FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. SheerID

SheerID

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does SheerID do?

SheerID is a US based identity verification provider that lets retailers offer gated discounts to specific consumer segments (students, teachers, military, healthcare workers, first responders, age verified shoppers). The SheerID verification form is embedded in the checkout flow and confirms eligibility by checking authoritative databases. SheerID processes substantial personal data (full name, date of birth, school or employer name, professional ID) and is a critical GDPR processor with high risk level.

What SheerID is and how it works

SheerID is an identity verification platform that lets brands offer gated promotions to specific consumer segments. Common segments include students, teachers, military, healthcare workers, first responders, seniors, age verified adults and recent movers. The verification form is embedded in the checkout or signup flow; the consumer provides their details, SheerID checks authoritative databases (university registrars, employer directories, government records) and returns an eligibility verdict. The brand applies the discount only to verified consumers.

What data SheerID processes

Depending on the verification type, SheerID collects full name, date of birth, address, email, phone number, employer or school name, professional or student identification number, and sometimes documentary evidence (uploaded photo ID, pay stub, enrolment certificate, transcript). Some verifications imply special categories of data under Art. 9 GDPR (healthcare profession status indicates health context, religious organisation membership reveals religion). The platform sets cookies on the verification form domain to support session state.

GDPR implications

SheerID is a processor of consumer personal data under GDPR. The retailer is the controller and must sign the SheerID DPA, document the processing in its record of processing activities, run a DPIA (mandatory given the scope of data) and inform consumers. For special categories of data (Art. 9), explicit consent is needed or another Art. 9 lawful condition. For verifications that affect access to a service (e.g. military discount), Art. 22 GDPR considerations on automated decision making apply.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and disclosure requirements

Before opening the verification form, disclose to the consumer that SheerID will process their data on US servers, what data will be collected, the legal basis (consent or contract), the purpose (verifying eligibility for a discount), the retention, and that the consumer can refuse and pay full price instead. The form itself collects the personal data only after the consumer has clicked through, and SheerID provides standard consent language that can be customised.

Data transfers and sub-processors

SheerID is US headquartered and processes data primarily in the United States, with EU sub-processors for some specific data sources (university registrars in the EU, EU based military identity systems). Transfers to the US rely on SCCs and the EU, US Data Privacy Framework. A Transfer Impact Assessment is required and should be substantive given the categories involved.

Practical compliance steps

Sign the SheerID DPA, run a DPIA before launch (mandatory), inform consumers clearly in your checkout flow about the data transfer and verification process, present an alternative way to access the price (no discount but no data sharing), avoid using SheerID for special categories without explicit consent, set short retention for verification outcomes (the verdict needs to be retained only as long as the discount is valid), and audit Art. 22 GDPR safeguards (human review for refused verifications).

GDPR consent category

Essential

Websites using SheerID must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) for identity verification disclosures; contract performance (Art. 6(1)(b)) where verification is required to access a discount or service
Risk levelhigh
Applicable regulationsGDPR, GDPR Art. 9 for any sensitive category verification, eIDAS for identity, AML where financial services apply

DPIA considerations

SheerID processes substantial personal data: full name, date of birth, residential address, email address, phone number, employer or school name, professional or student ID number, sometimes supporting documents (uploaded ID, pay stub, enrolment certificate). For some verifications, sensitive data (health profession, military status) is processed under Art. 9 GDPR. Key DPIA considerations: (1) the data category is substantial and includes some sensitive categories; (2) authoritative database lookups happen across multiple jurisdictions, creating additional flows; (3) US hosting and processing requires SCCs and TIA; (4) document upload for manual verification raises stronger security obligations; (5) verification outcomes can affect access to discounts, raising fairness considerations under Art. 22 GDPR. A DPIA is mandatory.

Sample consent text

We use SheerID to verify your eligibility for special pricing. SheerID processes your full name, date of birth, professional or student status, and may transfer this data to SheerID Inc. in the United States. Your data is used only for the verification and is not shared for marketing. You can refuse verification, but in that case the discount will not apply.

Technical details

Tracking methodJavaScript verification form (sheerid.js) embedded on the publisher website
Server locationUnited States (SheerID Inc.) with EU sub-processors
Data transferred outside the EUSheerID is a US headquartered identity verification provider. Hosting is primarily in the United States with regional processing in the EU for some data sources. Transfers rely on Standard Contractual Clauses and the EU, US Data Privacy Framework.

SheerID is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site