Copying identity cards – allowed or not?

13 August 2019

Recently, the statement "prison for photocopying an ID card" has been heard quite frequently. This is due to the Public Documents Act, which came into force on July 12, 2019. Below, we explain what this actually means and what restrictions this law entails.

At the outset, it is worth noting that the Act on Public Documents encompasses not only identity cards but also a whole catalog of documents – as contained in Article 5 of this Act. This catalog is divided into three categories, depending on the significance of the document for the security of the state.

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay up to date.
RECEIVE PACKAGE
The identity card is at the top of the list of the first category of documents, while other items include: passport, civil status certificate, driving license, police officers' service IDs, documents confirming professional qualifications, school completion certificates, and student IDs.

What is the main purpose of the Act on Public Documents?

What is the main purpose of the Act on Public Documents? To dispel any doubts that have arisen in connection with the entry into force of the Act on Public Documents, it should be pointed out that its aim is not to combat the phenomenon of photocopying identity documents by various institutions, such as banks, insurers, or other entrepreneurs who engage in such practices in their operations. The Act on Public Documents does not contain regulations regarding the collection of personal data, for example, as a result of photocopying or scanning documents. In such cases, the provisions of the GDPR will apply first and foremost.

The main objective of the law is to combat document forgery, impersonation crimes, and numerous frauds involving loans or credits. As indicated by the Polish Data Protection Authority, the practice of impersonating others to obtain loans or purchase valuable items on credit has significantly intensified due to so-called collector's documents. These documents closely resemble original identity cards or driving licenses. Therefore, to take out a loan, it was sufficient for a fraudster to order a collector's document and provide the details of another person. According to a report prepared by the Polish Bank Association based on data from the Credit Information Bureau, in the very first quarter of 2019, 1,117 attempts to defraud loans amounting to a total of PLN 63,291,030 were thwarted. The new law on public documents aims to complicate this practice.

Imprisonment for creating a replica of an identity card

According to the wording of the new regulations, anyone who produces, sells, or possesses a replica of a public document for the purpose of disposal may be subject to a fine, restriction of liberty, or imprisonment for up to 2 years. The law also defines what constitutes a replica of a public document. Namely, a replica will be a copy or reproduction, for example, of an identity card or another document referred to in the law, sized between 75% and 120% of the original and possessing the authenticity features of a public document.

The Polish Data Protection Authority points out that the concerns of entrepreneurs that criminal liability under the new regulations threatens any copying or printing of public documents for official, business, or professional purposes, as defined by separate regulations, or for the use of the person for whom the public document was issued, are misguided.

Nevertheless, the Polish DPA simultaneously emphasizes that before making a copy of, for example, an identity card or driving license, one should consider whether such action does not violate the law on public documents. One may become the subject of interest of law enforcement authorities if they determine that a replica of a public document has been made, rather than a photocopy.

Data minimization principle

When preparing a copy of a document, it is important to remember the data minimization principle expressed in the GDPR. The Polish Data Protection Authority indicates that when examining the justification for collecting photocopies of documents by an entrepreneur, it will pay particular attention to the scope of data retained by them.

GDPR Compliance Diagnosis - do it yourself!

A business that photocopies an identity card should primarily consider whether it has a valid legal basis for processing all personal data contained in the document. An identity card – in addition to the card number, first name, last name, and date of birth of its holder – contains a number of other pieces of information about the individual, such as their image, maiden name, parents' names, place of birth, height, eye color, and PESEL number. Often, a business that makes a copy of an identity card does not have a legal basis (as expressed in Article 6 of the GDPR) for processing all the data contained therein. Therefore, it is crucial to analyze the necessity of making a copy of the document beforehand. In the event of an inspection, the supervisory authority will undoubtedly verify whether the scope of data processed by the business is limited to what is necessary for the purposes for which the data is processed, and thus – whether the entity does not violate the principle of data minimization, as expressed in Article 5 of the GDPR.

When can a photocopy be made?

As previously explained, the provisions of the Public Documents Act do not prohibit the making of photocopies of individual documents. This does not mean, of course, that businesses can photocopy identity cards, passports, and other documents at their discretion. In this regard, it is essential to keep in mind the applicable regulations concerning personal data protection, due to the wide range of personal data contained in the relevant documents.

A business that wishes to make and store photocopies of documents, including identity cards, should particularly pay attention to whether the applicable laws authorize them to do so. Banks come to mind as entities authorized to undertake such actions. According to the position of the President of the Polish DPA, such practice is permissible only in specific situations. The Polish Data Protection Authority explains that it would be an abuse for a bank to make a photocopy of an identity card when opening an account, checking creditworthiness, or entering into a credit agreement.

Banks, justifying the necessity of making a copy of an identity document, refer to Article 112b of the Banking Law. It is worth remembering that the cited provision only authorizes them to process data contained in identity documents and does not in any way constitute permission to make copies of the discussed documents.

Another act that should be mentioned in this context is the Act on Counteracting Money Laundering and Terrorist Financing, specifically its Article 34(4). According to the content of this provision, certain entities are authorized to make copies of identity documents for the purposes of applying financial security measures. Among the entities authorized to copy identity documents under the mentioned act are, in particular, banks and insurance companies. These entities have the right to process personal data contained in identity documents and to store copies thereof in case of doubts regarding the legality of the financial operations conducted. Institutions covered by the scope of the act are obliged to demonstrate to the relevant authorities specified in the act that, taking into account the level of identified risk of money laundering and terrorist financing associated with the given economic relationships or occasional transaction, they have applied appropriate financial security measures. Financial security measures include, among others, customer identification and verification of their identity.

However, it should also be noted that the Act on Counteracting Money Laundering and Terrorist Financing does not authorize the entities specified therein to photocopy identity documents for purposes other than ensuring financial security.

Student ID

Following the entry into force of the Act on Public Documents, many employers hiring students under civil law contracts also have doubts. The provisions of the Act on the Social Insurance System indicate that a student who works under a civil law contract and has not yet reached the age of 26 is not subject to mandatory retirement and disability insurance. Consequently, the Social Insurance Institution, in the event of conducting inspections at an employer hiring students under civil law contracts for whom contributions are not paid, particularly requires the submission of a copy of the student ID.

Free GDPR advice
There are no stupid questions regarding GDPR.
There are free answers
Take advantage of free legal or IT advice.
I HAVE A QUESTION
Due to the fact that the student ID has been included in the list of public documents specified in Article 5 of the Act on Public Documents, concerns have arisen among employers. However, these concerns are unfounded, as we are once again dealing with a situation where a copy of the document is necessary to fulfill the obligations imposed on the employer by applicable legal regulations, and thus it does not fall within the scope of the Act on Public Documents. The employer will not store a replica of the student ID that could be used for illegal purposes, but only a copy of the ID for the potential purpose of providing it to the Social Insurance Institution.

It is therefore important to carefully analyze the changes introduced in the regulations and not always rely on the headlines of articles available online. In particular, it is necessary to distinguish between a replica and a photocopy of the document, which is not covered by the Act on Public Documents. Of course, unjustified photocopying of documents and the accumulation of excessive personal data will never be justified from the perspective of applicable personal data protection regulations; however, in situations provided for by law, entrepreneurs have such a possibility. At the same time, the Polish DPA reminds us that if we previously agreed to copy our ID, we always have the right (based on the rights specified in Article 17 GDPR) to request the data controller to delete such data. In justifying the request for data deletion, it should be indicated that the personal data was collected in violation of the law and exceeds the permissible scope. Furthermore, it is worth remembering that if this request is not fulfilled, the individual has the right to lodge a complaint with the President of the Polish DPA.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.