Account atelier
A request should explain its lawful purpose
The operator should identify which entity collects the document, why it is required, which fields are necessary and what happens if the request is declined. A generic chat demand or sudden request from a new domain is insufficient. Verification should not be used as a reason to collect unrelated information.
- ANamed collecting entity
- BSpecific purpose
- CData minimisation
Account atelier
Use only a verified secure channel
Email attachments and messaging apps can expose identity documents to interception or impersonation. Confirm the domain and published upload route independently. Where appropriate, add a purpose-specific watermark without obscuring required details, retain a copy of what was supplied and never include account passwords or one-time codes.
- AVerify the upload route
- BConsider a watermark
- CNever include login secrets
Account atelier
Retention and deletion deserve an answer
A privacy policy should state how long identity records are held, which processors receive them, where they may be transferred and how access or deletion requests work. Closing an account may not erase records immediately when a lawful retention duty exists, but an operator should explain the basis rather than promising instant deletion.
- ARetention period
- BProcessor and transfer detail
- CQualified deletion rights