Data sources, security & compliance

Where BrokPass gets its data, how we handle it, and the limits we set for ourselves. Written for compliance, procurement and data-protection reviewers.

BrokPass is not the official register

BrokPass is an independent verification service. It is not operated, endorsed or approved by any supervisory authority, and it is not affiliated with ORIAS, FSMA, AFM or CBI. We reflect the official registers; we do not replace them. For a legally authoritative confirmation, always consult the official register directly (linked in the table below and on every verification result).

Where the data comes from

Every record originates from an official or public register source. Real-time means the official register is queried live per request; the other sources are the register's own public open data, synced on the cadence shown, then normalized into one schema.

RegisterSupervisory authoritySource typeUpdate frequencyOfficial link
ORIASFranceORIAS — Organisme pour le Registre unique des Intermédiaires en Assurance, Banque et FinanceOfficial register, queried livereal-timeRegister
FSMABelgiumFSMA — Financial Services and Markets Authority (Belgium)Official public open data, syncedupdated weeklyRegister
AFMNetherlandsAFM — Netherlands Authority for the Financial Markets (Autoriteit Financiële Markten)Official public open data, syncedupdated dailyRegister
CBIIrelandCentral Bank of Ireland (CBI)Official public open data, syncedupdated dailyRegister

What we do — and do not — do with register data

BrokPass normalizes official register data into one schema so a record from FSMA looks the same as a record from ORIAS, AFM or CBI to your systems. That normalization — plus id auto-detection, change detection and monitoring — is the service.

We do not resell raw register lists. BrokPass is not a bulk data broker: you verify or monitor specific intermediaries and receive normalized records and change events, not a downloadable copy of a national register.

Data protection (GDPR)

What is processed

A verification query processes a business identifier — a SIREN or ORIAS number, a BCE/KBO number, a KvK number or a CBI C-number — and returns the public register data about the corresponding regulated professional (registration status, categories and the other fields the register publishes). This is public, professional-context information, not special-category data.

Lawful basis

Processing rests on legitimate interest (Article 6(1)(f) GDPR): verifying that an insurance or finance intermediary is authorised — a legitimate interest of the business relying on that professional and, under the IDD, often a regulatory expectation. The data concerns professionals in a public register, kept to what verification requires.

Data-subject rights

Requests from data subjects (access, rectification, objection and the other GDPR rights) are handled per our privacy policy. To exercise a right, contact gdpr@yet.lu.

Security posture

Encrypted in transit

All traffic to the site and API is served over HTTPS/TLS. Verification requests and responses are encrypted end to end.

EU-hosted

The service runs on European infrastructure, and register data stays within EU-hosted systems.

Least data

We process the identifier needed to run a check and the public register data it returns — no more than verification and monitoring require.

We do not claim certifications we do not hold. If your procurement process needs a specific security questionnaire or data-processing agreement, contact us and we will work through it.

Compliance or procurement questions?

For due diligence, a DPA, a security questionnaire or vendor onboarding, write to assurtech@yet.lu. For data-subject requests, contact gdpr@yet.lu.