5 ms·
Why wouldn't they? There are probbaly significant downsides if they fail an audit requirement, and they're probably mandated to retain records for some period,
by observationist 3mo ago
Why wouldn't they? There are probbaly significant downsides if they fail an audit requirement, and they're probably mandated to retain records for some period, with no consequences to extended retention.
Set up a system so that it costs you nothing to do a bad thing but possibly wrecks you legally and financially to do the good thing, and people will inevitably do the bad thing. They shouldn't be collecting this information in the first place.
The people who design these policies are incapable of actually building things that work. They are not the intelligent, competent leaders exercising a careful craft that they like to pretend they are.
They keep going after age verification, online ID, central bank digital currencies, etc - keep this incident in mind. The people who implement and write these policies are morons. They don't game things out and plan for redundancy or resiliency. They don't take into account bad faith actors. They don't account for deliberate exploitation of the system.
- onetokeoverthe 3mo ago[dead]
- charles_f 3mo ago> Why wouldn't they? They most likely weren't allowed to keep it past the verification per GDPR art.5. Once the passport has been verified for whatever purpose they needed it ("age verified to be > 18yo on 2026-06-12" or "identity verified to be XXXX YYYY"), there is no legitimate use for the passport photo and details anymore, and they should delete it.
- petercooper 3mo ago(I'm naive in this area, but..) I wonder if the various "proof of age" laws coming into play will clash with the GDPR in insidious ways. Like requiring identity providers to hold definitive "proof" of why they made an assessment rather than merely proving and discarding. I assume/hope there is some cryptographic way to do this rather than hang on to passport and ID images, however.
- lschueller 3mo agoThere are established ways / protocols to hold and provide cryptographically valid proof of a verification process, without any need to keep the actual id images in any storage. And to my knowledge there is no requirement for compliant KYC (Know your customer) to provide their ID as a proof as long as the verification process itself is compliant and audited in accordance to certain criteria. You can compare this in a certain way to file hashes. A successful verification with a predefined minimum level of credibility can be encrypted to a special string for later being used, if a service needs to verify the person again. It doesn't matter then, that the original passport images or video ident has been deleted the second after id verification has been completed.
- charles_f 3mo agoI'm somewhat knowledgable on privacy topics, pasting my answer to another comment: The EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept". ^1: https://www.edpb.europa.eu/system/files/documents/2025-04/ed https://www.edpb.europa.eu/system/files/documents/2025-04/ed..., number 36.
- aand16 3mo agoLink is broken
- ligne 3mo agoThe original post (and correct link) is here: <https://news.ycombinator.com/item?id=48725917 https://news.ycombinator.com/item?id=48725917>
- elric 3mo agoI agree with the theory, but I guarantee you that in practice the vast majority of orgs are storing way more data than they should.
- 3mo ago
- TZubiri 3mo ago>Why wouldn't they? There are probbaly significant downsides if they fail an audit requirement, Right, and keeping old passports used for verification should cause an audit to fail.
- lazide 3mo agoNot if there is no law about it. If there is a law about verifying buyers, how else are they going to pass that audit?
- subscribed 3mo agoThere's a law forbidding storage beyond necessary minimum and law punishing such behaviour unless another law necessitated storage of the original document in the unsecured, unencrypted form. Doubtful. There's also laws mandating secure systems design. Separately there's no _need_ to store the original document if the verification system is sound (and audit real, not some phony crap like in some of the scandals posted here on HN).
- lazide 3mo agoIf you need to prove you sold to real people, storing their credentials is a necessary thing, for as long as your need to prove that. At least with the way things currently are. How else do you expect it to work? ‘Honest, we checked’ checkboxes?
- hackinthebochs 3mo agoIf the credentials are stored for some period of time, then an inspection will reveal those stored credentials within the preservation window. Unannounced inspections will then show with high certainty a legitimate validation process. The auditor can act as a customer and validate whether phony credentials are rejected.
- lazide 3mo ago