A public-interest model act by April Smith, J.D.

A common name must never become a lesser identity.

The Placeholder Name and Identity Integrity Act establishes enforceable protections when real people are confused with duplicates, placeholders, synthetic identities, test records, or other people who share their name.

No common-name safe harbor.

An organization cannot excuse misidentification by calling a lawful name “too common,” “generic,” or “placeholder-like.”

Positive / Negative Sequential-Consent Logic

If a license or passport fails inspection, do not collect a face scan.

A rejected, unreadable, incomplete, mismatched, or non-qualifying identity document is a negative state. There is no valid reason to escalate that failure into more intrusive facial or liveness collection. The document result must be resolved first and must never be silently converted into biometric permission.

DOCUMENT POSITIVE

Biometric step may proceed

Only after the purpose, comparison target, verification vendor, recipients, retention period, deletion rule, alternatives, and affirmative consent are disclosed.

DOCUMENT NEGATIVE

Stop. No face scan.

Explain why the license or passport failed, issue a receipt, disclose what happened to every prior submission, and provide a bounded correction or appeal route without biometric escalation.

“Document negative → stop. Document positive → a disclosed biometric step may proceed. A positive face result cannot cure a failed document.”
License / passportFace / livenessOutcomeRequired treatment
PASSPASSVerified

Verification may close only after the person receives a custody receipt, vendor disclosure, retention terms, and a reviewable result.

PASSFAILNot verified

Explain the biometric failure. Permit only a bounded retry with clear notice and renewed consent. Never label the identity verified.

FAILPASSNot verified

The positive face result cannot cure a failed license or passport. Quarantine or delete the biometric record unless a new valid document and renewed consent create a lawful positive path.

FAILFAILNot verified

Stop collection. Explain why the document failed, preserve the receipt, disclose retention or deletion, and provide a correction or appeal route.

Collection creates a duty to account.

The person must be able to see where every license, passport, selfie, face scan, and liveness record went; who processed it; what was created from it; how long it was retained; whether it was disclosed; and when it was deleted or placed under verified restriction.

Open the supporting Identity Verification Chain of Custody Standard →

The governance gap

One collision can become an entire false identity.

Identity systems rarely fail in isolation. A bad match can alter access, eligibility, billing, security, records, verification, reputation, and the person’s ability to prove who they are.

01

Common-name collision

Two real people are merged, substituted, or treated as interchangeable because their names match.

02

Placeholder contamination

A lawful identity is confused with a default, example, test, synthetic, or nameless record.

03

Cross-system propagation

One bad association travels through vendors, exports, identity graphs, eligibility systems, or shared services.

04

Human disbelief

The person is treated as less credible because their lawful name resembles a generic or placeholder identity.

Two-level discrimination

Human disbelief + system collision

Placeholder-name discrimination operates twice: a person may be disbelieved by a human decision-maker while automated systems simultaneously merge, suppress, substitute, or contaminate their records. The Act treats both as connected governance failures.

The proposed standard

Eight enforceable organizational duties

The burden belongs to the organization that designed, selected, connected, or relied on the identity system—not to the person forced to compete with its synthetic or incorrect record.

01

Detect before deciding

Screen for collisions among real, duplicate, placeholder, synthetic, training, test, and nameless records before identity-dependent action.

02

Isolate synthetic records

Prove that non-human and test identities are technically separated from production identity, payment, biometric, credential, and account systems.

03

Hold adverse action

Place an immediate identity-integrity hold when a collision is suspected. Do not suspend, deny, downgrade, close, or accuse during review.

04

Preserve the trail

Retain access logs, source records, joins, transformations, confidence scores, changes, handoffs, and downstream disclosures.

05

Disclose the source

Tell the person which record, system, vendor, match rule, or decision introduced the disputed identity information.

06

Correct the network

Repair every downstream recipient and connected system—not only the screen where the error became visible.

07

Confirm restoration

Provide written confirmation of what was corrected, where it was corrected, who was notified, and what remains under review.

08

Repair the harm

Provide a meaningful route to recovery for losses, denial, delay, exposure, reputational damage, and labor imposed by misattribution.

Burden of proof

The organization must prove isolation.

The organization bears the burden of proving that its placeholder, synthetic, test, duplicate, or nameless records were technically isolated and did not contaminate the real person’s identity, accounts, addresses, payments, credentials, documents, biometrics, or records.

Individual protections

The Identity Integrity Bill of Rights

01

Notice of a suspected or confirmed identity collision

02

Immediate identity-integrity hold and protection from adverse action

03

Access to source, matching, access, change, and disclosure records

04

A named human reviewer with authority to correct the record

05

A meaningful opportunity to submit contextual evidence once

06

Correction across all recipients and dependent systems

07

Written closure only after the person can verify restoration

08

Recovery for measurable losses caused by misattribution

Implementation pathway

Ready for policy, procurement, regulation, and law.

Platforms & vendors

Add collision controls, identity-integrity holds, source disclosure, and downstream correction to support and trust systems.

Healthcare & finance

Prevent common-name and placeholder contamination from reaching records, payments, eligibility, or identity verification.

Government

Use the Act as model legislative language, agency policy, procurement requirements, or an auditable redress standard.

Auditors & regulators

Test isolation, trace record lineage, measure resolution time, and require proof that corrections propagated.

Model policy clause
“No person shall bear the burden of disproving, untangling, or competing with a placeholder, synthetic, test, duplicate, or misattributed identity created, maintained, connected, or relied upon by an organization.”

Originator and Author of Record

April Smith, J.D.

Systems Governance & Safety · Governance Architect · Creator of PIAIF

April Smith created this Act and its Positive / Negative Sequential-Consent Logic from documented systems analysis and lived evidence. It belongs within her broader identity-integrity and systems-governance work.

View the central authorship record →

The governing principle

A real person must never be forced to compete with a false identity created by a system.

Identity integrity is not a customer-service courtesy. It is an organizational duty.

Return to the Act