CHAPTER IXPROVISIONS RELATING TO SPECIFIC PROCESSING SITUATIONS

Article 87Processing of the national identification number

Official text

Member States may further determine the specific conditions for the processing of a national identification number or any other identifier of general application. In that case the national identification number or any other identifier of general application shall be used only under appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation.

Commentary

Article 87 deals with identifiers that governments or other authorised bodies use to distinguish one person reliably from everyone else. Although the provision is only two sentences long, it addresses a major privacy risk: a permanent or widely used identifier can connect information about the same person across tax, employment, health, banking, welfare, education and other systems.

The central rule is:

Member States may adopt special national rules for national identification numbers and other identifiers used across society. If they do so, the identifiers may be used only with safeguards appropriate to the risks posed to individuals.

Article 87 does not itself authorise the collection or use of an identification number. It also does not replace the ordinary GDPR. A controller normally needs:

  1. a lawful basis under Article 6;
  2. compliance with the Article 5 principles;
  3. satisfaction of any specific national conditions adopted under Article 87;
  4. appropriate technical, organisational and legal safeguards.

The provision leaves Member States substantial room to regulate these identifiers because national identification systems vary widely. Some countries use one central number across many government functions. Others use separate tax, social-security, healthcare or population-register identifiers. Article 87 sets a common minimum safeguard while allowing those national differences to continue. The official text confirms both elements: Member States may determine specific conditions, but use under those conditions remains subject to appropriate safeguards for data subjects’ rights and freedoms.


1. Why national identification numbers require special attention

A national identification number is usually designed to identify a person accurately and consistently.

A name alone is not always sufficient. Many people may have the same name. Addresses change. Dates of birth are shared by many individuals. A unique identifier allows a public body to locate the correct record.

Illustration

Two people are named Elena García and were born on the same date. One applies for a tax refund and the other is receiving a pension. A unique identifier helps the tax and pension authorities avoid:

  • assigning the refund to the wrong person;
  • linking the wrong earnings history;
  • disclosing one person’s information to another;
  • creating duplicate public records. The same feature that makes an identifier useful also makes it dangerous. A stable and unique number can act like a universal connecting key.

Illustration

A tax authority, hospital, employer, bank and insurance company each hold one person’s identification number. If those databases are connected through the number, an organisation may create a combined profile showing:

  • income;
  • employment;
  • illnesses;
  • insurance claims;
  • family details;
  • welfare payments;
  • property;
  • financial transactions. The number may contain little information when viewed alone, but its ability to connect several databases makes it highly privacy-sensitive. Article 87 therefore protects not only the secrecy of the number itself. It protects people against the broader consequences of uncontrolled linkage, surveillance, impersonation and function expansion.

2. What is a national identification number?

Article 87 does not define “national identification number.”

In ordinary terms, it is a number or code assigned under a national system for the reliable identification of a natural person. It is commonly used by one or more public authorities and may sometimes be used by private organisations where national law permits.

The number may be:

  • permanent for life;
  • replaced in limited circumstances;
  • assigned at birth;
  • assigned on residence or immigration;
  • sector-specific;
  • used across several public services;
  • based partly on personal characteristics;
  • randomly generated.

Article 87 commentary generally treats national identification numbers as personal data under Article 4(1), because they identify or uniquely distinguish natural persons. It also distinguishes a central national identifier from other identifiers that perform a similar generally applicable function.

[!example] Illustration A population-register number assigned to every resident and used by tax, social-security and municipal authorities is a national identification number. A customer number created by one supermarket only for its loyalty scheme is normally not a national identification number. It is personal data, but its use is confined to one commercial relationship. The difference is not simply whether a string of digits identifies someone. Article 87 is concerned particularly with identifiers having a broad or generally applicable role.

3. “Any other identifier of general application”

Article 87 extends beyond one formally designated national identification number. It also covers“any other identifier of general application.”

This wording prevents national systems from avoiding the safeguard merely by calling a widely used number something else.

An identifier of general application is likely to be one that:

  • is assigned systematically to a large population;
  • uniquely or reliably identifies persons;
  • is accepted or required across several contexts;
  • is capable of linking records between different systems;
  • is used beyond one limited transactional relationship.

