Secure Portal
Authenticated, encrypted, role-bounded submission—not ordinary email, unclear links, or informal attachments.
Sensitive identity evidence governance
Sensitive identity evidence demands a traceable purpose, secure handling, component-level status, and verified closure.
Adopt the Custody StandardAuthenticated, encrypted, role-bounded submission—not ordinary email, unclear links, or informal attachments.
Immediate receipt identifies the file type, time, requesting purpose, session, controller, and verification provider.
Document status is resolved and displayed separately before any biometric collection may be authorized.
Every collector, verifier, processor, reviewer, recipient, purpose, reuse, and derivative is named.
Retention begins with a stated limit; deletion, redaction, restriction, or legal hold remains visible and provable.
The subject receives an exportable custody report showing disposition of every document and biometric component.
The governing principle
A person should never be left unable to determine where a license, passport, selfie, face scan, or liveness record went.
Before collection, the system must identify the purpose, requesting organization, verification provider, data required, decision logic, comparison target, access boundaries, retention, deletion, and alternatives. After submission, it must issue a receipt and maintain a user-readable chain of custody through verified closure.
A failed component must never become an invisible gateway for collecting more sensitive data.
Sequential consent logic
A negative document state cannot be transformed into a positive biometric permission. Each component keeps its own status, and only the valid positive path may advance.
Explain why the scan is necessary, what it will be compared against, who receives it, and how long it will be retained.
Face/liveness scan may proceedDo not collect a face scan. Close or reset the attempt and explain receipt, retention, deletion, and appeal status.
No biometric escalationVerification decision matrix
Proceed only for the disclosed purpose. Issue session and report IDs, access history, retention terms, and closure details.
Explain the biometric failure. Permit only a bounded retry with clear notice. Never label the identity verified.
A positive face result cannot cure a failed document. Quarantine or delete the biometric record unless a new valid document and renewed consent are provided.
Stop collection. Close or reset the attempt. Provide deletion or redaction status for both failed components.
Allowed only when parallel collection was disclosed before capture. Show both components as pending—never falsely label one failed.
Identity Data Furnisher & Custody Report
The report must identify every entity and event—not merely state that verification “failed.” It must be exportable, account-specific, and understandable without reconstructing multiple support threads.
A unique verification-session ID and custody-report ID for every attempt.
License front, license back, passport, selfie, face scan, and liveness status shown separately.
Requesting platform, verification vendor, subprocessors, cloud storage, human reviewers, and recipients.
Original files, extracted text and fields, document images, templates, embeddings, biometric derivatives, and risk signals.
Who viewed, processed, transferred, disclosed, reused, corrected, restricted, or deleted each component.
The specific decision being made, why each data type was necessary, and whether use changed later.
Retention start, exact period or criterion, deletion date, backups, legal holds, and proof of final disposition.
Dispute, correction, freeze, restriction, consent withdrawal, redaction, deletion, appeal, and human review pathways.
Cybercrime & identity-theft prevention
Foreseeable human impact: unexplained repeated collection can cause acute distress, especially for people already notified of data breaches. Systems must reduce uncertainty with immediate receipts, plain-language status, bounded collection, and named accountability.
Originating case-study architecture
These patterns describe governance failures without alleging misconduct by an unidentified person. The standard exists so no provider can collect citizenship documents and biometrics while leaving the subject unable to trace their disposition.
Verified closure test
A provider must be able to answer these requirements for the specific account and verification attempt—not with generic policy language alone.
Platform & regulatory adoption
A user-side record can preserve submission evidence and expose unanswered gaps; it cannot inspect a provider’s private servers or prove undisclosed use. The provider and its vendors must supply the authoritative custody, access, retention, and deletion records.