Privacy policy for BankID
Applies to BankID, services in the BankID app and our webpages.
Version 3.2, 18.08.2026
The BankID app is downloaded to your iOS phone from the App Store or Android phone from Google Play, and you can use services available in the app more quickly and easily.
See also www.bankid.no/en for help using the BankID app.
Services in BankID app
With the BankID app you can
- use BankID services to verify your identity, sign something, log in to a service, or confirm a payment. The BankID app can replace your BankID code device, but you can also still use the code device
- use the BankID Signing service (qualified signing) to sign documents with a qualified signature
- use the ID Check service to digitally verify your identity using your passport or national ID card if you have been asked to do so
- use the ID Card service in the BankID app to confirm your name and age in physical situations at merchants
- use the Data Sharing service, which allows you to share data with merchants
A prerequisite for activating BankID services and ID Card in the BankID app is that you have already been issued a BankID.
Services with BankID code device
With the BankID code device, you can
- perform BankID services to verify your identity, sign something, log in to a service, or confirm a payment. The BankID code device can be replaced by the BankID app, but you can also continue using the code device.
Data controller
Stø AS, org. nr. 927 611 929, is the data controller when you use BankID and the BankID app for BankID services, ID card, BankID Signing Certificate (qualified signing), ID Check, ID Card and Data Sharing. For the ID check service other parties may also be data controllers, such as banks or other merchants that need to verify your identity. Stø AS is the data processor on behalf of the data controllers in these cases.
What personal data do we process?
When using BankID services:
- name, national identity number or D-number, nationality, telephone number and ID document presented when issuing your BankID
- name of the issuer of your BankID
- unique identifier for identification of you and your BankID
- time of issuance, revocation and other changes in your BankID certificate
- your BankID's validity period and status
- transaction history (merchant name, time, transaction type, and transaction category)
Your national identity number or D-number may be disclosed from the BankID service to merchants that have a legal basis in law, regulations or decisions adopted pursuant to law, and that are subject to a regulatory obligation to collect and process your national identity number or D-number in connection with the merchant’s establishment of a customer relationship or the merchant’s provision of customer services to the end user.
When using the BankID signing service (qualified signing):
- Qualified Signature Certificate
- certificate holder's name, nationality, date of birth, national identity number or D-number, IP address, language preference, location data, browser information
- document potentially containing personal data (temporary storage during signing)
- PID (unique identification number of the certificate holder)
- OrderID (unique identification number on specific certificate)
- name of the merchant (in case the merchant is a sole proprietorship)
- timestamping
When using the service ID Check:
- personal data read from the machine-readable zone (MRZ) of the passport/ID card and from the chip (name, date of birth, nationality, document number, document type and expiry date)
- face photo taken when you take a photo of the "photo page" of the passport/ID card
- facial image (selfie) taken with your smartphone (during visual identification)
- ethnicity (to prevent discrimination)
- login session information
When using the service ID Card in the BankID app:
- personal data read from the machine-readable zone (MRZ) of the passport/ID card and from the chip (name, date of birth, nationality, document number, document type and expiry date)
- face photo taken when you take a photo of the "photo page" of the passport/ID card
- transaction history (name of merchant, time, what information was provided)
When using the service Data sharing:
- telephone number
- national identity number
Digital behavioural information (for all services in BankID and the BankID app):
Information about your digital devices, user environment (incl. IP address) and usage behaviour is used for transaction monitoring, fraud prevention, fraud detection and management of security incidents.
Purposes
Stø AS processes personal data in order for you to use BankID and the BankID app for services that are available in the BankID app. See which services (purposes) are available in the sections “Services in BankID app” and “Services with BankID code device”, in addition to Terms of use of BankID-app. In addition, your personal data is used for billing, error correction, transaction monitoring, fraud prevention, detection and handling of security incidents, for reporting statistics, marketing and improvement of the services.
The facial images processed in the ID Check service are used to verify you as a legitimate user. Implicitly, the facial images are also used for fraud detection, minimizing biases, and other improvements to the solution.
Where is your information obtained from?
From you – the personal data processed about you will mainly be obtained from you as the user of the services, in connection with the issuance of the services and from your devices when you use the services.
From third parties – in order to offer you services and comply with legal requirements, information will also be obtained from third parties. For example, in connection with identifying you when issuing BankID, information will be obtained from the Population Register, and when using the services, information will be collected from merchants (such as websites, online stores, or similar).
