Skip to main content

Proportionate Verification

Where the organisation requests identity verification, it asks only for what is necessary to confirm the person's identity.

Criterion
C2
Level
Level 1
Domain
Identity Verification
Reflects
Article 12(6)

Intent

Identity checks are a legitimate protection against disclosing someone's data to the wrong person. They stop being that when the organisation asks for more than the check needs.

How to test it

An assessor scores the criterion against a single response:

Score 2
The organisation asked only for what it needed to be satisfied the person is who they say they are.
Score 1
Everything the organisation asked for bears on identity, but it asked for more of it than it needed, such as two documents where one would have settled the question.
Score 0
The organisation asked for material that does not bear on identity, or for a document whose other contents it had no need to see.
Not applicable
The organisation did not request identity verification.

The law it reflects

This criterion reflects Article 12(6) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.

See C2 in context in the full standard.