Possible examples may include:

  • social-security numbers;
  • tax-identification numbers;
  • national registry numbers;
  • healthcare identifiers;
  • residence or population numbers;
  • identity-card numbers;
  • other broadly recognised public identifiers.

Whether passport numbers fall within Article 87 may depend on national law and how they are used. A passport number is certainly personal data, but it may change when a passport is renewed and may serve primarily as a document identifier rather than as a permanent person-wide linking key. Some national systems may nevertheless regulate it as an identifier of general application.

3.1 Sectoral identifiers

A sectoral number may fall into a grey area.

Illustration

A healthcare number is assigned to everyone using the national health system. It is used by:

  • hospitals;
  • doctors;
  • laboratories;
  • pharmacies;
  • insurers;
  • health regulators. It is not used for tax or electoral administration. Nevertheless, within healthcare it is general, persistent and highly linkable. It may qualify as an identifier of general application under national law, or it may be protected through specialised health-data legislation rather than Article 87 alone. The practical question is not merely what the number is called. The court or supervisory authority should consider what the identifier does:
  • How widely is it assigned?
  • How many sectors use it?
  • Can it connect independent databases?
  • Is it stable over time?
  • Is it required to obtain essential services?
  • What consequences follow if it is misused?

4. Ordinary account identifiers are not automatically covered

Many identifiers are personal data without being Article 87 identifiers.

Examples

include:

  • employee numbers;
  • student numbers;
  • online usernames;
  • loyalty-card numbers;
  • customer account numbers;
  • device identifiers;
  • IP addresses;
  • telephone numbers;
  • vehicle-registration numbers. These may identify or single out people and therefore remain fully protected by the GDPR. But they are not necessarily national identifiers or identifiers of general application.

Illustration

A hotel assigns guest number 74631 to one customer. The number is personal data because the hotel can connect it with the customer’s identity and bookings. However, the number is used only inside the hotel’s reservation system. It does not ordinarily constitute an Article 87 identifier. Compare a national resident number required by:

  • the hotel;
  • the employer;
  • tax authorities;
  • a bank;
  • the healthcare system. That number has far greater cross-context linking power and falls much closer to Article 87’s concern.

5. The identifier is personal data

A national identification number is normally personal data because it relates to an identified or identifiable natural person.

The number may be personal data even when displayed without a name.

Illustration

A file contains only: 7482910635 If the controller can use that number to retrieve the person’s tax, employment or identity record, the person is identifiable. The identifier does not become anonymous simply because the name has been removed. This is particularly important in data-sharing arrangements.

Illustration

A hospital sends a research institution records containing:

  • diagnosis;
  • treatment;
  • national identification number. The hospital removes names and describes the data as anonymous. They are not anonymous if the national number provides a direct or readily usable route back to the patient. Depending on the context, the data may be directly identifiable or, at minimum, pseudonymised.

6. National numbers are not automatically Article 9 special-category data

A national identification number does not automatically become special-category data under Article 9 merely because it is important or sensitive.

Article 9 covers specified categories, such as:

  • health;
  • genetic data;
  • biometric identification data;
  • racial or ethnic origin;
  • political opinions;
  • religious beliefs;
  • trade-union membership;
  • sex life;
  • sexual orientation.

A national number usually identifies the individual but does not, by itself, fall into one of those listed categories. Article 87 commentary similarly observes that national identifiers were not expressly placed within Article 9, although Member States may impose heightened national protection.

This distinction has practical consequences.

Illustration

A bank records a customer’s national number for a legally required identity check. The bank needs:

  • an Article 6 lawful basis;
  • compliance with Article 87 national rules;
  • appropriate safeguards. It does not automatically need an Article 9 exception merely because it uses the national number.

6.1 When the number reveals sensitive information

The position changes if the structure or use of the identifier reveals Article 9 information.

Illustration

Suppose an identification number contains coded information indicating:

  • sex;
  • region of birth;
  • date of birth;
  • immigration category. The number may directly or indirectly reveal additional personal characteristics. If one of those characteristics falls under Article 9, the processing may involve special-category data in addition to the identification number. Likewise, linking a national number to a medical database means the resulting record contains health data even if the number alone does not. The correct analysis is contextual: The number is not automatically Article 9 data, but the information encoded in it or connected to it may be.

