Imagine discovering, while checking your bank records, that a lending institution is already demanding monthly payments for a loan you never signed for. This is precisely what a female employee experienced after attempting to exercise her right to be forgotten with her former employer. What began as a seemingly harmless, almost administrative step turned into a genuine financial nightmare, revealing in the process a flaw broader than this isolated case: humanity’s instinctive reactions to requests for personal documents.
- A female employee sent her identity card and her bank details for a GDPR request, and six weeks later a fraudulent loan was opened in her name
- GDPR never requires a RIB or a full, front-and-back identity card to verify identity; a partially masked document suffices
- You should mask sensitive information on an identity card, add a handwritten note detailing the document’s purpose, and never transmit a RIB for a procedure that involves no money transfer
- When a simple GDPR request turns into a financial nightmare
- The classic trap: why companies demand documents they should never require
- Six weeks of silence, then the discovery that changes everything
- What the law really says about deleting your personal data
- The reflexes to adopt before sending any document to a company
When a Simple GDPR Request Becomes a Financial Nightmare
It all starts with a laudable intention: to stop letting personal information linger with an employer you left months ago. The process is called a data deletion request, governed by the General Data Protection Regulation, more commonly known by its acronym, GDPR. On paper, it seems straightforward: an email or a letter, and the company must comply within a reasonable timeframe. In practice, however, some organizations demand disproportionately burdensome supporting documents, under the pretext of verifying the requester’s identity. This is how the victim of this story ended up sending a copy of her identity card and, even more surprisingly, a bank statement, the infamous RIB. A gesture of trust that would carry consequences far heavier than anticipated.
The Classic Trap: Why Companies Demand Documents They Should Never Require
This scenario is sadly not isolated. Many HR departments, sometimes due to ignorance of the rules, sometimes due to misguided caution, request proofs that have no bearing on the purpose of the request. Verifying someone’s identity to delete an employee file theoretically requires only a simple, partially masked identity document, never a RIB. The latter, however, contains highly sensitive data: the IBAN, the name of the bank, and sometimes enough information to initiate direct debits. Coupling a full identity card with a RIB essentially provides all the keys needed to commit identity fraud. It is precisely this explosive mix that allowed, in this case, a fraudulent credit to be opened in the victim’s name.
Six Weeks of Silence, Then the Discovery That Changes Everything
After sending the documents, there was no news for several weeks. The silence, at first, did not seem alarming: administrative services often take time to process such requests. It was while reviewing her bank history, almost by chance, that the victim spotted an unusual line: a consumer loan had been opened in her name, for which she had never applied. Six weeks had elapsed between sending the documents and this discovery, a period long enough for bank data to circulate, be exploited, and help assemble a fraudulent financing file with a credit institution that did not scrutinize its verifications. The speed with which a simple copy of a RIB can be diverted shows how these documents, often treated as routine, deserve far greater vigilance.
What the Law Really Says About Deleting Your Personal Data
The GDPR is crystal-clear on this point: a request to delete personal data never requires sending a RIB or a full, front-and-back unmasked identity card. The law allows a company to verify the requester’s identity only if there is a reasonable doubt, and that verification must remain proportionate to the objective pursued. Practically, this means that a copy of an identity card with certain details masked, such as the document number or the full date of birth, is more than enough. No regulation requires you to transmit bank details to exercise this right. Moreover, the CNIL regularly reminds that companies should not demand more than what is strictly necessary, or risk sanctions for disproportionate data processing.
The Reflexes to Adopt Before Sending Any Document to a Company
When faced with this type of request, a few simple precautions can spare you a lot of trouble. It is especially advised to:
- Never send a RIB for a process that involves no payment
- Always mask the ID number, signature, and photo when sending an identity document
- Prefer adding a handwritten note stating the exact purpose of the document, such as document transmitted solely for identity verification within a GDPR request
- Request in writing the precise legal basis justifying the request for documents
- Keep a record of all exchanges in case of later dispute
If there is any doubt about the legitimacy of a request, you can also contact directly the organization that issued it to verify its authenticity before sending anything. This vigilance, which seems almost reflexive to some, remains too infrequent in the face of administrative documents perceived as routine.
This misadventure recalls a simple rule that is all too often forgotten: every document transmitted, even in a context that seems legitimate, should be questioned before being sent. A RIB, a full identity card, these are keys that unlock far more doors than one imagines. In an era when administrative processes are increasingly online, learning to recognize a disproportionate request becomes almost as essential as knowing how to lock your door when you leave home. So, next time a company asks you for proof for a procedure that has nothing to do with money, the question to ask yourself is simple: do they actually need it?