Skip to main content

The organisation states that the person's identity information is used only to confirm identity and is not kept afterward.

Intent

Using the right of access should not leave the organisation holding a copy of the person’s passport. Saying the documents are not kept tells the person it does not.

How to test it

An assessor scores the criterion against a single response:

Score 2
The organisation stated the identity information is used only to confirm identity, and that it is not kept afterwards.
Score 1
The organisation stated the identity information is deleted but not what it was used for, or stated what it was used for but not whether it is kept.
Score 0
The organisation said nothing about what happens to the identity information, or stated that it keeps it.
Not applicable
The organisation did not request identity verification.

The law it reflects

This criterion reflects Article 5(1)(e) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.

See C5 in context in the full standard.

Back to reference material

Report a problem with this page