FIELD-LEVEL DATA MINIMIZATION
Collect only what this application currently needs.
Inventory version 2026-08-01. Every entry states scope, purpose, access, retention, and deletion. The current flow collects no face template, inferred age or sex, ethnicity, emotion, identity, network address, device fingerprint, or raw representative-authority document.
Current minor-applicant policy
The current Digital Citizen application pilot accepts individuals age 18 or older based only on a self-declared birth date. The site does not infer age from a selfie and collects neither guardian data nor a minor's selfie. Because no guardian-consent path is live, minors cannot currently save or submit this application. This limit applies to the Digital Citizen application, not as site-wide age verification.
account_emailAll application paths- Purpose
- Tie the application to the verified account and send service notices.
- Access
- Applicant and authorized support or reviewers
- Retention
- While the account or an auditable credential record remains active.
- Deletion
- Removed with eligible account data; a one-way audit reference may remain after issuance.
legal_nameC, B and G applications- Purpose
- Identify the declared person, entity, or public institution for authorized review.
- Access
- Applicant and authorized reviewers
- Retention
- Until withdrawal, deletion approval, or the end of an applicable credential audit period.
- Deletion
- Deleted with an unissued application; issued records retain only the minimum auditable claim.
country_or_regionAll application paths- Purpose
- Apply regional policy and route an authorized review.
- Access
- Applicant and authorized reviewers
- Retention
- Same period as the application or minimum credential record.
- Deletion
- Deleted with eligible application data.
birth_dateC applications only; self-declared- Purpose
- Enforce the current adult-only pilot and support authorized review; never inferred from a face.
- Access
- Applicant and authorized reviewers
- Retention
- Until withdrawal, approved deletion, or an applicable credential audit period ends.
- Deletion
- Deleted with an unissued application and excluded from public credentials.
legacy_birth_month_gender_phoneNot collected by the current application- Purpose
- No current purpose; legacy columns are retained only for safe migration compatibility.
- Access
- Not shown in the current application response
- Retention
- Cleared when an existing draft is next saved; no new values are accepted.
- Deletion
- Cleared on save or eligible application deletion; never inferred from a selfie.
entity_registration_and_roleB and G applications- Purpose
- Route a future authorized institution and representative-authority review.
- Access
- Applicant and authorized institutional reviewers
- Retention
- While the application or minimum institution credential audit record remains active.
- Deletion
- Deleted with an unissued application; no raw authority document is stored in D1.
authority_referenceB and G applications; bounded metadata only- Purpose
- Point an authorized reviewer to a public or official authority reference.
- Access
- Applicant and authorized institutional reviewers
- Retention
- Same period as the institution application.
- Deletion
- Deleted with eligible application data; confidential or raw evidence must not be entered.
selfie_imageOptional until submission; separately consented- Purpose
- Support authorized review and, where available, a browser-only face-presence check.
- Access
- Applicant and authorized reviewers through private storage
- Retention
- Until consent withdrawal, application withdrawal, approved deletion, or the documented review need ends.
- Deletion
- The applicant can delete it independently; no face template or demographic inference is retained.
face_presence_statusSubmission capture metadata- Purpose
- Record only whether the browser saw a face or routed capture to manual review.
- Access
- Applicant and authorized reviewers
- Retention
- Same period as the application review record.
- Deletion
- Reset when the selfie is deleted; never treated as identity verification.
consent_receiptEvery application-data or selfie consent- Purpose
- Prove the policy version, purpose, grant time, and withdrawal time shown to the applicant.
- Access
- Applicant and privacy-authorized staff
- Retention
- Kept as a minimal consent audit record after application withdrawal where permitted.
- Deletion
- Contains no selfie or application field values; handled through the Privacy Request Center.
Your data and consent remain under your control
After sign-in, download a versioned consent receipt or request access, correction, export, deletion, or consent withdrawal.