Proportionate Verification
Where the organisation requests identity verification, it asks only for what is necessary to confirm the person's identity.
Intent
Identity checks are a legitimate protection against disclosing someone's data to the wrong person. They stop being that when the organisation asks for more than the check needs.
How to test it
An assessor scores the criterion against a single response:
- Score 2
- The organisation asked only for what it needed to be satisfied the person is who they say they are.
- Score 1
- Everything the organisation asked for bears on identity, but it asked for more of it than it needed, such as two documents where one would have settled the question.
- Score 0
- The organisation asked for material that does not bear on identity, or for a document whose other contents it had no need to see.
- Not applicable
- The organisation did not request identity verification.
The law it reflects
This criterion reflects Article 12(6) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.
See C2 in context in the full standard.