No Verification on an Identified Route
The organisation does not request identity verification where the request comes through a route that already identifies the person.
Intent
Asking for a passport from someone who wrote from the email address on their own account adds a barrier and collects sensitive data the organisation did not need.
How to test it
An assessor scores the criterion against a single response:
- Score 2
- The organisation acted on the request without asking for identity documents, because the route the person used already identified them.
- Score 1
- The organisation asked for something small to confirm the account, such as a reference number it already holds.
- Score 0
- The organisation asked for identity documents even though the request came from an account the person was signed in to, or an address held on their record.
- Not applicable
- The person made the request through a route that does not identify them, such as a general enquiries address.
The law it reflects
This criterion reflects Article 12(6) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.
See C1 in context in the full standard.