Proportionate Verification
Where the organisation requests identity verification, it asks only for what is necessary to confirm the person's identity.
Intent
An identity check protects the person from having their data sent to someone else. It stops doing that when the organisation asks for more than the check needs.
How to test it
An assessor scores the criterion against a single response:
- Score 2
- The organisation asked only for what it needed to be satisfied the person is who they say they are.
- Score 1
- Everything asked bears on identity, but the organisation asked for more of it than needed, such as two documents where one would have settled the question.
- Score 0
- The organisation asked for material that does not bear on identity, or for a document whose other contents it had no need to see.
- Not applicable
- The organisation did not request identity verification.
The law it reflects
This criterion reflects Article 12(6) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.
See C2 in context in the full standard.