7. Article 87 does not itself create a lawful basis

The phrase “Member States may further determine the specific conditions” does not mean that any use of a national identifier is lawful unless national law prohibits it.

A controller must still identify a lawful basis under Article 6.

Possible bases include:

  • legal obligation;
  • performance of a task in the public interest;
  • exercise of official authority;
  • contractual necessity in limited cases;
  • legitimate interests, where national law permits and the balancing test is satisfied;
  • consent, although consent may be unsuitable in many mandatory-identifier contexts.

Illustration

An employer requests a national tax identifier because labour and tax law requires payroll reporting. The likely lawful basis is compliance with a legal obligation, not employee consent. If the employer later uses the number to search unrelated commercial databases, the original legal obligation does not authorise the new use.

7.1 Three-layer test

Where national rules exist under Article 87, a controller should normally ask three separate questions:

Layer 1: Is there an Article 6 lawful basis?

Without one, the processing is unlawful.

Layer 2: Does the processing satisfy the Member State’s Article 87 conditions?

National law may restrict:

  • eligible controllers;
  • purposes;
  • disclosures;
  • retention;
  • display;
  • verification;
  • combination with other records.

Layer 3: Are appropriate safeguards in place?

Even if the lawful basis and national permission exist, security and rights protections remain necessary.

Illustration

A bank is legally permitted to collect the national identifier for anti-money-laundering verification. That does not automatically permit the bank to:

  • print it visibly on marketing letters;
  • use it as an account password;
  • disclose it to advertisers;
  • retain unredacted identity documents forever;
  • use it to combine unrelated consumer profiles.

8. Meaning of “may further determine”

Article 87 is an opening clause. It allows Member States to supplement the GDPR with more specific national rules.

The word“may” means a Member State is not required to adopt a single separate statute entitled “National Identification Number Act.” It may regulate identifiers through:

  • tax legislation;
  • social-security legislation;
  • banking law;
  • employment law;
  • healthcare law;
  • identity-document law;
  • general data-protection legislation.

The word“further” is equally important. It indicates that national law supplements rather than replaces the GDPR baseline. Commentary on Article 87 explains that the provision does not seek to regulate the creation of national identifier systems comprehensively; instead, it allows national conditions while preserving GDPR compatibility and minimum protection.

8.1 What Member States may regulate

National law may specify:

  • who may collect the identifier;
  • for which purposes;
  • in which format;
  • whether consent is permitted;
  • whether publication is prohibited;
  • when private-sector use is allowed;
  • which recipients may receive it;
  • when records must be deleted;
  • whether masking is mandatory;
  • whether regulatory permission is needed;
  • what security controls apply;
  • what penalties follow misuse.

Illustration

A national law may allow national-number processing only by:

  • tax authorities;
  • social-security bodies;
  • healthcare institutions;
  • employers for payroll;
  • banks for legally required verification. Retailers may be prohibited from requesting it for ordinary loyalty programmes.

8.2 What Member States may not do

National discretion is not unlimited.

A national law should not:

  • remove all GDPR rights;
  • authorise indiscriminate use without safeguards;
  • permit incompatible use without justification;
  • undermine data minimisation;
  • make surveillance unlimited;
  • exclude effective remedies;
  • contradict the Charter.

A law authorising every public and private body to use one universal identifier for any convenient purpose would be difficult to reconcile with the safeguard requirement.


9. The meaning of “specific conditions”

The conditions should identify more than a vague statement that national numbers must be used carefully.

A useful national framework may specify:

  • legally permitted purposes;
  • authorised users;
  • access criteria;
  • sharing rules;
  • security requirements;
  • retention criteria;
  • rights of the individual;
  • oversight;
  • audit obligations;
  • sanctions.

[!example] Illustration A law states: “Organisations may use the national number where useful.” This provides little protection because “useful” could cover almost any commercial purpose. A more specific rule might state: “An employer may process the national tax number only where necessary to comply with payroll, tax, social-security or legally prescribed employment obligations, and must restrict access to authorised payroll personnel.” The second rule gives controllers and individuals a clearer understanding of lawful use.

