Saltar para o conteúdo

oneVcard and DORA

The Digital Operational Resilience Act (DORA) sets high standards for digital operational resilience in the financial sector, including for the ICT providers you rely on. oneVcard is built to support you as a financial entity in meeting them.

Digital operational resilience, made binding

DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025 and requires banks, insurers, payment providers and other financial entities to ensure their digital resilience, including the risks posed by the ICT third-party providers they use. As a provider of digital business cards for teams, we see ourselves as a dependable link in that chain and help you meet your DORA obligations towards regulators.

What you can rely on with oneVcard

Security & data protection

State-of-the-art technical and organisational measures: encryption in transit and at rest, strict access controls and regular reviews.

Resilience & availability

Redundant infrastructure, automated backups and tested recovery processes keep your digital business cards available.

Incident management

Monitoring and defined processes to detect, handle and report ICT-related incidents, including timely notification of affected customers.

Third-party transparency

We disclose the subcontractors and data centres we use and, on request, add the contractual arrangements DORA requires (Art. 30).

Hosting in the EU

Operations and data storage in data centres within the European Union, fully GDPR-compliant.

Evidence & documentation

On request we provide information on security, availability and processes for your ICT third-party risk management.

Common questions about DORA & oneVcard

Is oneVcard itself subject to DORA?

DORA applies primarily to financial entities. oneVcard is an ICT third-party provider: we are not directly subject to the regulation, but we help you meet your requirements for the providers you use.

Do I get the information I need for my register of information?

Yes. On request we provide the details relevant to your register, such as scope of service, data categories, place of processing and subcontractors used.

Do you sign the contractual clauses DORA requires?

For Team and Enterprise customers we add the content required by Art. 30 DORA to the contractual arrangements. Just get in touch.

Where is my data processed?

In data centres within the EU and GDPR-compliant. You'll find details in our privacy policy and data processing agreement (DPA).

Request DORA documentation

Need information for your ICT third-party risk management? We'll provide the right evidence.