7 ms·
The lack of security is one thing, but why have they retained the information at all! iirc, one of the elements of GDPR is "storage limitation", i.e. you must
by gertrunde 3mo ago
The lack of security is one thing, but why have they retained the information at all!
iirc, one of the elements of GDPR is "storage limitation", i.e. you must not keep personal data for longer than you need it - and in this case, the data is only needed to verify the age of the user, and shouldn't ever be required again (unless people can now get younger).
Once a document has been used to verify a person's identity and that the person is of legal age, there is no reason to retain a copy of the document any more.
It would be reasonable and fair to retain a photo of the user to verify that the person matches the account, but that's it.
- rationalist 3mo ago10 years after I took the ACT, I received a letter from a university that I never went to, saying my SSN was leaked. WHY THE F**k ARE THEY HOLDING ON TO THAT 10 YEARS LATER!?!?!? Of course now I know better than to give out my SSN to anyone who asks for it, but I didn't know that as a teenager. Until stupid s**t like this becomes illegal, it will just keep continuing.
- vrsgjye 3mo ago[dead]
- robrtsql 3mo agoDon't be so hard on 17-ish-year-old you. What exactly were you supposed to do? Not take the ACT (and probably not get into your desired college)?
- DANmode 3mo agoAsk if it’s required, instead of assuming it is, is the point. Modern equivalent “move over here for your picture ‘for the doctor’.” No thanks, I’d like to opt-out!
- AgentOrange1234 3mo agoThis is a real problem. I was appalled when renewing my car this year that I now need a Texas by Texas account (https://www.texas.gov/texas-by-texas/ https://www.texas.gov/texas-by-texas/), which wants... a social security number because why?!?! Anyway, yet another data breach incoming.
- axus 3mo agoI'd hope that there's an in-person option for renewal. Maybe people without a data plan don't exist anymore?
- Tangurena2 3mo ago> which wants... a social security number because why? Because of federal child support legislation. If you are $2500 (or more) in arrears, your passport gets cancelled. Most states will also suspend/revoke your professional licenses and possibly driving license when you cross that state's threshold. https://travel.state.gov/en/passports/contact-support/legal-matters/child-support.html https://travel.state.gov/en/passports/contact-support/legal-... https://en.wikipedia.org/wiki/Child_support_in_the_United_States https://en.wikipedia.org/wiki/Child_support_in_the_United_St... > In 1996, Congress passed and President Bill Clinton signed the Personal Responsibility and Work Opportunity Act (42 U.S.C. § 666), which required that states adopt UIFSA by January 1, 1998 or face loss of federal funding for child support enforcement. Every U.S. state has adopted either the 1996 or a later version of UIFSA. https://en.wikipedia.org/wiki/Uniform_Interstate_Family_Support_Act https://en.wikipedia.org/wiki/Uniform_Interstate_Family_Supp... When I worked for my state's motor vehicle bureau, one of the verification apis that the driving license/ID folks got to use was a verification of citizenship/lawful residence service. Which used SSNs.
- cute_boi 3mo agoI think every SSN is already leaked and government is doing nothing. I tried to change SSN and they told me it is not possible.
- recursivecaveat 3mo ago100s of millions have definitely been exposed already. The best defence is probably to be a baby so your risk window is minimal. I haven't been able to pull that off personally, so I follow the other recommended piece of advice which is to keep your credit checks permanently frozen with the agencies and only temporarily thaw it for specific usages. https://www.upguard.com/breaches/social-insecurity-billions-of-social-security-number-and-passwords https://www.upguard.com/breaches/social-insecurity-billions-...
- alwa 3mo agoWhich is a shame, as there are only hundreds of millions possible… and they still have to include room in that 9-digit namespace for non-social-security-involved ITINs and employer ID numbers!
- throwaway173738 3mo agoThey’ll definitely issue loans to a child. You have to actually put a special freeze on your child’s credit account, which is insane but welcome to the US, where any obstruction to the wheels of commerce is an affront to our national dignity.
- frollogaston 3mo agoI've had stuff like this happen too, and always wondered if they really leaked my data or were just notifying everyone whose data they possibly leaked.
- bigfishrunning 3mo agoI think the argument is "if they didn't retain your data, it couldn't have possibly leaked"
- frollogaston 3mo agoYeah I meant it's possible they didn't retain your passport, they just know you took the test at some point.
- Sohcahtoa82 3mo agoThe real answer? In case you want to retrieve your test scores 10 years after you took it. They need some way to uniquely identify you. Sure, they could have given you a specific test taker ID, but what if you lost that? They could have created a way for you to log in with an e-mail address, but what if you changed e-mail addresses? You might think "Why would I need my test scores from 10+ years ago?", but my wife just started a job and they demanded her college transcripts to prove she went there...over 20 years ago.
- catlikesshrimp 3mo agoIdentify the student by full name, dob, date of admission, career, etc. It takes 5 minutes instead of one. The problem here is using a username (the ID) as a password (security check)
- throwaway173738 3mo agoAnd make them call the registrar during regular hours. That’s what I had to do to get a transcript from 15 years ago once. The registrar holds the records and should be able to provide them.
- xmcp123 3mo agoI think the issue here is that it was the university, not ACT. ACT has a valid reason for holding it. A university he never went to does not.
- TZubiri 3mo agoI'm not american, but the idea that your SSN, which is effectively a (federal) unique identifier for a person, would be secret, is very foreign. In most countries, like most databases, our primary keys do not hold an expectation of secrecy. I would even argue that the expectation of secrecy is what creates it's secret semantics, that is, it's secret because you make it secret. I get that it's a collective action thing, if you just publish your own SSN, a bank in another state might not be aware it's a public thing for YOU, and might open an account for a stranger. Interestingly enough, for corporations, their identifiers, EIN, are not assumed to be private, in many states these are available through the DoS public records. So it turns out the system works just fine if you make the ID of a person (juristic or legal) public.
- smcin 3mo agoSo what prevents people applying for loans or doing identity theft, in other countries?
- rightbyte 3mo agoTo sign on for a house, marry, claim a child as yours etc you need witnesses where I live. Web of trust I guess? If someone takes a loan in my name and I don't receive the money it is not an identity theft it is fraud and the victim is the bank not me.
- sleepybrett 3mo agodo you think scammers don't travel in packs?
- smcin 3mo agoI meant online. Lower-value types of fraud, like e-commerce, prepaid mobile phone bills.
- petilon 3mo agoSure, but what if someone steals your money by impersonating you? Here too, ideally the victim is the bank, but now the onus is on you to convince the bank that they are the victim. They are going to say you're the victim, your identity got stolen, sorry you lost all your savings! We need to update our laws. This is not "Identity Theft", this is "Negligent Verification Fraud", and it is the bank's fault because they were lax in their verification process.
- Tangurena2 3mo agoMy first university, back in the 1970s, used my SSN as my student ID and was embossed into the ID card (who is that stranger in the photo?). Nowadays, no university uses SSN for student IDs. There's a saying that applies: the past is a foreign country.
- dotancohen 3mo ago> Once a document has been used to verify a person's identity and that the person is of legal age, there is no reason to retain a copy of the document any more. Might KYC laws and general CYA policies prefer to keep the proof of age? For instance to protect e.g. against a minor altering the date on their passport. Especially in such a regulated industry.
- charles_f 3mo agoThe EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept". ^1: https://www.edpb.europa.eu/system/files/documents/2025-04/edpb_statement_20250211ageassurance_v1-2_en.pdf https://www.edpb.europa.eu/system/files/documents/2025-04/ed..., number 36.
- dotancohen 3mo agoThank you.