Verification Data Not Retained
The organisation states that identity information provided for verification is used only to confirm identity and is not kept afterward.
Intent
Exercising the right of access should not leave the organisation holding a copy of the person's passport. Saying the documents are not kept is what lets the person see that it does not.
How to test it
An assessor scores the criterion against a single response:
- Score 2
- The organisation stated that the identity information is used only to confirm identity, and that it is not kept afterward.
- Score 1
- The organisation stated that the identity information is deleted but not what it was used for, or stated what it was used for but not whether it is kept.
- Score 0
- The organisation said nothing about what happens to the identity information, or stated that it keeps it.
- Not applicable
- The organisation did not request identity verification.
The law it reflects
This criterion reflects Article 5(1)(e) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.
See C5 in context in the full standard.