Identity
How to verify an identity in New Zealand without breaching privacy
Identity verification is a corroboration exercise, not a data grab. What to check, in what order, and what not to collect.
Published · Reviewed
Identity verification sounds like a lookup and is actually a judgement. You are deciding whether the records in front of you describe a real person, whether that person is the one you are dealing with, and whether the level of assurance you have reached matches the decision you are about to make. Done well, it uses less information than people expect. Done badly, it collects far more than it needs and still gets the wrong person.
Start with the decision, not the data
Before any search, write down what turns on the answer. Opening an account with credit exposure, serving proceedings, releasing a file to a claimed authorised person and paying out a claim all carry different consequences and therefore different assurance levels. The Privacy Act 2020 requires that collection be necessary for the purpose, so the decision sets the ceiling on what you may collect.
A useful discipline is to state the minimum sufficient result. For a routine matter it may be: "one current address confirmed by two independent records, and a name match on date of birth". Once that is met, stop. Continuing to search because more data is available is precisely what principle 1 prohibits.
The corroboration model
Identity in New Zealand is not held in a single authoritative civil register that private organisations can query. Verification is therefore triangulation across independent records that were created for different reasons at different times.
Records that carry weight
- Company and director records. Where the subject has been a director or shareholder, the Companies Register links a name to addresses, dates and other entities. It is public, dated, and strong corroboration.
- Property and title records. Ownership records tie a named person to a property over a period, which supports an address history rather than a single point.
- Security interests on the PPSR. Registered interests recorded against a debtor name provide an independent creation event with a date attached.
- Credit file address history. Usually the most current address data available, and available only where the Credit Reporting Privacy Code 2020 permits your access.
- Directory and digital footprint information. Useful for confirming an existing hypothesis; weaker as a starting point because of age and self-reporting.
- Insolvency records. Definitive where they exist, and material to any credit or litigation decision.
Independence is the point. Two records derived from the same original submission are one record. If a directory entry and a marketing list both trace back to a form the subject filled in five years ago, they agree with each other and prove nothing.
Handling near-matches
A near-match is a warning, not a result. Same surname and initial at a plausible address, with a date of birth out by a year, is exactly the pattern that produces wrong-person contact. Resolve it by finding a record type you have not used yet, or by asking the subject a question only they can answer, rather than by weighing the evidence you already have more generously. Where the match cannot be resolved, report it as unresolved. Most wrong-person contacts originate in an unresolved near-match that was recorded as a match.
Minimisation in practice
Minimisation is easier to describe than to do, because thorough people like completeness. Three habits make it real.
First, choose sources in sequence rather than in parallel. Run the source most likely to answer the question, then stop and assess. Running everything at once guarantees you collect information you did not need.
Second, keep the finding, not the haystack. If the decision required a confirmed current address, retain the confirmed address and the two source references, not the full extracts of every record you looked at.
Third, separate verification from investigation. Confirming that a customer is who they say they are is not licence to build a picture of their affairs. If a genuine investigative need arises later, it is a new purpose with its own declaration.
Fairness and intrusiveness
Principle 4 requires that collection be fair and not unreasonably intrusive in the circumstances. Two applications matter here. Never obtain information by pretext — claiming to be the subject, a relative, or an official is unlawful collection. And be careful about collecting from people around the subject: asking a neighbour or an employer about someone discloses that you are enquiring into them, which is itself a disclosure with consequences.
The record to keep
The evidence of a good verification is short: the decision it supported, the assurance level required, the sources used, the identifiers matched, who ran it and when, and the conclusion reached including any residual doubt. If you cannot produce that in a paragraph, the process was not controlled.
intelID captures the same material as a by-product of the search: an authorised-purpose declaration before the query, role-based access limiting which sources a user can reach, and a full audit record afterwards. See how a search runs, the sources available, and the authorised-purpose article for the declaration wording. Teams with AML obligations should also read the corporate and compliance page.
Access to intelID is limited to verified, licensed users. You can request access or read our compliance position first.