Comment by chezelenkoooo

3 hours ago

Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure.

So most businesses are not permitted to just delete the data.

Back In The Day, if somewhere like a car hire agency wanted to record proof of identity they'd photocopy your driver's license on paper, and store it in a filing cabinet. The computer record of a customer's account would just say "driving license checked, on file at branch #1234"

Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.

Regulatory retention is a valid reason for some of this data to exist. It isn't a blanket justification for every intermediary in the verification chain to retain its own permanent copy. If anything, that makes minimizing the number of copies even more important.