6 ms·
> Why wouldn't they? They most likely weren't allowed to keep it past the verification per GDPR art.5. Once the passport has been verified for whatever purpose
by charles_f 3mo ago
> Why wouldn't they?
They most likely weren't allowed to keep it past the verification per GDPR art.5. Once the passport has been verified for whatever purpose they needed it ("age verified to be > 18yo on 2026-06-12" or "identity verified to be XXXX YYYY"), there is no legitimate use for the passport photo and details anymore, and they should delete it.
- petercooper 3mo ago(I'm naive in this area, but..) I wonder if the various "proof of age" laws coming into play will clash with the GDPR in insidious ways. Like requiring identity providers to hold definitive "proof" of why they made an assessment rather than merely proving and discarding. I assume/hope there is some cryptographic way to do this rather than hang on to passport and ID images, however.
- lschueller 3mo agoThere are established ways / protocols to hold and provide cryptographically valid proof of a verification process, without any need to keep the actual id images in any storage. And to my knowledge there is no requirement for compliant KYC (Know your customer) to provide their ID as a proof as long as the verification process itself is compliant and audited in accordance to certain criteria. You can compare this in a certain way to file hashes. A successful verification with a predefined minimum level of credibility can be encrypted to a special string for later being used, if a service needs to verify the person again. It doesn't matter then, that the original passport images or video ident has been deleted the second after id verification has been completed.
- charles_f 3mo agoI'm somewhat knowledgable on privacy topics, pasting my answer to another comment: The EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept". ^1: https://www.edpb.europa.eu/system/files/documents/2025-04/ed https://www.edpb.europa.eu/system/files/documents/2025-04/ed..., number 36.
- aand16 3mo agoLink is broken
- ligne 3mo agoThe original post (and correct link) is here: <https://news.ycombinator.com/item?id=48725917 https://news.ycombinator.com/item?id=48725917>
- elric 3mo agoI agree with the theory, but I guarantee you that in practice the vast majority of orgs are storing way more data than they should.
- M95D 3mo agoCan't find the reference by date. What's the name of the document?
- charles_f 3mo agoFixing the link: https://www.edpb.europa.eu/system/files/documents/2025-04/edpb_statement_20250211ageassurance_v1-2_en.pdf https://www.edpb.europa.eu/system/files/documents/2025-04/ed...