Identification can be necessary in order to deliver services and products. This concerns customers, employees and (in some cases) business contacts. Examples are the HR department, collection points where customers have to identify themselves, and contacts who only get access after identification.
It is not always clear whether identification is required or allowed and, if so, how it should be done. As a result, identification does not take place in the right way.
Most companies and organisations also have to identify people in different ways, because the way of identifying is determined by the different purposes (the services and goods) there are, and by whom the purpose is for (to whom the service or goods are delivered).
Employees are identified differently from customers, because the purpose to be achieved is different. The identification of customers can differ per group of customers, because the purposes can differ (the services and goods delivered to each group).
Mandatory and non-mandatory identification
You cannot choose the way of identifying yourself. There is mandatory and non-mandatory identification. In the case of mandatory identification, it is prescribed when and how identification must take place. Employees must be identified when they start work, by making a copy of their identity document. Hired-in staff must be identified too, but again in a different way.
With non-mandatory identification, you have to choose a way of identifying in which the minimum necessary amount of personal data is collected, and only if that data is needed to achieve the purpose and there is a legal basis for collecting it (consent that has been given is an example of such a basis).
That does not mean identification is always allowed when it is not mandatory. If there is no purpose, there may be no identification. A customer who buys a product in a shop does not have to be, and may not be, identified, because there is no purpose.
If the customer signs up for promotions and wants to receive emails, there is a purpose and personal data may be collected, but only if there is a legal basis that allows it. In this case data can be collected if the customer gives consent in the correct way.
No more data than necessary
Being allowed to identify someone does not mean you may simply collect personal data either. Only the data needed to send the customer in the example emails may be collected. Collecting more data than necessary is not allowed either. If there are several pieces of data with which the purpose can be achieved, the minimum has to be chosen from them. Minimum means that with less data the purpose could no longer be achieved. And if you have to choose between those pieces of data, you must choose the ones that would have the least impact on the customer if, for example, a data breach occurs.
The chosen way of identifying must match the personal data required. When logging in to a website, for example a news site, an email address or username combined with a password is sufficient and no other identification is needed. When collecting an order, viewing a shielded identity document is sufficient, or recording a few details.
If identification is possible without collecting personal data, that has advantages, because the requirements the GDPR sets for processing data (including collecting it) then do not apply. The conditions that must be met in order to be allowed or required to identify, and the way of doing so, do not change. An example is establishing someone’s age when they buy goods subject to an age limit; this can be done by viewing the identity document with a minimum of data.
Agreements per sector
Because the restrictions on non-mandatory identification can cause problems, agreements on how to identify people have been made for a number of sectors and activities. An example is the car rental sector, where it is permitted to make a copy of a shielded identity document or to ask to see it. This is only to prevent theft. The data (if copied) must be destroyed immediately after the rental ends. This category forms the third category.
How to determine how you should identify
Using the rules above, you can determine how identification should take place:
- Determine how many different purposes there are and which groups: customers, employees, hired-in staff, freelancers, volunteers and certain suppliers.
- Determine for which of those purposes and groups identification is mandatory, and how it has to be done per purpose and/or group.
- Establish for which purposes there is no obligation to identify, but for which agreements have been made on how identification may take place (more is permitted).
- For the remaining purposes there is no obligation to identify and no agreements have been made.
- Determine per purpose what is minimally needed to achieve it, and choose the personal data that could have the least impact on a person in the event of a data breach.
- Choose a way of identifying that does not reveal more personal data than strictly necessary (such as a shielded identity document).
See https://landing.rendement.nl/avg-tool/ for detailed compliance forms. With this AVG and AVG Plus tool you can determine for each purpose and group how to identify people correctly. The AVG and AVG Plus tool enable continuous monitoring of the GDPR and NIS2 compliance of the company or organisation. The AVG and AVG Plus tool include an ICT check for NIS2 compliance.