Not a vulnerabilityNothing is exploited. The number is read from a document or a field the person supplied, exactly as the builder intended, and forwarded by design. A vulnerability register has no place for a transfer that works correctly.
What it is
A system reads a national identification number, either from a field the person fills in, from the machine-readable zone or chip of an identity document, or from a record it already holds, and sends it onward to a party that performs no task for which a state assigned that number. The number frequently travels as part of a larger blob, such as raw document data, rather than as a labelled field.
Why it is a separate entry
This number is the key that joins registers which are meant to stay apart. Unlike a cookie it cannot be reset, it is the same number for a lifetime, and once a private party holds it, every later dataset can be matched on it. In much of the EEA private use is restricted precisely because of that property.
How it arises
a document or chip read in full and uploaded as a whole, with the number inside it
an onboarding flow that asks for the number because a form template contained the field
an identifier reused as an internal customer key after it entered the system for another purpose
Not to be confused with
A party with a statutory task that requires the number, such as a tax or healthcare body, is not this entry. Nor is a check that returns only a yes or no derived from the number. The distinguishing feature is that the number itself reaches a party for which no statute provides.
How to establish it
A request body or upload containing a value that satisfies the structural check for the national identification number in question, sent to a host operated by a party other than the one with the statutory task. Where the number is embedded in raw document data, the finding is the presence of that field within the payload.
method network-with-identifierQoD 88
Requirements on the measurement
use your own document and your own account; this is the one place where a measurement must never involve someone else's identity
capture the payload, not only the request line; the number is usually in the body or in a binary blob
note where the number came from: typed field, machine-readable zone, chip file, or already held by the system
record the moment in the flow at which it is sent, since sending before any service is requested is a separate question from sending at the point of a check
What would refute it
by handThe receiving party performs the statutory task for which the number exists.finding falls
by handThe value is not the statutory number but a structurally similar one, such as a customer or document number.Apply the checksum or structural rule for that country before claiming anything.finding falls
not from the captureThe number is transmitted only to a processor acting for the party with the statutory task, under its instructions.reclassify
by handThe person entered the number themselves in a free-text field with no prompt for it.Different finding: the system does not ask for it but does forward it.weakens
Where this plugs into existing processes
The one question that surfaces itShow me every field that leaves during identification, including what is inside the document data you upload.
In a DPIA, verify this
Verify which fields actually leave during identification, byte for byte, rather than the field list in the supplier's description.
As a procurement clause
No national identification number leaves the controller's own environment, demonstrated on delivery by a capture of a complete onboarding.
With a complaint, hand over
The captured payload with the number located in it, the structural check that confirms what it is, and the point in the flow at which it was sent.
Reproduction
METHOD.md · by hand · no dedicated reproduction exists yet; follow the general method and the indicator above
Legal framing
nl-uavg-46
eu-gdpr-5-1-c
eu-gdpr-6-1-a
Objections, and the answer
“The person consented to identity verification.”
Consent to being identified is not consent to a specific number reaching a specific party, and where national law restricts use of the number, consent does not lift that restriction.
“We do not use the number, it merely passes through.”
Receiving is processing. If it is not used, it did not need to be sent, which is the finding rather than a defence.
“It was inside the document data, we did not ask for it.”
Reading a document in full is a choice about what to read. The number is in the payload either way, and the party that built the read decided its scope.
What this does not establish
harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
unlawfulness; that is for a supervisory authority or a court
intent; a fault is usually a build decision, not a plan
absence: not finding it in one capture is not evidence that it is not there
DPE Catalogue. DPE-2026-0017: Statutory identification number to a third party. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0017
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0017, established under DPE Measurement Method 1.0”
Identifiers are permanent and are never
reused. An entry that is deprecated keeps its number and its address, with the reason attached, because
references to it exist elsewhere.