Skip to main content

Verification Explained

Where the organisation requests identity verification, it states why the verification is needed.

Criterion
C3
Level
Level 2
Domain
Identity Verification
Reflects
Article 12(6)

Intent

A demand for identity documents with no reason reads as an obstacle. Saying why it is needed lets the person see it as a protection rather than a delay.

How to test it

An assessor scores the criterion against a single response:

Score 2
The organisation said what the verification is for, such as making sure it does not send the person's data to someone else.
Score 1
The organisation said the check is required by its policy or by the law, without saying what the check is for.
Score 0
The organisation asked the person to prove their identity and said nothing about why.
Not applicable
The organisation did not request identity verification.

The law it reflects

This criterion reflects Article 12(6) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.

See C3 in context in the full standard.