Verify the request before the document
Requests for identity documents are a staple of fraud, and the request itself is the part most worth scrutinising. Confirm through a contact route you already had — a number from a statement or the organisation's published site — rather than one supplied in the message.
This separate verification step can reduce impersonation risk. It is still important to examine the request and follow the organisation's documented process.
Ask whether the full document is required
Many processes need one field: a date of birth, a document number, an address, an expiry date. Sending a complete high-resolution scan when a single fact was needed hands over far more durable identity data than the task required.
Ask what specifically is being verified. Requirements for redacted or partial copies vary, so follow the requesting authority's rules rather than assuming one will be accepted.
What happens to the copy afterwards
Once sent, the document lives in the recipient's systems: their inbox, their backups, their downloads folder, and whatever staff access their processes allow. None of that is governed by your vault, and deletion on your side recalls nothing.
Setting an explicit expectation — what it is for, and that it should be deleted afterwards — is worth doing even though you cannot enforce it.
Preparing the copy
- Confirm the request through a separate, trusted contact route.
- Ask whether a redacted or partial copy is acceptable.
- Remove unnecessary metadata, including location.
- Where appropriate, mark the copy with its purpose and date.
- Send once, confirm receipt, then delete the temporary export from Photos, Files, and Downloads.
A note on marking
Adding a visible note of the purpose and date can discourage reuse of the copy elsewhere. Do not alter a document being submitted to an authority unless its rules explicitly permit it — for those, send it unmodified through the channel they specify.
Three mistakes
- Sending to an address copied from an unverified message.
- Leaving the export sitting in Photos or Downloads afterwards.
- Assuming deleting your copy affects the recipient's.
A fictional example
Maya starts with a non-sensitive test: “Confirm the request through a separate trusted contact route.” Next, Maya follows the second check: “Ask whether a redacted or partial copy is acceptable.” This fictional scenario demonstrates the decision process; it is not a report of product testing.
Common mistakes
- Sending to an address copied from an unverified message
- Leaving the export in Photos or Downloads
- Assuming deletion recalls the recipient's copy
What this workflow does not change
- Sending to an address copied from an unverified message
- Leaving the export in Photos or Downloads
- Assuming deletion recalls the recipient's copy
Questions people ask
Can a watermark prevent misuse?
No. It can add context but is not a technical access control.
Should I use ordinary email?
Use the recipient's approved secure channel and understand its retention; email may create many durable copies.