Mobile-ID / Certificates & scope
RAR/C06 · eID / SSO / ShareInfoISO/IEC 24745:2022
Phase 7 publication editionPOL-ACCEPTABLE-USE

Acceptable use

Limit biometric identity use by purpose, authority and user rights.

Full public textOrganization/contract scoped

This is the full text published in the Phase 7 package. Effective dates, responsible contacts and contract-specific parameters are maintained in the corresponding release and deployment records.

01

Permitted purposes

The relying organization deploys only purposes identified in the service record with appropriate processing authority. Applications, devices and accounts are scoped to an organization, workflow and permissions. Possessing an API account or enrolled reference does not authorize every use.

02

Correct-person enrollment

Do not enroll another person's palm under a verified identity, borrow a session, alter proofing results or bypass participant continuity checks. Suspected duplication or impersonation requires authorized review. Do not merge patient, student or employee records merely because matching results are similar.

03

Out-of-scope activity

Do not use the system for cross-organization tracking, out-of-scope searches, secret harvesting, reference commercialization or unapproved retraining. Do not bypass limits, impersonate devices, use compromised credentials or conduct unauthorized attack testing. Explain these restrictions to integrators and operators.

04

Rights and alternatives

Biometric failure must not automatically deny emergency care or essential services. The organization provides suitable alternatives and handles misidentification disputes. People unable to present a palm, children and represented individuals follow appropriate pathways rather than being labeled fraudulent merely because matching fails.

05

Accounts, devices and data

Users protect access information and report compromise or misuse through published channels. Connect only devices and software covered by the approved profile. Website examples and simulations must not receive real personal data, and operational records must not be exported to personal machines or unapproved tools.

06

Authorized enforcement

On suspected misuse, record the event, scope and minimal evidence for authorized assessment. Restrictions on accounts, devices or purposes are proportionate to risk and agreement, with user-rights safeguards. Do not erase all data or lock an organization without an appropriate decision, except for pre-authorized emergency controls.

07

Review, restoration and termination

Affected parties receive an explanation/review route under the approved process. Restoration confirms that the cause is addressed, authority remains valid and additional controls are complete. Termination follows retention and evidence policies; it does not create an unlimited right to keep or reuse biometric references.

Responsibility & deployment annex

Detailed responsibilities are determined by activity and deployment records; this public document does not replace customer-specific contractual annexes.

  • The relying organization defines business purposes, populations and operational authority within the deployment.
  • Mobile-ID supplies and operates components within the agreed scope, including integration, control configuration and related evidence.
  • Device suppliers support models, firmware, SDKs and maintenance within authorization; data access is never implicit.
  • Legal, security and service ownership assignments are maintained in each organization’s operating records.

Execution and evidence cycle

  1. Record purpose, organization, data/device scope and the business reference.
  2. Verify authority, applicable conditions, configuration and relevant obligations.
  3. Execute with data minimization, authorization and necessary evidence.
  4. Close with confirmations from relevant systems, response handling and remaining exceptions.

Legal and reference sources

Detailed obligations, periods and exceptions apply according to law, contract and the actual service configuration.

Contact about applicability

Send contact details and a general question only; sensitive records require a confirmed channel.

info@mobile-id.vn

Search Trusted Palm ID

Selected interface