I hit them with the fact that a person controlling the e-mail address can use their ‘Forgot password’ feature to take control over the account and access my sensitive data they’re in possession of or steal my identity using their own services.
this was their excuse to why they won’t delete my info without proof of ID.
I told them no, I told them that if my bank or phone provider or online grocer who all have much more important and sensitive info, namely my payment/bank details, can verify me without extra documentation, so can they, they still said no.
So I’ve filled a complaint with the ICO, there’s fuck all else I can do unfortunately…
Yeah, this is how it’s always gone for me before, which is why I’m so taken aback by this company’s demand…
Which they can by asking me to confirm who I am from the information they already have, the whole point is that they’re demanding I provide additional documentation to prove my identity, which is complete overkill* and something that I have never come across, and shouldn’t have to comply with.
But either way, if they need my ID before they’ll provide my info, asking for it to try and catch them on a mistake only to be met by the same barrier (them demanding ID), it isn’t going to work…
*(My brain can’t deal with that document you linked right now, but the relevant governing body here (ICO) say “The organisation might need you to prove your identity. However, they should only ask you for just enough information to be sure you are the right person.”
That’s just not true, I’ve put through a ton of requests in the past, for companies that had much more sensitive data (like payment details) and have never been asked for ID.
Thanks for clearing that up, definitely not looking for compensation or anything, just for my request for deletion to be respected, but adding something like that to a complaint would definitely help. Thanks!
Thanks that’s more clear, but will they not just ask for an ID again before they’d agree to send that info?
Considering the information I’m asking them to delete, yes.
first ask for a listing of all the information they have about you, before asking for deleting your data. this listing must contain the request itself. if your request is missing, they are likely breaking compliance rules.
I’m not quite understanding, do you mind breaking that down for me?
Their reply:
The reason that we ask for ID is to safeguard your personal data by verifying that the request is genuine before proceeding with deleting your personal data. This process is consistent with guidance published by the Information Commissioner’s Office. (https://ico.org.uk/your-data-matters/your-right-to-get-your-data-deleted/)
The purpose of this process is to prevent someone unauthorised from requesting deletion of your data, for example where there are shared email addresses, or someone has access to your account or email address, or where someone is spoofing your email address. Please see our Privacy Policy (xxxxxx) for more information about personal data we collect store and process.
Please be assured that when you send ID to our dedicated ID email address, this is automatically and permanently deleted from our systems within 7 days. We do not continue to store or process your ID beyond this time or use it for any other purpose other than to verify your identity to action your erasure request.
If you would prefer not to send ID via email, you can post copies to our address and upon receipt from our team we will then securely dispose of the copies. Please send these to:
Data Protection Team,
xxxx
xxx
xx
I hope the above explains our rationale and allays any concerns you may have. If you have any further questions please do not hesitate to ask.
It is, had a proper look and also definitely not what they’re meant to be doing:
https://ico.org.uk/for-the-public/your-right-to-get-your-data-deleted/#:~:text=The%20organisation%20should%20delete%20your,impossible%20or%20involve%20disproportionate%20effort.
I replied saying no, and told them again to delete my data.
Took me a minute to find, but that’s really great info, thanks!
I’ve already filled a complaint with the ICO since the company continued to refuse to delete my data, so we’ll see what they come back with (their own guidelines say something very similar - “they should only ask you for just enough information to be sure you are the right person”) if they side with the company I will definitely be quoting these guidelines.