes personal data in the context of vehicle registration, holder/owner, road tax, insurance, inspection and enforcement. Below we account for how we handle this.

Legal basis and purpose limitation

Processing is based on a task in the public interest or performance of a contract (registration, tax, insurance, enforcement). Purpose is defined per function; access to data is limited to what is necessary for the specific purpose (purpose-bound access).

Data minimisation

We only process data necessary for the tasks: identification of vehicle and holder/owner, plate, VIN, insurance and inspection status, and where needed data for enforcement (e.g. caseRef for police lookups). No unnecessary access to policy details (privacy-by-design).

Retention and deletion

Retention periods follow the applicable policy per jurisdiction and requirements for fiscal and administrative accountability. After the retention period, data is deleted or anonymised in accordance with the established retention and deletion policy.

Data subject rights

Data subjects may in principle request access, rectification, restriction or erasure from the competent authority of the relevant island. The platform supports traceability so that such requests can be handled correctly.

Security

Access is verified (authentication) and authorised (role-based). Sensitive data is encrypted where applicable (encryption at rest/transit). See also Security.

← Compliance & accountability Governance & Legal →