10. Appropriate safeguards are mandatory

Article 87 says that where a Member State establishes specific conditions, the identifier shall be used only under appropriate safeguards.

The word “shall” creates a binding limitation.

National law cannot merely authorise processing. It must ensure that the system protects rights and freedoms.

The safeguards should correspond to the actual risks of the identifier. A number that enables access to several public databases requires stronger safeguards than an internal customer code.


11. Data minimisation

The first major safeguard is limiting collection to situations where the identifier is genuinely needed.

Illustration

A gym asks every member for a national identification number to prevent duplicate memberships. The gym could use:

  • email address;
  • customer number;
  • membership card;
  • telephone number. Collecting the national identifier may be unnecessary and disproportionate. Compare a bank verifying a new customer under a statutory anti-money-laundering obligation. The number may be necessary to confirm identity and screen legally required records. The controller should be able to explain:
  • why the number is needed;
  • why a less intrusive identifier will not work;
  • whether the full number is required;
  • whether it must be stored after verification.

11.1 Collection versus retention

Even where viewing the number is necessary, permanent retention may not be.

Illustration

A service provider checks a national identity document to confirm age. It may need to record only:

  • age verified;
  • verification date;
  • verification method. Keeping a complete copy of the document and national number may be excessive unless another law requires it.

12. Purpose limitation and function creep

Function creep occurs when an identifier collected for one legitimate reason gradually becomes used for unrelated purposes.

Illustration

An employer collects the national number for payroll. Later, it uses the number to:

  • search employees’ property records;
  • obtain commercial risk scores;
  • create attendance codes;
  • track healthcare interactions. These secondary uses are not automatically lawful because the employer already possesses the number. Purpose limitation requires the organisation to assess every new use separately.

12.1 Universal identifier risk

A universal number makes linking technically easy. Article 87 safeguards should make unauthorised linkage legally and operationally difficult.

Possible measures include:

  • sector-specific identifiers;
  • function-specific tokens;
  • legal prohibitions on matching;
  • access controls;
  • logging;
  • independent authorisation;
  • separation of databases.

[!example] Illustration Rather than sharing one raw national identifier between tax and healthcare systems, a trusted service may generate different sector-specific identifiers linked through a protected conversion mechanism. A healthcare provider cannot then use the health identifier to search tax records.

13. Masking and truncation

Full identifiers should not be displayed where partial information is sufficient.

Illustration

A customer-support employee needs to confirm which account is being discussed. The interface may display: 4821 rather than the complete national number. Other techniques include:

  • showing only the final digits;
  • replacing the number with a token;
  • masking printed documents;
  • excluding identifiers from email subject lines;
  • redacting copies provided to third parties. Masking does not make the data anonymous. The organisation can still link the masked value to a person. But it reduces unnecessary exposure.

14. Authentication and identification are different

An identifier tells the organisation which person or record is involved. It should not ordinarily be treated as proof that the person presenting it is the rightful holder.

Illustration

A caller provides a person’s national number. If the bank treats that alone as sufficient authentication, anyone who obtains the number may gain account access. A secure system distinguishes:

  • identification: “I claim to be customer X.”
  • authentication: “I can prove that I am customer X.” Appropriate safeguards may require:
  • multi-factor authentication;
  • secure credentials;
  • verified documents;
  • one-time codes;
  • trusted digital identity;
  • risk-based checks. A national number should not function as a secret password, especially where it appears on many documents.

15. Encryption, pseudonymisation and tokenisation

National identifiers should usually be protected in storage and transit.

Possible safeguards include:

  • encryption;
  • field-level protection;
  • pseudonymisation;
  • tokenisation;
  • hashing with appropriate controls;
  • key separation;
  • secure transmission.

Illustration

A hospital uses the national number to match patient records. Its analytics environment does not need the raw number. The hospital replaces it with a research token and keeps the mapping key in a separate protected environment. This does not necessarily make the information anonymous. The hospital can still reconnect the token with the patient. But pseudonymisation reduces exposure.

15.1 Unsalted hashing may be inadequate

National numbers often have predictable formats and a limited range.

If an organisation simply hashes such numbers without strong additional controls, an attacker may compute possible values and recover the originals.

