Nobody said I had to email it

I am getting married in October. In the months leading up to it I have been asked to email a photograph of my driver's licence or my passport six times. Two of those were a venue and a DJ, and one was an accountant. My fiancée has been asked three times, every one of them by a school, in the course of registering to teach.

This is the one that made me stop and look at it properly. I have reworded the opening lines, the list of documents is theirs word for word.

Hi Rob, I still need your ID before I can lodge your paperwork. Could you send it through when you get a chance?

Options legally required to lodge your NOIM are:
Birth certificate or an official extract AND driver's licence
or
Australian passport
or
Overseas passport

Read it again and notice what it does not say. It does not say the documents have to be emailed. What the law requires is that they see them, and how they get in front of them is not mentioned anywhere. The requirement and the request turned up in the same message, and nobody reads that and thinks the second part is optional.

Everything in that email is correct. A celebrant has to be satisfied that I am who I say and has to see evidence of my date and place of birth, and the Attorney-General's Department guidance for authorised celebrants allows them to do that from a scan sent by email. They were following that guidance, in the way almost every couple would prefer, at the point in the process where they were quite reasonably chasing me. The guidance does not require them to keep any of it. The only disposal advice in it covers hard copy paperwork after it goes to the registry, so nothing there tells them what to do with a scan sitting in a mailbox.

So the problem is not that request. The problem is that I cannot tell it apart from the other eight.

What I actually could not tell

A request to email identity documents arrives with no way to sort it. I could not tell whether the document was going to be looked at and closed, or looked at and saved. I could not tell whether the copy would sit in one mailbox or be forwarded to a second person, or whether the mailbox syncs to a phone, or how long the backups run. I could not tell whether anyone at the other end had ever decided how long to keep it, and I am fairly confident that in most cases nobody had, because keeping it is not a decision anyone makes, it is what happens when no one makes one.

Nine requests, nine mailboxes I do not control, nine retention practices I will never see, and no mechanism by which anyone tells me if one of them is read by someone who should not have it.

That is not a complaint about any of the nine. It is a description of what the person being asked has no way to be aware of.

Why I could say no and most people cannot

I said no every time, and not because I am more careful than anyone else.

I have run large scale infrastructure for many years, across school systems, finance and retail, and a large part of that work was finding out what was actually being held. Identity documents turned up everywhere, for onboarding, for staff, for volunteers, for contractors, for compliance checks that had a clear start and no defined end. Every one of them was collected for a reason that made sense on the day it was collected. Almost none of them had a date attached to them, so the copies outlived the reason they were taken, then outlived the person who took them, sitting in a share or a mailbox that had been accumulating permissions for a decade. When somebody finally asked who could read them, working out the honest answer took weeks and the answer was worse than anyone had assumed.

None of that was negligence. Every individual decision was defensible on the day it was made, but nobody owned the outcome.

That is just how I think when these requests arrive, and most people have not been exposed to this. They are not being careless, they just don't know to push back.

There is a second thing, and it matters more. Pushing back on a celebrant is a conversation I can afford to have, because the worst outcome is a slightly awkward exchange with someone I am paying. My fiancée's three were schools deciding whether she can work. Saying no to the organisation that controls whether you are employed is a completely different transaction, and she said no anyway, and each time it cost her calls and follow-ups and time she did not have.

The cost of asking the question is paid immediately by the person being asked. The cost of the copy sitting somewhere for years is paid later, by the same person, invisibly, and possibly never. People are not choosing convenience over safety. They are choosing a real cost now over a theoretical one later, which is what anyone does.

The advice does not fit the problem

The standard advice is to never email identity documents and to use a secure portal instead. The advice is aimed at the wrong thing. It treats the risk as being in the transmission, and the transmission is only part of it. A document that travels through a portal and is then downloaded, checked and left in the same folder is in exactly the same place it would have been. Moving the file more carefully does not change what is kept.

Certified copies mean a trip to the post office and a wait. In-person sighting does not work for anyone doing this interstate or remotely, which by now is most people. Refusing outright works if you can afford to refuse.

There is no tidy answer available to the individual, and I am not going to pretend there is one. The answer is not available at that end of the transaction at all.

What I found afterwards

I went looking after the celebrant email, and found that the regulator had already written most of this down.

The OAIC's privacy guidance for reporting entities under the AML/CTF Act, published in February and updated in April, says that the AML/CTF Act does not require scanned copies or photocopies of identity documents to be kept for record keeping purposes. What is required is the information from the document, the name, the date of birth, the address, the expiry, the document number, along with what you did to verify and what the outcome was. It goes further and says entities should take reasonable steps to destroy or de-identify the full copies they hold. The OAIC's own word for a store of retained identity documents is honey pot.

From 1 July this year that reached lawyers, conveyancers, accountants, real estate agents and property developers for the first time, and the Privacy Act small business exemption stops applying to them for that activity, so a large number of firms that have always taken a scan and put it in a folder now have a written instruction not to.

That is a real change and it is worth knowing. One of my nine was an accountant, so one of them sits in the class of business the reforms reached, although whether that particular firm is covered depends on which services it provides and I have not asked. The other eight sit outside all of it, and a DJ is nowhere near it.

That range is the point. One had a statutory reason to see the documents. One is in the only sector on my list where somebody has now written down what to keep. Three were an employer deciding whether my fiancée could work. At least two had no reason I have been able to work out. None of that difference was visible in the request. They all read the same way and they all wanted the same file.

The part that is mine

The request to send through a copy of your licence is one of the most ordinary requests in Australian business. It is ordinary enough that nobody queries it, and requests nobody queries are the ones worth impersonating. The message I quoted at the top would be trivial to imitate, the tone is right, the process reference is right, and the legal list is publicly available. Whether an imitation would actually land in my inbox depends on whether the sender's domain can be sent from by anyone else, and in the work I do, on the businesses I scan, the answer is usually that nobody has checked.

None of that was on my mind when the email arrived. What was on my mind was that I had been asked six times, and that I only knew how to answer because I had already spent years watching what happens to documents like it.

Sighting a document takes a second. Keeping a copy of it lasts as long as nobody looks. Almost everybody makes the first decision deliberately and almost nobody makes the second one at all.

Back to Writing