Why Are You Still Saving IDs?
Someone recently rented a car and found their driver’s license for sale on the dark web within hours. They aren't the only one. Over 150 million licenses are currently circulating on a new dark web platform.
If your business process involves taking a photocopy or a digital scan of a customer's ID to "keep on file," you haven't built an archive. You've built a target.
Most small firms treat identity documents as static evidence. You check the license, scan it into a folder called 'Client Onboarding', and leave it there for five years because you’re worried some future auditor might ask if you actually verified the person.
That's a mistake. The risk of holding that image far outweighs the benefit of having it as proof. When you store an unencrypted JPEG of a passport or license on a shared drive, you aren't just storing a name; you're storing everything a fraudster needs to open a bank account in your client's name.
Delaware has already started tightening breach reporting and expanding privacy protections. While you might not be based in Delaware, the trend is clear. Regulators are losing patience with firms that collect "just in case" data.
You’ll hear consultants tell you to simply implement a sophisticated Identity Access Management (IAM) system. That's expensive, over-engineered for a ten-person office, and usually ends up being ignored by staff who find the login process too slow.
The cheapest control is the one that removes the risk entirely: stop storing the image.
If you need to verify an identity, do it in real-time. Look at the ID, confirm it matches the person, and then tick a box in your CRM that says "ID Verified - [Date] - [Staff Name]". That is your evidence. A timestamped log entry is far more useful to an auditor than a grainy photo of a license from 2021 that you can't even prove hasn't been tampered with.
The strongest objection here is usually the "compliance requirement" argument. You'll be told that certain regulations require you to maintain records of identity verification for several years.
Read those rules again. Very few actually demand you keep a copy of the document itself. They demand proof that the verification happened. There is a massive difference between an audit trail and a treasure trove of PII. If your internal policy says you must keep the scan, change the policy. The policy is not the law; it's just a habit someone wrote down three years ago.
The second-order effect here hits your insurance. Most Professional Indemnity or Cyber policies have clauses about "reasonable security measures." If you have a breach and the forensic report shows you were storing hundreds of raw ID scans in an unencrypted folder, your insurer has a very convenient reason to deny the claim. You've essentially created a liability that your policy isn't designed to cover.
If you absolutely cannot stop collecting them—perhaps because of a specific contractual obligation with a larger client—don't just put them in a folder.
Put them in a password-protected zip file or use an encrypted vault. Better yet, set an auto-delete trigger. If the law says you need to keep the record for three years, the file should vanish at 36 months and one day. Manual deletion never happens; the "cleanup" folder only grows until the drive is full or the hackers arrive.
I'm not saying you should ignore KYC rules. I'm saying that hoarding digital copies of government IDs is a lazy way to handle compliance that creates an enormous amount of risk for almost zero actual utility.
If your current process involves a scanner and a folder, you aren't being thorough. You're just collecting ammunition for the next data breach.
Check the 'Client Onboarding' or 'KYC' folder on your shared drive this week and delete every ID scan that is older than your legal retention period.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- Data breach at South Korean streaming service Tving affects 39 million accounts - MLex Data Privacy (Google News)
- Thailand to Enforce Crypto Travel Rule in 2027 With Stricter Transfer Checks - CryptoRank Compliance Week (Google News)
- SEC proposes N5bn capital threshold as Nigeria tightens online forex - blueprint.ng Compliance Week (Google News)
- Thailand Implements Crypto“Travel Rule” Via Self-Custody Wallet Checks - Menafn Compliance Week (Google News)
- Florida Revokes License Plate Reader Approvals Amid Privacy Concerns - SSBCrack Data Privacy (Google News)
- Delaware Expands Privacy Protections, Tightens Breach Reporting - Bloomberg Law News Data Privacy (Google News)
- Fla. bans ALPRs installed by local law enforcement from all state roads - Police1 Data Privacy (Google News)
- 153M+ driver’s licenses for sale on new dark web platform - malwarebytes.com Data Privacy (Google News)