Reliable design may require:

  • keyed hashing;
  • securely managed secrets;
  • random tokens;
  • restricted mapping tables;
  • rotation and separation controls.

16. Access control and logging

Only personnel who need the identifier for an authorised task should have access.

Illustration

In an employer’s systems:

  • payroll staff may need full access;
  • a line manager may need only an employee number;
  • reception staff may need no national identifier;
  • IT administrators may need technical access under monitored conditions. Safeguards may include:
  • role-based access;
  • least privilege;
  • approval workflows;
  • periodic reviews;
  • automatic deactivation;
  • access logging;
  • alerts for unusual searches;
  • disciplinary rules.

16.1 Browsing risk

Public-sector databases containing national identifiers can be attractive to curious or malicious insiders.

Logging should permit detection of:

  • searching for relatives;
  • celebrity lookups;
  • bulk exports;
  • unusual after-hours access;
  • repeated access outside assigned cases.

A log is useful only if it is reviewed. Collecting logs indefinitely without monitoring them does little to prevent misuse.


17. Preventing unnecessary copies

National identifiers often spread because organisations photocopy complete identity documents.

Illustration

A hotel needs to comply with a guest-registration obligation. Staff photograph the passport and send the image through a personal messaging account. The image contains:

  • name;
  • photograph;
  • passport number;
  • nationality;
  • date of birth;
  • signature. Even if some information is legally required, copying and transmitting the complete document through an insecure channel may be excessive. A better process may:
  • capture only mandatory fields;
  • use a secure registration system;
  • restrict access;
  • delete the image immediately if it is not legally needed;
  • provide a clear notice.

18. Retention and deletion

A stable identifier should not be retained indefinitely simply because storage is inexpensive.

The controller must determine:

  • statutory retention period;
  • operational necessity;
  • limitation period;
  • archival requirement;
  • deletion or irreversible anonymisation process.

Illustration

A bank is required to retain identity-verification information for a defined legal period after the customer relationship ends. The bank may retain the national identifier for that period. After the period expires, the bank should not continue retaining it merely because the customer might return someday, unless another lawful justification applies. Deletion should cover:

  • live systems;
  • exports;
  • local files;
  • unnecessary copies;
  • processor environments. Backups may follow a controlled expiry cycle, provided the data are no longer available for ordinary use.

19. Transparency

Individuals should ordinarily be informed:

  • that the identifier is collected;
  • why it is needed;
  • whether provision is mandatory;
  • legal basis;
  • recipients;
  • retention;
  • rights;
  • consequences of refusing.

Illustration

A form asks for a national number but gives no explanation. The person cannot know whether it is needed for:

  • tax reporting;
  • identity verification;
  • credit scoring;
  • marketing;
  • database matching. A proper notice should connect the identifier with a concrete purpose. Where national law requires the number, the controller should identify the legal obligation rather than present the request as voluntary consent.

Consent must be:

  • freely given;
  • specific;
  • informed;
  • unambiguous;
  • withdrawable.

In many national-identifier contexts, consent is not freely given.

Illustration

An employee is told: “Consent to the use of your national number for payroll or you will not be paid.” The processing may be legally necessary, but the employee has no genuine choice. Legal obligation is the more appropriate lawful basis. Similarly, a public authority providing a statutory benefit should not ordinarily rely on consent where the person cannot realistically refuse processing.

Consent might be possible for a genuinely optional and separate use, but Article 87 national law may still prohibit that use.

21. Accuracy and identity mismatches

National identification numbers are designed to improve accuracy, but errors can have severe consequences.

Illustration

A number is entered incorrectly and the system links one person’s debt to another. The innocent person may suffer:

  • denial of credit;
  • tax enforcement;
  • loss of benefits;
  • investigation;
  • reputational harm. Safeguards should include:
  • check digits;
  • identity verification;
  • duplicate detection;
  • correction workflows;
  • human review;
  • notification of significant changes;
  • accessible dispute mechanisms. Because the same identifier may appear across databases, one error can spread rapidly. Controllers should not assume that a match is correct merely because the numbers are identical. Errors, fraud or recycled identifiers may still occur.

22. Rights of the data subject

Article 87 does not remove GDPR rights.

