Can businesses demand physical ID cards for GDPR identification checks?

A recent Amsterdam District Court judgment on whether ID cards can be requested for data subject identification raises interesting points re GDPR and data minimisation – and how controllers can reach a satisfactory level of identification.

Context:
– A controller (C) had 2 processes for verifying the identity of data subjects making a request: (i) verification through login (request submitted while logged in to an account? Properly identified!) and (ii) verification through a copy of an ID card (if the request was submitted by any other means).
– C’s privacy statement mentioned the possibility of submitting *redacted* identity documents, but C did not mention that when it reached out to data subjects to ask for a copy of an ID card.
– The Dutch data protection authority, the Autoriteit Persoonsgegevens (AP), fined C for infringing Art. 12(2) GDPR: requesting an ID card in all of these cases, C did not facilitate the exercise by data subjects of their rights.

The judges seem to have chosen a middle ground between C and the AP:

– “a copy of an identity document is not in and of itself an unreasonable means of identifying a person

– however, C “always asked for a copy of the identity document and did not process a request as long as no copy had been provided [even though] it was not in all cases about (very) sensitive personal data of […] clients and, at least in part of the cases, it was also possible to achieve identification of applicants in other, less intrusive, ways than by providing a copy of an identity document (such as identification via e-mail, which was later introduced as a standard arrangement).�

– in addition, “[i]t must be assumed that the identity document to be provided also often contained more personal data than necessary to identify the applicant, such as a [Burgerservicenummer/BSN*], a photograph and a document number. This is not in line with the principle of data minimisation. Although the privacy statement stated that the [BSN*] and photograph could be masked, [C] did not mention this possibility if it requested a copy of an identity document.

– Due to this likelihood of excessive processing, the procedure was considered “too rigid”, creating an “unnecessary obstacle in advance at least for part of the requests

* BSN = strictly regulated in the Netherlands, like many national identification numbers across the EU.

Some thoughts:
– This reasoning won’t apply everywhere (not all ID cards feature the same information on their front/back and not all countries consider the information on them to be sensitive)
– If you actively facilitate redaction (ex ante) or systematically apply it (ex post), some concerns may be met [but ex post = processing = higher risk]
– If you choose lower-risk means of identification, you may be able to avoid having to propose alternatives in advance

Decision (in Dutch): https://lnkd.in/eCM85n4y

🫖

Did this analysis get you thinking? Reach out!

DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!

Get in touch ↗   Let's connect on LinkedIn ↗