Not a vulnerabilityNothing is exploited and nothing fails. The reader captures what it was built to capture; the objection is to that scope, not to a defect in it.
What it is
To answer a narrow question, such as whether someone is over eighteen or whether a name matches, the system photographs or chip-reads the document in full and transmits everything it obtained: the complete machine-readable zone, the portrait image, the security object, the document number, the nationality. The relying party frequently receives, and needs, only a yes or no.
Why it is a separate entry
The person shows a document to answer one question and hands over a permanent dossier instead: a face image usable for recognition, numbers that never change, and a nationality that was nobody's business. The gap between what was asked and what was taken is invisible at the moment it happens, because the interaction looks like holding a card against a phone.
How it arises
a verification component that reads all available data groups because the reader supports them
the whole capture uploaded for server-side processing, with the narrowing done afterwards
an image retained as proof of the check rather than the result of the check
the comparison performed by a remote service, so the image travels even where the device could do it
Not to be confused with
An ordinary identity check, where a person shows a document and a human or a system compares it, is not this entry. Nor is a chip read that stays on the device and yields only a derived answer. The distinguishing feature is that material beyond what the question needs leaves the device.
How to establish it
The upload during a check contains fields or files beyond those needed for the stated question: a portrait image or a complete machine-readable zone where the result exposed to the relying party is a single attribute or a boolean. The comparison between what was transmitted and what the result contains is the finding.
method network-with-identifierQoD 85
Requirements on the measurement
your own document only, on a device you control
capture the payload of the upload, not only its size; the finding is which fields are in it
record what the relying party receives back, since the gap between the two is the measurement
note whether the narrowing happens on the device or after the upload; only the first avoids the transfer
What would refute it
by handThe relying party needs the full data set for a task set out in law, such as a statutory identification duty.finding falls
automatedAll processing happens on the device and only the derived answer leaves it.finding falls
by handThe extra fields are needed to verify the authenticity of the document itself.Authenticity checking can require the security object. That justifies reading it, not retaining it, and the two are separate questions.weakens
by handThe person was offered a check that reads less and chose the wider one.weakens
Where this plugs into existing processes
The one question that surfaces itWhat question does this check answer, and what exactly leaves the phone in order to answer it?
In a DPIA, verify this
Verify which data groups the reader actually extracts and transmits, against the single question the check exists to answer.
As a procurement clause
The check returns a derived attribute and the source material stays on the device, demonstrated on delivery by a capture of one complete check.
With a complaint, hand over
The captured upload with its field list, the answer the relying party received, and the difference between them.
Reproduction
METHOD.md · by hand · no dedicated reproduction exists yet; follow the general method and the indicator above
Legal framing
eu-gdpr-5-1-c
eu-gdpr-9-1
eu-gdpr-13
Objections, and the answer
“We need the document to establish that the person is who they claim.”
That is the question, and the question can be answered with the answer rather than the source material. Reading in full and narrowing afterwards is a design choice, and the transfer has already happened by then.
“The portrait is only used for the comparison.”
A face image processed for unique identification is a special category regardless of how briefly it is used. Use and category are separate questions.
“The consent screen explained it.”
Test that. Compare the field list the person was shown with the field list in the payload; where the second is longer, the explanation was not of this processing.
“The comparison has to happen in the cloud.”
That is a build decision, not a necessity: comparison on the device is demonstrably possible. Where it happens remotely, the sample leaves and the transfer question follows it.
What this does not establish
harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
unlawfulness; that is for a supervisory authority or a court
intent; a fault is usually a build decision, not a plan
absence: not finding it in one capture is not evidence that it is not there
DPE Catalogue. DPE-2026-0018: Identity document read beyond the check. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0018
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0018, established under DPE Measurement Method 1.0”
Identifiers are permanent and are never
reused. An entry that is deprecated keeps its number and its address, with the reason attached, because
references to it exist elsewhere.