Skip to main content
intelID
Menu

Identity

How to verify an identity in New Zealand without breaching privacy

Identity verification is a corroboration exercise, not a data grab. What to check, in what order, and what not to collect.

Published · Reviewed

Identity verification sounds like a lookup and is actually a judgement. You are deciding whether the records in front of you describe a real person, whether that person is the one you are dealing with, and whether the level of assurance you have reached matches the decision you are about to make. Done well, it uses less information than people expect. Done badly, it collects far more than it needs and still gets the wrong person.

Start with the decision, not the data

Before any search, write down what turns on the answer. Opening an account with credit exposure, serving proceedings, releasing a file to a claimed authorised person and paying out a claim all carry different consequences and therefore different assurance levels. The Privacy Act 2020 requires that collection be necessary for the purpose, so the decision sets the ceiling on what you may collect.

A useful discipline is to state the minimum sufficient result. For a routine matter it may be: "one current address confirmed by two independent records, and a name match on date of birth". Once that is met, stop. Continuing to search because more data is available is precisely what principle 1 prohibits.

The corroboration model

Identity in New Zealand is not held in a single authoritative civil register that private organisations can query. Verification is therefore triangulation across independent records that were created for different reasons at different times.

Records that carry weight

  • Company and director records. Where the subject has been a director or shareholder, the Companies Register links a name to addresses, dates and other entities. It is public, dated, and strong corroboration.
  • Property and title records. Ownership records tie a named person to a property over a period, which supports an address history rather than a single point.
  • Security interests on the PPSR. Registered interests recorded against a debtor name provide an independent creation event with a date attached.
  • Credit file address history. Usually the most current address data available, and available only where the Credit Reporting Privacy Code 2020 permits your access.
  • Directory and digital footprint information. Useful for confirming an existing hypothesis; weaker as a starting point because of age and self-reporting.
  • Insolvency records. Definitive where they exist, and material to any credit or litigation decision.

Independence is the point. Two records derived from the same original submission are one record. If a directory entry and a marketing list both trace back to a form the subject filled in five years ago, they agree with each other and prove nothing.

Handling near-matches

A near-match is a warning, not a result. Same surname and initial at a plausible address, with a date of birth out by a year, is exactly the pattern that produces wrong-person contact. Resolve it by finding a record type you have not used yet, or by asking the subject a question only they can answer, rather than by weighing the evidence you already have more generously. Where the match cannot be resolved, report it as unresolved. Most wrong-person contacts originate in an unresolved near-match that was recorded as a match.

Minimisation in practice

Minimisation is easier to describe than to do, because thorough people like completeness. Three habits make it real.

First, choose sources in sequence rather than in parallel. Run the source most likely to answer the question, then stop and assess. Running everything at once guarantees you collect information you did not need.

Second, keep the finding, not the haystack. If the decision required a confirmed current address, retain the confirmed address and the two source references, not the full extracts of every record you looked at.

Third, separate verification from investigation. Confirming that a customer is who they say they are is not licence to build a picture of their affairs. If a genuine investigative need arises later, it is a new purpose with its own declaration.

Fairness and intrusiveness

Principle 4 requires that collection be fair and not unreasonably intrusive in the circumstances. Two applications matter here. Never obtain information by pretext — claiming to be the subject, a relative, or an official is unlawful collection. And be careful about collecting from people around the subject: asking a neighbour or an employer about someone discloses that you are enquiring into them, which is itself a disclosure with consequences.

The record to keep

The evidence of a good verification is short: the decision it supported, the assurance level required, the sources used, the identifiers matched, who ran it and when, and the conclusion reached including any residual doubt. If you cannot produce that in a paragraph, the process was not controlled.

intelID captures the same material as a by-product of the search: an authorised-purpose declaration before the query, role-based access limiting which sources a user can reach, and a full audit record afterwards. See how a search runs, the sources available, and the authorised-purpose article for the declaration wording. Teams with AML obligations should also read the corporate and compliance page.

Access to intelID is limited to verified, licensed users. You can request access or read our compliance position first.

Questions on this topic

What counts as verifying an identity?

Establishing, to a level appropriate to the risk, that a person exists and that the person you are dealing with is that person. It is a corroboration exercise across independent records, not a single lookup.

How many sources should agree?

At least two independent records that agree on the identifiers you rely on. For higher-risk decisions, add a third and record why the extra check was needed.

Is collecting a date of birth always justified?

Only where it is necessary to distinguish the subject from others with a similar name. If a name and address pair is sufficient for the decision, do not collect more.

What about AML customer due diligence?

Reporting entities have statutory obligations that supply a purpose for verification, bounded by that purpose. Follow your AML/CFT programme and your supervisor's guidance alongside the Privacy Act 2020.

How long should verification evidence be kept?

For the period your statutory or contractual obligations require, and no longer. Where no fixed period applies, set one in your retention policy and apply it.

More insights

Request access to intelID

There is no self-service signup. Access is granted after verification of your identity, your organisation and your authorised purpose.