Verified and Catalogued: How Identity Checks Are Quietly Assembling Your Digital Dossier
Photo: Argentine Government, CC BY 4.0, via Wikimedia Commons
There is a reasonable assumption embedded in most online verification requests: that the data you submit is used once, for the purpose stated, and then discarded. You upload a driver's license to confirm your age. You enter a Social Security number to open a brokerage account. You submit a utility bill to satisfy a landlord's tenant screening portal. Each transaction feels contained, purposeful, temporary.
It is not.
Behind the interfaces of legitimate-seeming verification workflows, a parallel industry is quietly operating — one that treats each identity check not as a single-use transaction, but as a data acquisition event. The companies facilitating these checks are, in many cases, building longitudinal records of who you are, where you have lived, what you own, and how you behave financially. And they are doing it largely without your informed awareness.
What Identity Verification Actually Involves
Modern identity verification is not a simple name-and-number confirmation. Services like Jumio, Onfido, LexisNexis Risk Solutions, and Socure deploy layered processes that can include document scanning, facial recognition, behavioral biometrics, device fingerprinting, and cross-referencing against proprietary databases built from prior verification events.
When a fintech startup integrates one of these platforms to onboard a new user, the verification company does not merely confirm that the submitted ID is authentic. It also logs the event. It records the device used, the location, the time, the document type, and often the selfie image captured for liveness detection. That data may then be retained, analyzed, and in some cases incorporated into the vendor's broader identity graph — a structure that maps individuals across multiple verification events conducted through different client companies.
The result is a profile assembled not by any single institution you chose to trust, but by a third-party intermediary operating in the background of dozens of services you use.
The Aggregation Problem at Scale
The deeper issue is not that any single data point is particularly sensitive. It is that aggregation transforms mundane fragments into something far more revealing.
Consider what a verification company might accumulate over several years of ordinary digital life: the address on your license when you opened a checking account in 2019, the address on a different document when you applied for a rental in 2021, your current address from a recent gig-economy onboarding. Taken individually, these are routine records. Assembled into a timeline, they constitute a residential history that a data broker would ordinarily have to purchase from multiple sources — and that you never consented to compile.
LexisNexis Risk Solutions, a division of RELX Group, is among the most prominent players in this space. Its identity verification and fraud prevention products serve banks, insurers, healthcare providers, and government agencies. The company's underlying data assets — which include public records, proprietary data partnerships, and event-based transaction logs — are substantial enough that the Federal Trade Commission has previously examined its data broker practices. Experian, TransUnion, and Equifax, the traditional credit bureaus, have similarly expanded their identity verification offerings, meaning the same companies that hold your credit history are increasingly positioned to hold your behavioral and document history as well.
Smaller, specialized players are also proliferating. Background check platforms like Checkr and Sterling serve employers and landlords. Payment authentication services like Plaid — which connects bank accounts to third-party apps — have faced regulatory scrutiny over the scope of data they access relative to what users believe they are authorizing. In 2020, Plaid settled a class-action lawsuit for $58 million after allegations that it had collected far more transaction history than users had consented to share.
The Consent Architecture Is Broken
There is a consent process attached to most verification services. It is, almost universally, inadequate.
The terms of service governing these interactions are typically presented by the primary company you are dealing with — the bank, the landlord's portal, the app — not by the verification vendor itself. References to third-party data processing are often buried in subordinate clauses, linked to separate privacy policies the average user will never read, and written in language that obscures rather than clarifies what is actually occurring.
This architecture is not accidental. As Privatty has documented in prior coverage of dark patterns and engineered privacy policies, the design of consent flows in digital services frequently prioritizes data acquisition over informed user choice. Verification systems are no exception. The urgency of completing a transaction — opening an account, securing a rental, getting paid — creates pressure that makes scrutinizing a third-party data processing agreement feel impractical.
Under the California Consumer Privacy Act and its successor, the CPRA, California residents have some rights to request deletion of data held by verification companies that qualify as data brokers. But enforcement is uneven, and the majority of Americans outside California have no comparable statutory protection at the federal level.
Practical Steps to Limit Your Exposure
While the structural problem requires legislative remedy, there are concrete measures individuals can take to reduce the data footprint they leave across verification systems.
Request data deletion directly. Major verification and identity data companies are required to honor deletion requests from California residents, and many honor them from other states as a matter of policy. LexisNexis, Acxiom, and Experian all maintain opt-out or deletion request portals. Submitting requests to these companies annually is a reasonable baseline practice.
Use the minimum viable document. When a verification service offers multiple acceptable forms of identification, choose the one that contains the least additional information. A state ID rather than a passport, for instance, omits travel history and country-of-birth data.
Read the third-party disclosure before proceeding. This is inconvenient, but it is the only way to identify which verification vendor is actually processing your data. Searching that vendor's name alongside terms like "data retention" or "privacy policy" will often reveal how long they hold verification records.
Monitor your credit and identity reports. Services that provide access to your credit bureau files will sometimes surface unexpected entries that indicate a verification inquiry you did not initiate — a potential sign that your identity has been incorporated into a profile without a corresponding transaction you recognize.
Limit app-based bank account connections. Services that require you to connect a bank account via a third-party aggregator deserve particular scrutiny. Review exactly what transaction history is being accessed, and revoke access through your bank's connected apps settings once the transaction requiring verification is complete.
The Shadow ID System Is Already Operating
The internet's identity infrastructure was never designed with privacy as a foundational principle. It evolved through commercial necessity, and the companies that positioned themselves as solutions to the resulting fraud and friction problems have built substantial data assets in the process.
What is emerging is, in effect, a parallel identification system — one that operates beneath the surface of the services you use, assembled from the residue of ordinary transactions, and governed primarily by the commercial interests of the companies maintaining it. Unlike a government-issued ID, you did not apply for this record. Unlike a credit file, you may not have a clear legal right to see it.
Owning your data, in this environment, requires understanding that verification is not neutral. Every confirmation of your identity is also a contribution to a record you did not choose to create. The first step toward controlling that record is knowing it exists.