Phil Aitken, Global Chief Information Security Officer, GBG
Reports have confirmed a widespread data breach involving drivers' licence and identity documents, allegedly including infrared and ultraviolet scans utilised for authenticating physical IDs. This incident is the latest in a series across our sector this year, serving as a valid reminder for organisations that depend on document verification to reassess their vendor selection and auditing processes.
Document verification providers hold some of the most sensitive data that exists: government IDs, biometric scans, personal identifiers that can't be reissued the way a password can. That's a different category of responsibility compared to most SaaS businesses, and it should be treated that way from the beginning, not patched on later.
Privacy, regulatory and security requirements are built into how we operate. We maintain governance, oversight and appropriate external certifications because we recognise the duty of care we have to our customers and their customers. You can learn more about our policies, processes, standards and certifications in our Trust Centre. Most vendor conversations centre on match rates, speed and fraud detection accuracy. Fewer focus on what happens to the document after it has been checked, although that is often where the real risk lies.
Whilst passwords can be changed the information lost if an identity is breached can have life long consequences for people. A compromised driver's licence, especially one that includes the security layers designed to prove it's genuine, is much harder to remediate. A driver's licence carries more than a photo: infrared and ultraviolet layers, chip data, and other embedded features exist specifically to defeat forgery. When those layers are exposed, the very features meant to defeat fraud become tools for it.
One of the main principles we've upheld over the years is that document persistence should be a choice, not a default. Our platform can process and verify an identity document without retaining it — verify, then delete. If a customer has a legitimate business need to retain data, for a better user experience, for example, that's available on their terms as well.
The tradeoff is real. Retained data can be useful for interface continuity, model improvement, and audit trails. We think the right answer is to give organisations that choice explicitly, rather than making retention an invisible platform default.
If this news has prompted your own security, privacy or fraud teams to take a closer look at your identity verification stack, here’s what we would focus on:
With over twenty years supporting highly regulated organisations worldwide, we have developed document authentication capabilities designed to verify government-issued IDs, detect fraudulent or tampered documents and strengthen confidence in identity verification processes. While this expertise does not eliminate all risks, it helps ensure our approach is built to withstand rigorous scrutiny.
If you have any questions about your document verification setup, data management or retention policies, reach out to us anytime.
Phil Aitken is Global Chief Information Security Officer, GBG