Trust Framework Addendum
Version 2.0 — 10th August 2026.
This Addendum applies to Mistho partners and customers who use Mistho’s services in the context of the UK digital verification services (DVS) trust framework (the “Framework”). It is Appendix 3 to the Mistho Partner Agreement (the “Agreement”), forms part of it, and is binding on all relying parties consuming attributes provided by Mistho under the Framework.
Mistho is certified under the Framework as an Attribute Service Provider, and is listed on the register of digital identity and attribute services maintained on GOV.UK (provider ID 9; service ID 206). Mistho’s certification is issued by an approved conformity assessment body.
This Addendum supplements, and does not reduce, the parties’ obligations under the Agreement, including its data protection obligations and the Data Processing Agreement. Where it conflicts with the remainder of the Agreement in relation to Framework matters, this Addendum prevails to the extent of that subject matter.
Purpose
Under the UK digital verification services (DVS) trust framework, attribute service providers are required to ensure that their relying parties comply with the same core trust, privacy, and inclusion principles.
This Addendum sets out those obligations, and the commitments Mistho gives in return. It is an exchange of obligations between both parties, not a one-way set of requirements: what Mistho commits to is in Part 1, and what you must do as a relying party is in Part 2.
The requirements in Part 2 are not unique to Mistho: they reflect obligations that already apply to relying parties under UK GDPR, data protection law, and general consumer protection regulation. This Addendum makes those obligations explicit and ensures consistency across all parties participating in the Framework.
Terms used on this page
- Attribute — a piece of information about an end-user (such as employment or income information) provided by Mistho as part of the services.
- Assurance Information — the metadata provided by Mistho with an attribute indicating its provenance and source, the binding between the attribute and the end-user, its freshness (when retrieved and, where the source provides it, when the underlying record was last updated) and quality indicators.
- Relying Party — an organisation that receives and relies on attributes. As a Mistho customer, you are a relying party.
- Trust Mark — any certification mark or trust mark associated with the Framework, including the UK CertifID trust mark.
- OfDIA — the Office for Digital Identities and Attributes, or any successor body responsible for the Framework. CAB — the accredited conformity assessment body certifying Mistho (currently Kantara).
Part 1 — What Mistho commits to
Certification and assurance
- 3.1 Mistho holds, and will use reasonable endeavours to maintain, certification as an Attribute Service Provider under the Framework for the certified services.
- 3.2 Mistho will provide attributes together with Assurance Information — provenance and source, binding, freshness, and quality indicators — in accordance with the Framework.
- 3.3 Mistho will operate a complaints and incident-handling procedure consistent with the Framework, and will make it available to you and to end-users.
- 3.4 Mistho will notify you without undue delay if its certification is suspended, withdrawn or materially changed, or if a change to the Framework materially affects the services or the obligations in this Addendum.
Failures and interruptions in the services
- 3.5 Mistho will notify you of any failure or interruption in the services that could reasonably be expected to affect your use of the services and, where you hold your own certification under the Framework, your certified service or your certification status. Mistho will provide such information as you reasonably require to manage that risk. This applies to all customers, whether or not you hold certification. Notice is given in accordance with the service level terms at Appendix 1 (Service Level Agreement) to the Agreement; this obligation states no separate notification deadline and does not vary those terms.
- 3.6 Mistho states the position on its supply chain plainly, rather than implying greater resilience than it has. Delivery of the services depends on third parties which Mistho does not control: the authoritative sources from which attributes are retrieved and, for certain retrieval routes, a supplier through whom access to those sources is obtained. Mistho holds no service level in respect of any of them. Mistho will use reasonable endeavours to support you in managing the consequences of any failure or interruption arising from these dependencies, including by routing to an alternative retrieval route where one is available, by giving notice under 3.5, and by providing the information described in 3.7.
- 3.7 On your request following a failure or interruption in the services, Mistho will provide you, within 10 working days of the request:
- a written summary of the incident covering its cause, duration, scope of impact and corrective action;
- confirmation of the incident window, the retrieval routes affected, and whether the quality of attributes was implicated;
- confirmation of whether any attribute shared with you during that window is affected and, if so, which transactions; and
- confirmation of the corrective action taken and its status.
Where a request would require Mistho to disclose another customer’s data or information that is confidential, Mistho will state what is being withheld and why, rather than declining silently. This applies to all customers, whether or not you hold certification.
Attribute quality and recency
- 5.3 Agreed position on attribute quality. Mistho expresses the quality of each attribute it shares through the Assurance Information accompanying that attribute, which records accuracy, integrity, binding and matching, together with the provenance and authenticator basis for each. The parties agree that this constitutes the agreed position on the quality requirements Mistho will meet in respect of the attributes it shares with you. The current specification of the Assurance Information, including the quality indicators emitted and their meaning, is published in Mistho’s technical documentation and API specification. You may retrieve the current position at any time, and are responsible for referring to it when determining how to rely on an attribute.
- 5.4 Agreed position on recency. Mistho expresses the recency of each attribute through the timestamp at which it was retrieved from the authoritative source and, where the source provides it, a per-record indication of when the underlying record was last updated. Mistho does not apply a freshness threshold on your behalf. You agree that you will determine and apply your own recency requirements to the attributes you receive, using the information supplied. The parties agree that this constitutes the agreed position on how recently attributes will have been checked when shared.
