DPE-2026-0043

Registers joined on a person number

Records collected under one statutory task are joined to another body's records on the statutory number.

In het NederlandsRegistraties gekoppeld op persoonsnummerWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Chain APIwebdesktop status active
Not a vulnerabilityNothing is broken into. The bodies exchange deliberately, usually under an arrangement they wrote themselves, and the objection is to the combination rather than to a defect.

What it is

Two public bodies each hold records for their own statutory purpose. The statutory personal number makes joining them trivial, so a file, a query facility or a shared environment comes into being in which records from both sit next to each other about the same person. The combination answers questions neither register was created for. The person sees only the outcome: a check, a selection, a decision that draws on information they gave somewhere else.

Why it is a separate entry

Each register was justified separately and the combination was justified nowhere. A person cannot see which body drew on which source, cannot correct a record at the body that used it, and cannot avoid the number, because it is assigned to them. The combined set then becomes the reason to keep data longer, share it further and select on it.

How it arises

Not to be confused with

A statutory number reaching a party with no statutory task is Statutory identification number to a third party, where the recipient should not hold it at all. Here both bodies may hold the number, and the fault is the joining of records collected for different purposes. Two commercial parties matching identifiers is Identifier synchronisation between parties.

How to establish it

An access request to one body returns fields that only the other body collects, or the body's own processing register names a source it does not collect itself. Both are documents the body publishes or must supply, and the comparison is a set difference on the fields.

method document-comparisonQoD 80

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itWhich provision permits combining these two registers, as opposed to holding each of them?
In a DPIA, verify this

Verify which provision names the combination, rather than the provisions that name each of the two registers.

As a procurement clause

A platform serving several bodies keeps their records separated, and a join requires a provision named per query and logged with it.

With a complaint, hand over

The access request answers from both bodies, the field that can only have come from the other, and the processing register entry of the same date.

Reproduction

Legal framing

Objections, and the answer

“Both bodies are allowed to use the number.”

For their own task, yes. The number is what makes the join cheap; it is not what makes it permitted. The provision has to name the combination.

“It is all one government.”

Not in law. Each body has its own task and its own basis, and that separation is the reason a person can give information to one without giving it to all.

“We only exchange what is necessary.”

Then the exchange answers a question and retains nothing. A stored combination is a different thing, and the two can be told apart by asking what is kept.

“The person can request access, so it is transparent.”

Access is a right, not a justification. That the combination becomes visible when someone asks does not establish that it was permitted.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0043 (Registers joined on a person number)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0043
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0043/index.json
Full
DPE Catalogue. DPE-2026-0043: Registers joined on a person number. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0043
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0043, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.