Depending on the circumstances, the person may exercise:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • complaint;
  • judicial remedy;
  • compensation.

National laws may restrict some rights only through a valid legal basis such as Article 23, not simply because an identification number is involved.

[!example] Illustration A person discovers that an insurer recorded the wrong national number. The person should be able to seek rectification because the error may connect the policy with someone else’s medical and claims history. Erasure may not be available where retention is legally required, but restriction may be appropriate while the dispute is investigated.

23. Data breaches involving national identifiers

A breach involving a persistent national number may create long-term risk because the person may be unable to change it.

Potential consequences include:

  • identity fraud;
  • account takeover;
  • impersonation;
  • linked-database attacks;
  • targeted phishing;
  • fraudulent public-benefit applications;
  • tax fraud;
  • credit abuse.

A controller must assess:

  • likelihood and severity;
  • surrounding data;
  • whether the number was encrypted;
  • who obtained access;
  • whether misuse is possible;
  • whether replacement is available;
  • whether affected persons need advice.

Illustration

A leaked file contains only random internal employee numbers. Risk may be limited. Another leaked file contains:

  • national identifier;
  • full name;
  • date of birth;
  • bank details;
  • address. The second breach permits much more powerful impersonation and matching. Notification and support may be required.

23.1 Breach response safeguards

Appropriate measures may include:

  • reporting under Article 33;
  • individual communication under Article 34;
  • fraud alerts;
  • replacement procedures where possible;
  • coordination with identity authorities;
  • monitoring;
  • clear protective guidance;
  • disabling identifier-only authentication.

24. A national number should not be treated as confidential forever

Many organisations incorrectly design security on the assumption that the national number is secret.

In reality, the number may appear on:

  • official correspondence;
  • tax forms;
  • employment records;
  • healthcare documents;
  • identity cards;
  • old databases.

The controller should assume that an attacker may already know it.

Illustration

A public-service portal asks users to log in with:

  • name;
  • national number. Both details may be publicly obtainable. The portal therefore provides weak authentication. Appropriate safeguards should treat the identifier as a reference key, not as a password.

25. Private-sector use

Article 87 does not confine national-number processing to government bodies. Private entities may process these identifiers where:

  • national law permits or requires it;
  • an Article 6 basis exists;
  • processing is necessary and proportionate;
  • safeguards are implemented.

Common private-sector contexts may include:

  • banking;
  • insurance;
  • employment payroll;
  • pension administration;
  • regulated telecommunications;
  • healthcare;
  • anti-fraud or anti-money-laundering duties.

[!example] Illustration An online retailer asks for the national number merely to personalise recommendations. Even if legitimate interests are claimed, national law may forbid the retailer from using the number for that purpose. By contrast, a regulated financial institution may be specifically required to record the number to perform customer due diligence. Private organisations must therefore analyse both the GDPR and the applicable national sectoral rules.

26. Cross-border processing

National-identifier rules are not fully harmonised.

A multinational company may process identifiers from several Member States, each with different legal requirements.

Illustration

A European employer has staff in Belgium, France, Portugal and the Netherlands. Its central HR system stores local national identifiers. The employer must consider:

  • each country’s employment and identifier rules;
  • permitted purpose;
  • local retention;
  • access restrictions;
  • international transfers;
  • whether central storage is permitted;
  • whether the global HR team needs full access. A practice lawful in one Member State may be restricted in another.

26.1 Centralised systems

Centralisation can improve security by reducing duplicate databases, but it can also increase the impact of a breach.

Safeguards may include:

  • local data partitions;
  • role-based country access;
  • separate encryption keys;
  • tokenisation;
  • regional retention rules;
  • local-law configuration;
  • access logging.

The controller should not assume that one global consent form resolves all national Article 87 conditions.


27. Relation to Article 10 criminal-conviction data

A national identifier may be used to retrieve criminal-record information.

The number itself is not Article 10 data merely because it can be used as a search key. But a record linking the number to:

  • arrest;
  • charge;
  • conviction;
  • offence;
  • security measure

involves Article 10.