Legal basis for processing
The processing of your personal data takes place on the legal basis of
- terms of use from Stø AS for BankID-services, for services in BankID-app, and BankID Signing (qualified signature)
- consent for ID check
- consent for personal marketing on social media and
- legal obligation or legitimate interest when Stø AS processes personal data to handle security incidents and to prevent fraud.
Use of sub-contractors and disclosure to third parties
Data processors (such as bank or IT service providers) may be used to process personal data on our behalf. In such cases, an agreement will be entered into with the data processors to ensure that the processing of the information is in accordance with the privacy regulations and other requirements for the processing of personal data. This applies regardless of whether the data processors in Norway or in other countries within the EEA/EU area or outside the EEA/EU are used. The use of data processors is not to be regarded as a disclosure of personal data.
For transfers to countries outside the EU/EEA, a valid transfer basis is required, and the following conditions must be met:
- the EU Commission has decided that an adequate level of protection exists in the country concerned
- other adequate safeguards have been put in place and/or the sub-contractor has provided the necessary guarantees that the personal data will be processed in a secure manner, for example through the use of standard contractual clauses (EU standard clauses) approved by the EU Commission or the sub-contractor has valid Binding Corporate Rules (BCRs)
- when it comes to exceptions in special cases, for example to fulfil an agreement with you or cases where you give your consent to the specific transfer
In addition, personal data may be disclosed to public authorities, merchants or other third parties if there is a legal basis for doing so.
Retention
Personal data will not be stored longer than is necessary to fulfil the purpose of the processing. After this, the information will be deleted or anonymized, unless the information shall be stored beyond this due to a legal requirement.
Information about your BankID transactions will be stored in accordance with retention routines for individual elements of the BankID services, for a maximum of 14 years.
Personal data in BankID Signing service (qualified signature) is stored for 7 years.
Personal data processed in ID Check is automatically deleted after 30 days.
Personal data processed in ID Card in the BankID app is automatically deleted if the service has not been used for one year or when the ID document expires.
Personal data (such as e-mail) which you provided to the service Data Sharing is stored at Stø AS as long as you are a BankID user.
Cookies and privacy on our websites
A cookie is a small text file that is downloaded and stored on your device, such as a phone or computer, when you open the BankID application or use BankID on a website.
When using BankID with a code device on websites and in the BankID app, necessary cookies are used for basic functionality and security purposes. These cannot be disabled.
Stø AS uses Vercel Web Analytics to analyse the use of the websites Bankid.no and Stoe.no. This solution stores only anonymised data and does not use cookies for data collection.
For other use of cookies, for example for personalised marketing purposes, we will first obtain your consent.
It is entirely possible to visit our websites without having to provide any information about yourself. It is only when you want to submit enquiries through a form that we need information in order to provide the service you request.
You can change your cookie settings yourself by clicking the cookie icon in the lower-left corner of the websites.
Your rights
Information about the processing of information about you must be clear and easily accessible so that you can gain a good understanding of how we process the information.
If the information we have about you is incorrect, you may request that the information be corrected, supplemented or deleted.
You have the right to request restriction of processing and may, under certain conditions, object to further processing of personal data or request that your personal data be transferred to yourself or another data controller (data portability).
Personal data processed on the basis of your consent will be deleted when you withdraw your consent, unless there is a legal basis for further retention.
You have the right to request access to the personal data we process about you.
Contact us
If you have any questions for us about the above services, you can contact our customer service. Please therefore contact your bank through the bank’s own customer service channels. Stø AS has an agreement with the banks regarding customer service.
Guidance on activating and using ID Card in the BankID app is available at
If you have further questions regarding ID Card in the BankID app, customer service for the service is provided by Kredinor AS at telephone number 23118255.
Complaints
If you believe that your personal data has been processed in violation of data protection laws, you can contact the bank or complain to the Norwegian Data Protection Authority ("Datatilsynet"). You will find contact information here: www.datatilsynet.no
Other
The text in this privacy statement may be updated. The latest version is always available via BankID app.
Document information | |
|---|---|
Valid from | 16. august 2023 |
Versjon | 3.0 |
Review | Yearly |
Approver | CFO |
Document owner | PVO |
Version history | |||
|---|---|---|---|
Date | Version | Description | Author |
5.11.2025 | 2.2 | Review, added document information | privacy advisor |
12.01.2026 | 3.0 | Update to Stø AS as a new issuer | DPO |
24.02.2026 | 3.1 | Update text to BankID code device users | DPO |
18.08.2026 | 3.2 | Review with updates concerning, among other things, data controllership and contact information, as well as reformatting. | DPO and privacy advisor |