Skip to main content

Where the organisation requests identity verification, it asks only for what is necessary to confirm the person's identity.

Intent

An identity check protects the person from having their data sent to someone else. It stops doing that when the organisation asks for more than the check needs.

How to test it

An assessor scores the criterion against a single response:

Score 2
The organisation asked only for what it needed to be satisfied the person is who they say they are.
Score 1
Everything asked bears on identity, but the organisation asked for more of it than needed, such as two documents where one would have settled the question.
Score 0
The organisation asked for material that does not bear on identity, or for a document whose other contents it had no need to see.
Not applicable
The organisation did not request identity verification.

The law it reflects

This criterion reflects Article 12(6) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.

See C2 in context in the full standard.

Back to reference material

Report a problem with this page