oneVcard and DORA
The Digital Operational Resilience Act (DORA) sets high standards for digital operational resilience in the financial sector, including for the ICT providers you rely on. oneVcard is built to support you as a financial entity in meeting them.
Digital operational resilience, made binding
DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025 and requires banks, insurers, payment providers and other financial entities to ensure their digital resilience, including the risks posed by the ICT third-party providers they use. As a provider of digital business cards for teams, we see ourselves as a dependable link in that chain and help you meet your DORA obligations towards regulators.
What you can rely on with oneVcard
Security & data protection
State-of-the-art technical and organisational measures: encryption in transit and at rest, strict access controls and regular reviews.
Resilience & availability
Redundant infrastructure, automated backups and tested recovery processes keep your digital business cards available.
Incident management
Monitoring and defined processes to detect, handle and report ICT-related incidents, including timely notification of affected customers.
Third-party transparency
We disclose the subcontractors and data centres we use and, on request, add the contractual arrangements DORA requires (Art. 30).
Hosting in the EU
Operations and data storage in data centres within the European Union, fully GDPR-compliant.
Evidence & documentation
On request we provide information on security, availability and processes for your ICT third-party risk management.
Common questions about DORA & oneVcard
Is oneVcard itself subject to DORA? ▼
DORA applies primarily to financial entities. oneVcard is an ICT third-party provider: we are not directly subject to the regulation, but we help you meet your requirements for the providers you use.
Do I get the information I need for my register of information? ▼
Yes. On request we provide the details relevant to your register, such as scope of service, data categories, place of processing and subcontractors used.
Do you sign the contractual clauses DORA requires? ▼
For Team and Enterprise customers we add the content required by Art. 30 DORA to the contractual arrangements. Just get in touch.
Where is my data processed? ▼
In data centres within the EU and GDPR-compliant. You'll find details in our privacy policy and data processing agreement (DPA).
Request DORA documentation
Need information for your ICT third-party risk management? We'll provide the right evidence.