Skip to main content

Verification Data Not Retained

The organisation states that identity information provided for verification is used only to confirm identity and is not kept afterward.

Criterion
C5
Level
Level 3
Domain
Identity Verification
Reflects
Article 5(1)(e)

Intent

Exercising the right of access should not leave the organisation holding a copy of the person's passport. Saying the documents are not kept is what lets the person see that it does not.

How to test it

An assessor scores the criterion against a single response:

Score 2
The organisation stated that the identity information is used only to confirm identity, and that it is not kept afterward.
Score 1
The organisation stated that the identity information is deleted but not what it was used for, or stated what it was used for but not whether it is kept.
Score 0
The organisation said nothing about what happens to the identity information, or stated that it keeps it.
Not applicable
The organisation did not request identity verification.

The law it reflects

This criterion reflects Article 5(1)(e) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.

See C5 in context in the full standard.