DPE-2026-0017

Statutory identification number to a third party

A number a state assigns for identification is transmitted to a party that has no statutory task requiring it.

In het NederlandsWettelijk persoonsnummer naar een derdeWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Data appwebAPI status active
Not a vulnerabilityNothing is exploited. The number is read from a document or a field the person supplied, exactly as the builder intended, and forwarded by design. A vulnerability register has no place for a transfer that works correctly.

What it is

A system reads a national identification number, either from a field the person fills in, from the machine-readable zone or chip of an identity document, or from a record it already holds, and sends it onward to a party that performs no task for which a state assigned that number. The number frequently travels as part of a larger blob, such as raw document data, rather than as a labelled field.

Why it is a separate entry

This number is the key that joins registers which are meant to stay apart. Unlike a cookie it cannot be reset, it is the same number for a lifetime, and once a private party holds it, every later dataset can be matched on it. In much of the EEA private use is restricted precisely because of that property.

How it arises

Not to be confused with

A party with a statutory task that requires the number, such as a tax or healthcare body, is not this entry. Nor is a check that returns only a yes or no derived from the number. The distinguishing feature is that the number itself reaches a party for which no statute provides.

How to establish it

A request body or upload containing a value that satisfies the structural check for the national identification number in question, sent to a host operated by a party other than the one with the statutory task. Where the number is embedded in raw document data, the finding is the presence of that field within the payload.

method network-with-identifierQoD 88

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itShow me every field that leaves during identification, including what is inside the document data you upload.
In a DPIA, verify this

Verify which fields actually leave during identification, byte for byte, rather than the field list in the supplier's description.

As a procurement clause

No national identification number leaves the controller's own environment, demonstrated on delivery by a capture of a complete onboarding.

With a complaint, hand over

The captured payload with the number located in it, the structural check that confirms what it is, and the point in the flow at which it was sent.

Reproduction

Legal framing

Objections, and the answer

“The person consented to identity verification.”

Consent to being identified is not consent to a specific number reaching a specific party, and where national law restricts use of the number, consent does not lift that restriction.

“We do not use the number, it merely passes through.”

Receiving is processing. If it is not used, it did not need to be sent, which is the finding rather than a defence.

“It was inside the document data, we did not ask for it.”

Reading a document in full is a choice about what to read. The number is in the payload either way, and the party that built the read decided its scope.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0017 (Statutory identification number to a third party)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0017
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0017/index.json
Full
DPE Catalogue. DPE-2026-0017: Statutory identification number to a third party. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0017
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0017, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.