7 min read
Why Companies Keep Collecting Your Whole ID
September 23, 2026

Key takeaways
-
Hotels, rental counters, delivery services: most of them only need to know you're old enough, or that you are who you say you are, but they collect and keep the whole document anyway.
-
Three separate incidents disclosed in 2026, spanning a genetics lab, a hotel check-in platform, and a prison phone service, together exposed personal documents for more than 4 million people
-
ID wallets let a person prove a fact about themselves (age, identity, eligibility) without handing over a document copy for someone else to store
-
The fix starts with the companies doing the asking: hotels, rental counters, services that only needed to confirm one fact. They can request less in the first place, instead of collecting the full document and then defending it with more security.
After the holidays, it's time to reflect a bit. A season where most of us hand over more personal data than we need to. A photo of our ID sent over WhatsApp to a countryside rental so the host can check us in before we arrive. A copy of our ID handed over to buy a local SIM card on a trip abroad. A copy of our driver's license for a rental car we'll use for a week.
Journalist Annie Lowrey recently gave a name to something most of us feel but rarely name: the "time tax," the paperwork, friction, and effort the state charges us just to access what's already ours. Her focus is government bureaucracy. But there's a private sector version of that same tax, and most of us pay it every day, not to the state, but to the small and large businesses we hand our data to just to get through the door.
None of these reasons are wrong, actually, they're pretty human. Sometimes we don't know what happens to that data once it leaves our hands. Sometimes the process gives us no other option, so we hand it over and move on. Sometimes it's simply urgency. Nobody wants to be the person who slows down check in to ask where their ID scan will end up.
But together, these small moments have built a habit of oversharing that regulated industries, and the vendors who serve them, have quietly built entire systems around.
That habit has a cost. This year alone, we've seen exactly what that cost looks like.
What happened to people's documents in 2026?
In June 2026, a genetics lab lost the health data of 2.8 million people, including Social Security numbers for some patients. A few weeks earlier, a hotel check-in system left more than a million guest passports, driver's licenses and selfie verification photos sitting in an unprotected cloud folder, the exact documents guests handed over just to prove they were who they said they were at the front desk. Around the same time, a prison phone service that asks callers to upload a photo ID before they can add money to an account or speak with an inmate left over 300,000 of those documents exposed on an unsecured server.
They have nothing in common except this: each one kept sensitive documents in a single place, longer than the moment they were needed.
Why do companies still ask for the whole document?
Here's the distinction that gets blurred every time: checking one fact about someone and asking for their whole document are two different things, even when the law requires some kind of record. A hotel may need to log who checked in. A prison phone service may need to confirm who was on a call.
Some of what these systems asked for may trace back to a real requirement, but needing to confirm one fact isn't the same as needing the entire document to get there. A passport has a photo, a signature, a document number, an issuing country, none of which a front desk or a call center actually needed to answer its one question. It's worth holding every document a company collects up to a simple test: does this confirm the one fact required, or go far beyond it? And more companies will likely face that test as AI makes it faster to exploit a stored document, matching a face, forging a scan, running fraud at scale, than the systems holding onto it were ever designed to withstand.
How do ID wallets solve this?
ID wallets, whether used for age verification, full digital identity, professional credentials, or a one time KYC check, sidestep the question entirely.
Instead of handing over a document for someone else to store, the person holds their own credentials, cryptographically signed and verifiable on the spot, and shares only what's needed for that specific check. No document scan gets stored.
The platform on the receiving end gets what it actually needed in the first place: a verified answer, not a document to look after.
Who's responsible: companies, or the people handing over their data?
Fixing this isn't only on the companies that hold our data. It's also on us, and on how we've been trained to hand over identity as if it were nothing.
Most of us learned to overshare identity documents the same way we learned most digital habits: by doing it enough times that it stopped feeling like a decision. We give up a passport scan because the form asks for it. We upload an ID because the app won't let us continue otherwise. Nobody sits us down to explain what happens to that copy after the transaction is done, so we assume someone else is handling that part responsibly.
That assumption needs to change on both sides. Companies need to stop asking for the whole document by default and start treating a single confirmed fact as enough. And people need a basic level of literacy about identity: what a document actually reveals, why one verification shouldn't require handing over everything on it, and why asking "why do you need all of this??" is actually a fair question, not an obstacle.
Neither side gets there alone.
What comes next?
People will keep doing whatever's easiest in the moment. Handing over a photo of an ID takes ten seconds, and asking why a company needs the whole thing takes a conversation nobody has time for at a hotel counter or a prison phone kiosk. Expecting that to change through better instructions or more awareness campaigns hasn't worked so far.
What actually shifts the pattern is making the easy option and the safe option the same one.
An ID wallet does that: the guest still taps a phone at check-in, the caller still verifies who they are in seconds. What disappears? Having to hand over an entire document just to confirm one thing about it.
That's what changes the next season of holidays, renewals and check-ins: not asking people to hand over less, but giving them a way to prove what's needed without handing anything over at all.
FAQ
What's the difference between checking one fact and collecting a full document?
Checking a fact confirms something specific about a person, like their age or identity, at a single moment. Collecting a document hands over everything on it: photo, signature, document number, address, far more than most checks actually require. Most systems ask for the full document by default, even when a single confirmed fact would do.
Do ID wallets eliminate the need for identity verification?
No. Someone still has to establish, at least once, that a person is who they claim to be. What changes is that the result becomes a reusable, cryptographically signed credential, so the identity doesn't need to be re-verified, or re-collected in full, by every business that later needs proof of it.
Are companies required to collect and store the documents they ask for?
It depends on the sector. Regulated industries like banking often face defined requirements tied to audit, fraud investigation, or legal requirements. Outside those cases, most of what gets collected, the full document instead of a single fact, isn't required by anything. It's just how the system was built.
How many people have been affected by identity data breaches in 2026?
Across just three disclosed incidents this year mentioned before, more than 4 million people had personal documents or health records exposed.

Ana Wedfry
Marketing