34. A practical compliance framework
An organisation planning to process a national identifier should document the following analysis.
First, classify the identifier
Determine whether it is:
- a formal national identification number;
- an identifier of general application;
- a sectoral identifier;
- an ordinary internal identifier.
Second, identify the applicable national law
Check:
- permitted actors;
- permitted purposes;
- collection conditions;
- disclosure restrictions;
- retention;
- security;
- sanctions.
Third, identify the Article 6 basis
Do not rely on Article 87 itself.
Fourth, test necessity
Ask whether the purpose can be achieved using:
- customer number;
- token;
- partial identifier;
- one-time verification;
- sector-specific code.
Fifth, map operations
Document:
- collection;
- verification;
- storage;
- access;
- use;
- sharing;
- transfer;
- deletion.
Sixth, apply safeguards
Use:
- masking;
- encryption;
- tokenisation;
- limited access;
- logs;
- retention controls;
- multi-factor authentication;
- vendor restrictions.
Seventh, provide transparency
Tell people why the number is needed and whether provision is mandatory.
Eighth, prepare for rights and incidents
Establish:
- correction procedures;
- breach response;
- fraud support;
- restriction mechanisms;
- deletion processes;
- complaint handling.
Conclusion
Article 87 recognises that national identification numbers occupy a special position in data protection law.
They provide major administrative benefits because they allow governments and authorised organisations to identify people reliably. But the same stable identifier can connect a person’s activities across otherwise separate parts of life. When used without restraint, it can become a tool for:
- identity fraud;
- surveillance;
- profiling;
- database linkage;
- exclusion;
- administrative error;
- loss of personal autonomy.
Article 87 therefore creates a controlled national opening clause.
Member States may establish specific conditions governing:
- who may use the identifier;
- for what purpose;
- in which circumstances;
- for how long;
- with whom it may be shared;
- which safeguards must apply.
Those national rules supplement rather than replace the GDPR.
The complete legal analysis normally requires:
Article 6 lawful basis + Article 5 principles + national Article 87 conditions + appropriate safeguards.
The number is not automatically special-category data under Article 9, but it may still be highly sensitive in practice. Its risk lies especially in persistence, uniqueness, linkability and difficulty of replacement.
The most important practical safeguards are:
- collect it only when necessary;
- do not use it as a password;
- mask it where the full number is unnecessary;
- separate it from ordinary operational identifiers;
- prevent unauthorised database matching;
- restrict and log access;
- encrypt or tokenise it;
- retain it only for a defined period;
- provide transparent information;
- establish rapid correction and breach-response procedures.
The simplest summary is:
A national identification number should be treated as a powerful linking key, not as an ordinary reference number. Article 87 allows each Member State to regulate that key according to its national system, but every permitted use must remain lawful, necessary, proportionate and protected by safeguards capable of preventing the number from becoming an instrument of fraud, uncontrolled profiling or universal surveillance.