Identity evidence may support a specific onboarding, anti-money laundering (AML) or Companies House check. That does not justify sending every requested document to any website. The requester must identify itself, explain the precise purpose, ask for no more than necessary and tell you how the data will be used and retained.
As at 19 July 2026, this site’s published materials do not let a reader independently verify the controller’s complete identity and contact details, all purposes and lawful bases, recipients, transfer safeguards or category-specific retention. Do not make an uninvited upload. Wait for a verifiable, case-specific invitation and complete privacy information.
Start by identifying the process
The phrase “ID check” can hide three legally and operationally different activities. Ask the requester to name the one it is carrying out.
1. The site’s own onboarding
A site may want to check that an applicant is a real person, prevent duplicate applications or assess stated programme criteria. That is its own processing activity. It needs a lawful basis, a clear purpose and a privacy notice, but it is not automatically required by Companies House or the Money Laundering Regulations.
An early expression-of-interest form should collect only what is needed at that stage. Full date of birth, residential history, a passport image, a facial image or banking transactions need a stronger and more specific justification than a name and contact detail. “We may need it later” is not enough.
This site’s current materials do not identify the data controller in a way a reader can independently verify, or establish that the operator is a secure document processor, an AML-supervised trust or company service provider (TCSP) or an Authorised Corporate Service Provider (ACSP). The words “secure upload” cannot substitute for evidence about the organisation, system, access controls and deletion process.
2. AML/KYC by a regulated provider
Where a regulated trust or company service provider is involved, it applies risk-based anti-money laundering (AML) customer due diligence (CDD), often described as know your customer (KYC), to the relevant customer, beneficial owner, ownership and control, purpose and ongoing relationship. The candidate’s identity can be part of that work, but it cannot stand in for checking the client and company.
This document-safety page does not reproduce the full provider-side process. Use KYC for company directors for that analysis, and ask only which legal entity performs the check, which supervisor covers it and why it needs each item.
3. Statutory Companies House verification
Companies House identity verification is a separate official process completed through GOV.UK One Login or an Authorised Corporate Service Provider (ACSP). It produces a personal code; it is not completed by sending documents to an onboarding website or passing a separate AML check.
Follow the dedicated Companies House identity-verification guide and the current official route. Companies House also says not to post or email identity documents to it.
Why a particular document might be requested
A legitimate requester should map each document to one stated purpose. The examples below are possibilities, not proof that this site or every provider needs them.
Photo identity document
A passport, UK photocard driving licence or other accepted document can help compare a name, date of birth and photograph against a reliable source. GOV.UK One Login publishes its own current list. An ACSP or AML-regulated provider must tell you what evidence it accepts under the route it is using.
Do not send an expired or altered document unless the official route expressly accepts it. Do not add invented details, cover security features at someone else’s direction or let another person impersonate you during a live check.
Facial image or liveness check
A selfie or short video may be used to compare the applicant with a photo ID or to test whether a live person is present. It creates additional privacy and impersonation risk. Ask whether it is essential, whether a human or automated system performs the comparison, who supplies that system, whether the image is used for any other purpose and when it is deleted.
The fact that one verification route uses a facial check does not mean every onboarding site is entitled to collect a selfie.
Proof of address
An address document may support an AML check, contact verification or another defined requirement. Ask which address is being checked and why. A director’s residential address and public service address serve different purposes; a requester should not blur them or imply that all residential details will be public.
If several documents could work, use the least intrusive accepted option. A recent council-tax bill or utility document may reveal less transactional information than a full bank statement, but only the requester can confirm its accepted evidence and legal basis.
Bank document
A bank document might be proposed to verify an address, account holder or future payment destination. Those purposes do not normally explain why a requester needs every transaction, balance, merchant and reference on a full unredacted statement.
Ask whether an account-confirmation letter, redacted statement or page showing only the necessary name, address, sort code and account number would suffice. Do not redact anything secretly where the recipient requires an unaltered document for a lawful check; agree permitted redactions first. Never provide online-banking passwords, PINs, one-time codes or remote access.
What data minimisation requires
The ICO explains that personal data must be adequate, relevant and limited to what is necessary. Its data minimisation guidance says an organisation should identify the minimum amount needed for its purpose and should not collect information on the off-chance it may be useful.
That means the request should vary by stage and risk. An initial enquiry, a regulated business relationship and Companies House verification do not justify identical data bundles. The organisation should be able to explain:
- why each field and image is needed now;
- whether providing it is legally or contractually required;
- what happens if you choose not to provide it;
- which alternatives are accepted;
- whether optional information is clearly marked; and
- whether the data will be reused for matching, marketing or another purpose.
If the answer is simply “KYC requires everything”, ask for a more precise explanation.
Privacy information to obtain first
The controller should give privacy information at the point of collection. According to the ICO’s right-to-be-informed guidance, core information includes:
- the controller’s legal name and contact details;
- each processing purpose and lawful basis;
- relevant legitimate interests, if relied on;
- recipients or categories of recipient;
- international transfers and safeguards, where applicable;
- the retention period or criteria;
- your applicable rights and the ICO complaint route; and
- whether the data is mandatory and any automated decision-making.
