Skip to main content

No Verification on an Identified Route

The organisation does not request identity verification where the request comes through a route that already identifies the person.

Criterion
C1
Level
Level 1
Domain
Identity Verification
Reflects
Article 12(6)

Intent

Asking for a passport from someone who wrote from the email address on their own account adds a barrier and collects sensitive data the organisation did not need.

How to test it

An assessor scores the criterion against a single response:

Score 2
The organisation acted on the request without asking for identity documents, because the route the person used already identified them.
Score 1
The organisation asked for something small to confirm the account, such as a reference number it already holds.
Score 0
The organisation asked for identity documents even though the request came from an account the person was signed in to, or an address held on their record.
Not applicable
The person made the request through a route that does not identify them, such as a general enquiries address.

The law it reflects

This criterion reflects Article 12(6) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.

See C1 in context in the full standard.