NBU allows private entrepreneurs to be users of BankID System
The National Bank of Ukraine has updated the Regulation on the NBU BankID System to bring its norms in line with the requirements of the Law of Ukraine "On Electronic Identification and Electronic Trust Services" and Regulation (EU) No. 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market.
This is stated in the report of the NBU, the Ukrainian News agency reports.
Normative regulation of the elements inherent in electronic identification schemes in the NBU BankID System will help to strengthen the reliability, security and expansion of the use of this system, as well as its future registration as an electronic identification scheme with an average (substantial) level of trust.
In particular, the updated Regulation:
- introduced the term "electronic identification service of the NBU BankID System" and regulated the procedure for its provision;
- provided a requirement for the existence of an open user account with the subscriber-identifier and an agreement concluded between them, which contains the terms of providing the electronic identification service, as well as information about its cost (in the case of setting a tariff by the subscriber-identifier);
- expanded the obligations of the identifier subscriber to post information about the service on the website; permanent storage of documents and electronic data obtained during the identification/verification of the user for the provision of the service; informing the user and the National Bank of violations of confidentiality and/or integrity of information affecting the provision of electronic identification services to the user;
- set requirements for subscribers-identifiers in terms of cyber and information security, namely, to implement an information security management system for the processes that ensure the functioning/use of the NBU BankID System in accordance with ISO/IEC27001:2022; to conduct an annual penetration test;
- in order to strengthen the protection of personal data of the user, the requirement to use dynamic multi-factor authentication by the subscriber-identifier was introduced.
In addition, the amendments to the Regulations include:
- the opportunity to use the NBU BankID System has been provided to individual entrepreneurs as users;
- the right of public law educational institutions to use the system on non-commercial terms to perform their functions has been regulated.
Subscribers-identifiers are obliged to bring their activities into line with the new requirements of the Regulation by June 30, 2026.
As the Ukrainian News agency earlier reported, the NBU BankID System is a national system of remote electronic identification and verification of users through banks, which allows users to confirm their identity electronically and receive public, financial and other services remotely.