Didit
Sign upGet a Demo
Gibraltar flag

Identity verification in Gibraltar

Identity verification and KYC/AML in Gibraltar

Executive summary. Gibraltar is a British Overseas Territory of approximately 34,000 people that punches far above its weight as an international financial centre, a global iGaming hub, and a pioneer in distributed ledger technology (DLT) regulation. The Gibraltar Financial Services Commission (GFSC) oversees a UK-aligned AML/CFT framework harmonised with EU AMLD5 and AMLD6. The DLT Regulations (2

14K+

Documents supported

(Government IDs from 220+ countries)

<30 sec

Average verification time

220+

Countries covered

(Government-issued IDs validated)

Market overview

KYC in Gibraltar, at a glance

Gibraltar has approximately 34,000 residents occupying 6.7 square kilometres at the southern tip of the Iberian Peninsula. Its economy is dominated by financial services, online gambling, and tourism. Key verticals driving KYC demand:

Supported documents

Every major ID in Gibraltar

Didit templates cover national IDs, passports, residence permits and regional documents — plus 14,000+ documents globally for cross-border flows.

Gibraltar identity card

British passport

EU/EEA national identity cards

Foreign passports

Regulators

Who supervises KYC/AML in Gibraltar

Gambling Commissioner

licenses and supervises remote gambling operators

Civil Status and Registration Office

HM Government of Gibraltar — Civil Status and Registration Office

restricted

Civil Status and Registration Office manages birth, marriage, and death records. Gibraltar identity cards issued to residents. British Overseas Territory — residents hold British Overseas Territories

Government & regulated databases

Authoritative sources Didit can cross-check against

Compliance framework

The law behind KYC in Gibraltar

AML framework

Proceeds of Crime Act 2015 (POCA)

Supervised by Gambling Commissioner

- Proceeds of Crime Act 2015 (POCA) — the primary AML/CFT statute, establishing money-laundering offences, suspicious-activity reporting, and confiscation powers. - DLT Regulations (Financial Services (Distributed Ledger Technology Providers) Regulations 2020) — 10 regulatory principles for DLT-based businesses, including AML/KYC requirements. Update expected late 2025/early 2026 to incorporate VASP registrations. - Gibraltar GDPR (Data Protection Act 2004, as updated) — aligned with EU GDPR. Gi

Data protection

Gibraltar General Data Protection Regulation (Gibraltar GDPR) modeled on EU GDPR. Gibraltar Regulatory Authority (GRA) oversees data protection.

Supervised by National DPA

The Gibraltar GDPR aligns with EU standards. Cross-border transfers to EU/EEA and UK are generally permitted. Transfers to other jurisdictions require appropriate safeguards (SCCs, BCRs, or adequacy decisions). The GRA enforces compliance.

Use cases

Built for the industries that regulate Gibraltar

Fintech

Neobanks, EMIs, payment institutions, lenders, brokerages.

1. Document capture. Scan of passport, Gibraltar ID card, or EU national ID. 2. Liveness and biometric match. Selfie with liveness detection, matched against the document portrait. 3. Data extraction. Full name, date of birth, nationality, document number, expiry date. 4. PEP and sanctions screening

Crypto / VASPs

Exchanges, custodians, wallets, on/off-ramps.

DLT-licensed businesses must comply with GFSC's 10 regulatory principles, including:

iGaming

Sports betting, online casinos, age-gated platforms.

Remote gambling operators must comply with Gambling Commissioner AML requirements:

Marketplaces

Gig platforms, delivery, creator economy, e-commerce.

Standard GFSC-compliant CDD for regulated platforms: document verification, PEP/sanctions screening, and risk-based ongoing monitoring.

Biometric liveness

ISO 30107-3 PAD Level 2 liveness, ready for Gibraltar

British passports held by Gibraltar residents contain biometric chips (ICAO 9303) with facial image and fingerprint data, supporting NFC-based verification. For international iGaming customers, the approach depends on issuing-country document technology. ISO 30107-3-compliant liveness detection is the standard for remote onboarding across all sectors. ---

CERTIFICATIONS

Certified for enterprise trust

Our platform meets the highest international standards for information security, data privacy, and biometric accuracy.

translation_v21.securityCompliance.certifications.items.gdpr.title

GDPR Compliant

Full EU data protection compliance

ISO 27001

ISO 27001

Information security management

translation_v21.securityCompliance.certifications.items.ibeta.title

iBeta Level 1

PAD (liveness + face match)

TRUSTED WORLDWIDE

What our customers say

Join thousands of companies that trust Didit for their verification needs

Logo

Didit’s NFC + active biometrics technology blocks the most advanced fraud scenarios, offering a level of security equivalent to or superior to in-person verification.

Spanish Financial Sandbox

CNMV, SEPBLAC & Spanish Treasury — Conclusions Report

Logo

Didit is an exceptionally valuable partner, delivering a stable and highly adaptable solution”.

Vuk Adžić

Head of the E-Business Department at Crnogorski Telekom

Logo

Didit offered us a robust technology with a simple implementation and adaptability to different markets”.

Fernando Pinto

CEO & CoFounder at TucanPay

Logo

Thanks to Didit we have been able to reduce manual processes and improve data extraction accuracy”.

Diana Garcia

Trust & Safety Executive at Shiply

Logo

Didit’s integration slashed verification times and costs, freeing resources for other projects”.

Guillem Medina

COO at GBTC Finance

Logo

Didit removed KYC costs, enabling faster scaling with high verification standards and less fraud.”

Paul Martin

VP Marketing & Growth at Bondex

Logo

Didit’s secure, user-friendly verification boosts customer trust and optimizes our process.”

Cristofer Montenegro

Executive assistant to the CEO at Adelantos

Logo

Didit ensures a precise, secure digital onboarding without slowing negotiations or client time.”

Ernesto Betancourth

Gerente de riesgos at CrediDemo

FAQ

Questions about KYC in Gibraltar

Is remote identity verification legal in Gibraltar?

Yes. Gibraltar permits remote KYC onboarding under its national AML framework, including document verification, biometric liveness and video identification where required by regulation.

What identity documents does Didit verify in Gibraltar?

Didit verifies all major national IDs, passports and residence permits issued in Gibraltar, plus 14,000+ document types globally for cross-border flows.

How much does identity verification cost in Gibraltar?

Didit charges $0.30 per verification with 500 free checks per month. No contracts, no minimums. Competitors typically charge $1.00–$2.50+ per verification.

Does Didit support AML screening for Gibraltar?

Yes. Didit screens against 1,000+ global watchlists including PEP databases, sanctions lists (EU, UN, OFAC, OFSI), and adverse media — covering all AML obligations in Gibraltar.

Is biometric liveness required?

Most regulated sectors in Gibraltar require or strongly recommend biometric liveness detection for remote onboarding. Didit provides ISO 30107-3 PAD Level 2 certified liveness.

Can Didit help with crypto/VASP compliance in Gibraltar?

Yes. Didit supports document verification, liveness, AML screening and ongoing monitoring aligned with Gibraltar’s crypto regulatory framework, including EU Travel Rule compliance where applicable.

Does Didit support age verification for iGaming in Gibraltar?

Yes. Didit provides document-based age verification and identity confirmation suitable for Gibraltar’s iGaming regulatory requirements.

Launch compliant KYC in Gibraltar today

500 free verifications per month. No contracts, no minimums. $0.30 per verification after the free tier.