Country-specific guidance Current
Storing client identity evidence securely under GDPR Article 32
Identity documents and due diligence records carry real risk if they're mishandled.
Once you've collected and verified a client's identity evidence, GDPR expects you to keep it secure, not just keep it. This guide sets out what that security obligation actually requires. It is general information, not legal or compliance advice.
Action plan
1 Apply technical and organisational measures matched to the risk GDPR doesn't prescribe one fixed control set; it expects measures proportionate to the risk involved.
GDPR Article 32 requires the controller and processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing. The article names pseudonymisation and encryption, ongoing confidentiality, integrity, availability and resilience of processing systems, the ability to restore access after an incident, and a process for regularly testing and evaluating those measures.
- Apply pseudonymisation or encryption to stored identity evidence where appropriate
- Maintain ongoing confidentiality, integrity, availability, and resilience of the systems holding it
- Test and evaluate the effectiveness of your security measures on a regular basis
Done when: Security measures for stored identity evidence are matched to the risk, tested, and regularly evaluated
EUR-Lex: General Data Protection Regulation (EU) 2016/679, Article 322 Treat identity and due diligence evidence as genuinely high-risk personal data Passports, national IDs, and ownership evidence are exactly the records a security incident would target.
Article 32 requires that, in assessing the appropriate level of security, account is taken of the risks presented by processing, including accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Identity documents, beneficial ownership evidence, and due diligence records sit squarely within that risk category, and should be treated accordingly rather than stored at the same level as routine correspondence.
- Assess identity and due diligence evidence against the specific risks Article 32 names
- Give this evidence a higher security tier than routine, low-sensitivity client correspondence
- Review that tier whenever the volume or sensitivity of stored evidence changes materially
Done when: Identity and due diligence evidence is stored at a security tier that reflects its actual risk, not a default level
3 Control who can access it, and keep a record of that control Article 32 covers who can touch the data, not only how it's encrypted or backed up.
Article 32 also requires the controller and processor to take steps ensuring that any natural person acting under their authority who has access to personal data only processes it on instructions from the controller, unless required to do otherwise by Union or member state law. Limit access to identity evidence to those who genuinely need it, and keep a record of that access control as part of your accountability evidence.
- Limit access to stored identity evidence to people who genuinely need it for their role
- Keep a record of who has access, and why
- Review access whenever a role or engagement changes
Done when: Access to stored identity evidence is limited to people who need it, with that limitation recorded
See setting a record-retention schedule for AML and GDPR evidence