Illustration

A background-screening provider stores: National number 1234: no match found. Depending on context, even the screening result may reveal criminal-record information. The controller may need to satisfy:

  • Article 6;
  • Article 10;
  • Member State criminal-record law;
  • Article 87 safeguards;
  • employment law;
  • transparency requirements.

28. Relation to biometric identifiers

Biometric data and national identifiers must not be confused.

A facial template or fingerprint may uniquely identify a person, but it is governed particularly by Article 9 where processed for unique identification.

A national number is assigned administratively.

Illustration

An identity system links:

  • national number;
  • facial template;
  • fingerprints;
  • digital signature. The number falls within Article 87. The biometrics may fall within Article 9. The combined system must satisfy both regimes. Because biometrics cannot easily be replaced, the combination creates especially high risk and may require:
  • a DPIA;
  • strong encryption;
  • separation;
  • strict purpose limitation;
  • independent oversight.

29. DPIAs and high-risk identifier systems

Article 87 does not automatically require a data protection impact assessment. Article 35 applies where processing is likely to result in high risk.

A DPIA may be required where identifiers are used for:

  • large-scale database matching;
  • public-service eligibility decisions;
  • profiling;
  • fraud detection;
  • behavioural monitoring;
  • linkage with health or criminal data;
  • biometric identity systems;
  • cross-sector data integration.

Illustration

A government proposes to link:

  • tax records;
  • welfare records;
  • education records;
  • property ownership through a national number to detect fraud. The project may have a legitimate aim, but it creates significant risks of:
  • false matches;
  • exclusion from essential benefits;
  • function creep;
  • mass surveillance;
  • opaque automated decisions. A DPIA should examine:
  • necessity;
  • proportionality;
  • data quality;
  • access;
  • algorithmic errors;
  • human review;
  • appeal;
  • security;
  • retention;
  • less intrusive alternatives.

30. Data protection by design and default

Article 25 is especially important for national identifiers.

A well-designed system should ensure that:

  • the number is collected only where needed;
  • full display is avoided;
  • access is restricted;
  • default exports exclude it;
  • logs detect misuse;
  • retention is automated;
  • sectoral identifiers are used where possible;
  • test data do not contain real numbers;
  • analytics environments use tokens.

Illustration

A public-benefits system includes the national number automatically in every report, email and spreadsheet. That design spreads the identifier unnecessarily. A privacy-protective design uses:

  • an internal case number for daily work;
  • the national number only in an identity-matching module;
  • masked display;
  • controlled retrieval;
  • automatic audit logs.

31. Processors and vendors

Controllers often use vendors for:

  • payroll;
  • cloud hosting;
  • identity verification;
  • document scanning;
  • fraud prevention;
  • public-service platforms.

The controller should ensure that the processor:

  • acts only on documented instructions;
  • applies security;
  • limits staff access;
  • uses approved subprocessors;
  • deletes or returns identifiers;
  • supports rights requests;
  • reports breaches;
  • does not reuse the numbers for its own purposes.

[!example] Illustration A payroll provider receives employee national numbers. It later uses them to build a commercial credit database. For payroll, it may be a processor. For the credit database, it is acting for its own purpose and may become a controller. Its role must be analysed operation by operation.

32. Common mistakes

“The number is public, so the GDPR does not apply”

Incorrect. Public availability does not remove the number from personal-data protection.

“The number is not Article 9 data, so it is not sensitive”

Incorrect. It may be highly risky even if not a special category.

“Consent permits any use”

Incorrect. National law may restrict processing regardless of consent, and consent may not be freely given.

“We need the number to identify the customer”

That statement is not enough. The controller should explain why a less intrusive identifier is insufficient.

“The number itself contains no private information”

It can link extensive private information across systems.

“Hashing makes it anonymous”

Not necessarily, especially where the identifier has a predictable format and limited range.

“A private company can never process it”

Incorrect. Private processing may be required or permitted by national law.

“Article 87 replaces Article 6”

Incorrect. The controller generally needs both an Article 6 basis and compliance with national Article 87 conditions.


33. Corrections and qualifications to the supplied commentary

The supplied commentary is broadly sound, but several points need refinement.

33.1 National identifiers are not used only by public authorities

They may be assigned through public systems but lawfully processed by private actors in regulated contexts.