Part 2 — What you must do as a relying party
Under clause 4 of the Addendum, you shall:
Data use and retention
- 4(a) use attributes and the services only for the purposes permitted under the Agreement and in accordance with applicable law, and not in any way that would cause Mistho to breach the Framework or its certification. You may only use attributes provided by Mistho for the specific purpose for which the individual has given consent, and may not repurpose attribute data for profiling, marketing, or other unrelated purposes.
- 4(e) implement appropriate technical and organisational measures to protect the attributes you receive, retain them only for as long as necessary, and comply with data protection legislation as controller for your own processing. You must securely delete attribute data in accordance with the Framework’s requirements, and for data subject access requests, corrections, or deletions you must work with Mistho to ensure these are addressed promptly.
Transparency, complaints and identity repair
- 4(b) before initiating a verification, provide end-users with clear and accurate information about the process and about how their data will be used, obtain any consent required, present the verification flow fairly (without deceptive or manipulative design), and honour an end-user’s decision to decline or withdraw.
- 4(h) handle and, where appropriate, escalate complaints relating to a verification, and signpost end-users to Mistho’s complaints procedure and, ultimately, to the Information Commissioner’s Office or other relevant body. If a complaint involves data collected or shared via Mistho, you must cooperate with Mistho in resolving the matter. You must also cooperate with Mistho in addressing identity repair requests. Where Mistho facilitates communication with you and an end-user about suspected identity misuse, you must engage promptly and take reasonable steps to support resolution.
Reliance on attributes and use of the Trust Mark
- 4(c) take account of the Assurance Information provided with each attribute in your own risk and decisioning processes, and not rely on an attribute beyond its stated assurance.
- 4(d) not state or imply that you are yourself certified under the Framework by reason of using the services, and use any Trust Mark only as, and to the extent, expressly permitted by Mistho or OfDIA.
- 5.1 You acknowledge that attributes are provided with Assurance Information, and that the appropriate use of an attribute depends on that information (including its source, binding level and freshness).
- 5.2 You are responsible for your own decisions made in reliance on attributes, consistent with the warranties and data protection provisions of the Agreement.
Fraud and security
- 4(f) promptly report to Mistho any suspected fraud, misuse, compromise or security incident affecting the services or attributes, and reasonably cooperate with Mistho and, where required, the CAB or OfDIA. You must maintain processes to identify and respond to potential fraud or misuse of attribute data, and cooperate with Mistho and relevant authorities in fraud investigations as required under the Framework.
Accessibility and inclusion
- 4(g) where you control the user interface of the verification journey, take reasonable steps to make it accessible and inclusive by following at least WCAG 2.2 AA or EN 301 549 standards, and to provide, or refer end-users to, an assisted or non-digital route where one is required.
- Where an end-user is unable to complete a verification through Mistho after retries, you are responsible for offering an alternative verification route (such as manual or in-person checks). This obligation ensures that no user is unfairly excluded, in line with inclusion requirements of the Framework and general consumer protection standards.
Service continuity
- 4(k) maintain an alternative means of verifying the information you obtain through the services, so that you are not wholly dependent on the availability of the services.
- This is a separate obligation from the alternative verification route under 4(g) above. 4(g) concerns an individual end-user who cannot complete a verification; 4(k) concerns the services themselves being unavailable. Both apply.
Audit and cooperation
- 4(i) reasonably cooperate with Mistho’s certification, audit and conformity-assessment activities so far as they relate to these obligations, including providing information reasonably required and permitting reasonable and proportionate audit on notice. You agree to provide Mistho with reasonable assistance to demonstrate compliance with this Addendum and the Framework, including making records available for review by Mistho or relevant authorities.
- 4(j) keep records relevant to your compliance with these obligations, and make them available to Mistho on reasonable request for certification and assurance purposes.
Changes to the Framework
- 6.1 The Framework is expected to change over time. Where such a change requires amendment of these obligations, Mistho may update this Addendum in accordance with the variation mechanism in the Agreement, acting reasonably and giving the notice required there.
Suspension or withdrawal of certification
- 7.1 If Mistho’s certification is suspended or withdrawn, or if the CAB or OfDIA so requires, Mistho may suspend, modify or withdraw the affected services on notice, without liability for doing so where required by the Framework, and the parties will discuss in good faith an orderly transition.
- Mistho may suspend or terminate your access to its services if you fail to comply with this Addendum.
Term, survival and general
- 8.1 This Addendum takes effect on the date of the Agreement (or, if later, the date on which both parties sign it) and is coterminous with the Agreement.
- 8.2 Obligations which by their nature should survive — including those relating to confidentiality, data protection, records and fraud reporting for the period of the Agreement — survive termination or expiry.
- 9.1 Except as expressly amended by this Addendum, the Agreement remains in full force and effect, and the general provisions of the Agreement (including governing law and jurisdiction — England and Wales) apply to this Addendum.
Versions of this Addendum
- This page presents version 2.0, dated 10th August 2026. It replaces version 1, which applied until that date.
- Earlier versions of this page are retained and dated. If you accepted these terms against an earlier version and need a copy of the text as it stood on the date of your acceptance, contact us at info@mistho.io.
Contact
- If you have questions about this Addendum, please contact us at info@mistho.io.