Remix.run Logo
chezelenkoooo 4 hours ago

Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure.

So most businesses are not permitted to just delete the data.

michaelt 3 hours ago | parent | next [-]

Back In The Day, if somewhere like a car hire agency wanted to record proof of identity they'd photocopy your driver's license on paper, and store it in a filing cabinet. The computer record of a customer's account would just say "driving license checked, on file at branch #1234"

Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.

SapporoChris 3 hours ago | parent | next [-]

A system abandoned decades ago? https://en.wikipedia.org/wiki/Gold_standard

Tarq0n 2 hours ago | parent [-]

https://en.wiktionary.org/wiki/gold_standard

expedition32 an hour ago | parent | prev [-]

Unfortunately letting random companies photocopy your passport leads to identify fraud.

veunes 3 hours ago | parent | prev [-]

Regulatory retention is a valid reason for some of this data to exist. It isn't a blanket justification for every intermediary in the verification chain to retain its own permanent copy. If anything, that makes minimizing the number of copies even more important.