33.2 Passport numbers are not invariably identifiers of general application

Their classification may depend on national law, stability and use across systems.

33.3 Member States do not have unlimited discretion

National conditions must comply with:

  • the GDPR;
  • the Charter;
  • proportionality;
  • necessity;
  • effective remedies.

33.4 Calling the identifier “sensitive” nationally does not place it automatically within Article 9

Member States may provide stronger protection, but they cannot rewrite Article 9’s EU-wide category list merely through terminology.

33.5 Article 87 is not a lawful basis

Permission under national identifier law does not replace Article 6.

33.6 Safeguards are broader than cybersecurity

They include:

  • purpose restriction;
  • minimisation;
  • anti-linkage controls;
  • transparency;
  • rights;
  • oversight;
  • retention;
  • accuracy;
  • authentication design.

33.7 Identity theft is not the only risk

Other risks include:

  • profiling;
  • surveillance;
  • exclusion from services;
  • data matching;
  • discrimination;
  • administrative error;
  • impersonation;
  • loss of autonomy.

33.8 Article 87 does not itself harmonise national-number regimes

Controllers operating across borders must examine the applicable national laws rather than relying solely on the GDPR text.


34. A practical compliance framework

An organisation planning to process a national identifier should document the following analysis.

First, classify the identifier

Determine whether it is:

  • a formal national identification number;
  • an identifier of general application;
  • a sectoral identifier;
  • an ordinary internal identifier.

Second, identify the applicable national law

Check:

  • permitted actors;
  • permitted purposes;
  • collection conditions;
  • disclosure restrictions;
  • retention;
  • security;
  • sanctions.

Third, identify the Article 6 basis

Do not rely on Article 87 itself.

Fourth, test necessity

Ask whether the purpose can be achieved using:

  • customer number;
  • token;
  • partial identifier;
  • one-time verification;
  • sector-specific code.

Fifth, map operations

Document:

  • collection;
  • verification;
  • storage;
  • access;
  • use;
  • sharing;
  • transfer;
  • deletion.

Sixth, apply safeguards

Use:

  • masking;
  • encryption;
  • tokenisation;
  • limited access;
  • logs;
  • retention controls;
  • multi-factor authentication;
  • vendor restrictions.

Seventh, provide transparency

Tell people why the number is needed and whether provision is mandatory.

Eighth, prepare for rights and incidents

Establish:

  • correction procedures;
  • breach response;
  • fraud support;
  • restriction mechanisms;
  • deletion processes;
  • complaint handling.

Conclusion

Article 87 recognises that national identification numbers occupy a special position in data protection law. They provide major administrative benefits because they allow governments and authorised organisations to identify people reliably. But the same stable identifier can connect a person’s activities across otherwise separate parts of life. When used without restraint, it can become a tool for:

  • identity fraud;
  • surveillance;
  • profiling;
  • database linkage;
  • exclusion;
  • administrative error;
  • loss of personal autonomy. Article 87 therefore creates a controlled national opening clause. Member States may establish specific conditions governing:
  • who may use the identifier;
  • for what purpose;
  • in which circumstances;
  • for how long;
  • with whom it may be shared;
  • which safeguards must apply. Those national rules supplement rather than replace the GDPR. The complete legal analysis normally requires:

Article 6 lawful basis + Article 5 principles + national Article 87 conditions + appropriate safeguards.

The number is not automatically special-category data under Article 9, but it may still be highly sensitive in practice. Its risk lies especially in persistence, uniqueness, linkability and difficulty of replacement.

The most important practical safeguards are:

  • collect it only when necessary;
  • do not use it as a password;
  • mask it where the full number is unnecessary;
  • separate it from ordinary operational identifiers;
  • prevent unauthorised database matching;
  • restrict and log access;
  • encrypt or tokenise it;
  • retain it only for a defined period;
  • provide transparent information;
  • establish rapid correction and breach-response procedures.

The simplest summary is:

A national identification number should be treated as a powerful linking key, not as an ordinary reference number. Article 87 allows each Member State to regulate that key according to its national system, but every permitted use must remain lawful, necessary, proportionate and protected by safeguards capable of preventing the number from becoming an instrument of fraud, uncontrolled profiling or universal surveillance.