Check that the notice describes the form in front of you. If a notice says only basic contact details are collected while the form asks for a full residential address, date of birth and nationality, the inconsistency should be resolved before submission.
Retention is purpose-specific
UK GDPR does not create one retention period for all ID documents. The ICO’s storage-limitation guidance requires an organisation to justify how long it keeps each category, review it and erase or anonymise data no longer needed.
Money Laundering Regulations 2017, regulation 40, generally requires a relevant person to retain specified CDD and transaction records for five years after the relevant business relationship ends, with defined exceptions. That rule should not be copied onto:
- a person who only completed an early interest form;
- documents collected for a different purpose;
- speculative information never used for CDD; or
- records held by an organisation that has not established it is a relevant person.
Ask when unsuccessful-applicant data, raw document images, facial captures and derived check results are each deleted. “As long as necessary” is not useful unless the criteria are explained.
Checking the channel without assuming it is safe
No upload method is risk free. HTTPS and a padlock protect part of a connection, but they do not prove the recipient’s identity, lawful purpose, internal access controls, storage encryption, processor contracts, breach response or deletion.
Before using a channel:
- Obtain the invitation through contact details you have independently verified.
- Confirm the exact legal recipient and domain.
- Open the privacy notice yourself rather than relying only on a message link.
- Check whether the link is personal, expires and limits document type.
- Ask who can access the file and how a mistaken upload is removed.
- Keep a record of what you sent, when, why and under which notice.
Do not move to personal email, messaging apps or a file-sharing account merely because someone says the official system is unavailable.
Red flags that justify stopping
Pause if the requester:
- will not identify the controller, provider or proposed company;
- says the whole document bundle is “required by UK law” without separating the purpose;
- asks for documents before explaining the director’s legal duties;
- wants passwords, authentication codes, card details or remote-device access;
- asks you to edit, borrow or falsify evidence;
- pressures you with a fee, deadline or threat of losing guaranteed income;
- uses a public upload page without an individual invitation;
- cannot give a retention period or deletion contact; or
- claims its upload automatically gives Companies House approval.
Preserve the request and verify the organisation through independent details. If identity misuse may have occurred, contact the relevant document issuer, bank, Companies House, ICO or official UK fraud-reporting service according to the risk.
Two illustrative examples
Proportionate request: after a separate education and screening stage, an identified regulated provider explains that it is conducting CDD for a named proposed relationship. It gives its supervisor details, a privacy notice, accepted document alternatives, permitted redactions and category-specific retention. It separately directs the candidate to GOV.UK for Companies House verification. This supports further checking, not automatic trust.
Unsafe request: an unknown contact sends a public link and demands a passport, selfie and complete statement that day. They refuse to identify the controller or beneficial owner and say the upload is legally required for Companies House. They also ask for a one-time bank code. Do not submit anything.
A decision checklist before sending ID
Answer yes, no or not sure:
- Can I independently verify the requesting legal entity?
- Do I know whether this is onboarding, AML CDD or Companies House verification?
- Is every document tied to a stated and lawful purpose?
- Have less intrusive evidence and permitted redactions been addressed?
- Does the privacy notice match the form and identify retention by category?
- Is the route invited and intended for me?
- Can I refuse or pause without being told that appointment is already agreed?
If any answer is no or not sure, pause. Read the current privacy information and ask for written clarification. Because this site’s controller and data-handling facts remain unconfirmed, the responsible next step is verification, not an uninvited upload.
Frequently asked questions
Is a passport always required for a director check?
No. The acceptable evidence depends on the process and route. GOV.UK One Login supports listed photo-ID and alternative routes in some circumstances; an ACSP or regulated provider may offer other approved evidence. The requester should explain its requirement and alternatives.
Must I provide a selfie and a full bank statement?
Not as a universal rule. A requester must explain why each item is necessary. If a bank document is used only to confirm a name, address or account, ask whether a redacted statement or less intrusive confirmation will meet the purpose.
Does sending ID to this site verify me for Companies House?
No. Only verification through GOV.UK One Login or a registered Authorised Corporate Service Provider completes the Companies House process. This site should not be assumed to be an ACSP.
How long can my documents be kept?
There is no single UK GDPR period for every document. The controller must justify category-specific retention. Defined AML CDD records are usually kept for five years after the relevant relationship ends, but that rule does not automatically cover every applicant record.
What should I do if the privacy information is incomplete?
Do not upload. Ask for the controller's legal name, contact details, purpose, lawful basis, recipients, transfer details, retention period and rights. If these cannot be verified, withdraw and consider reporting the concern to the ICO or the relevant official body.
Official sources and further reading
Access dates are shown for each source. Rules and guidance can change; reopen the source before relying on a time-sensitive point.
- Verify your identity for Companies House — Companies House; accessed 19 July 2026
- Verifying your identity for Companies House — Companies House; accessed 19 July 2026
- What privacy information should we provide? — Information Commissioner's Office; accessed 19 July 2026
- Principle (c): Data minimisation — Information Commissioner's Office; accessed 19 July 2026
- Principle (e): Storage limitation — Information Commissioner's Office; accessed 19 July 2026
- Money Laundering Regulations 2017, regulation 40 — legislation.gov.uk; accessed 19 July 2026