Skip to content
+370 5 212 1506 info@dat.lt

Personal code and ID copies: what you may ask a customer for

25 September 2026 · Good to know

A customer’s personal code (asmens kodas, the Lithuanian national identification number) may be processed only where one of the legal bases in Article 6 GDPR applies (Article 3(1) ADTAĮ, the Lithuanian Law on Legal Protection of Personal Data). The personal code may not be made public (Article 3(2) ADTAĮ) and may not be used for direct marketing (Article 3(3) ADTAĮ). Even with a legal basis, ask for the code only when you really need it for a specific purpose (Article 5(1)(c) GDPR). A copy of an identity document is usually not needed for customers: in most cases it is enough to see the document and note that it was checked.

What applies to employees and candidates is covered in Candidate CVs and ID copies: what an employer may keep. This article is about customers: buyers, tenants, club members, service users.

What the law says

Article 87 GDPR allows Member States to determine the specific conditions for processing a national identification number. In Lithuania, the specific rules for the personal code are in Article 3 ADTAĮ. It contains three rules:

  • the code is processed only where at least one basis in Article 6(1) GDPR applies;
  • the code may not be made public;
  • the code may not be processed for direct marketing.

The general GDPR principles do the rest. Data must be adequate, relevant and limited to what is necessary for the purpose (Article 5(1)(c) GDPR). By default, the controller must process only the data that is necessary for each specific purpose (Article 25(2) GDPR). So the question is always the same: what exactly is this code needed for, and can the purpose be achieved without it?

On what basis the code is requested

Contract. The code may be necessary to conclude or perform a contract (Article 6(1)(b) GDPR). But only where the contract really needs it, not because “we always do it this way”.

Legal obligation. Where a law requires the code, the basis is a legal obligation (Article 6(1)(c) GDPR). Then collect only what that law requires.

Legitimate interest. For example, assessing a customer’s creditworthiness. EDPB Guidelines 1/2024 (version for public consultation) list it among interests that can be recognised as legitimate (paragraph 16). But you then have to assess whether the customer’s interests override yours (Article 6(1)(f) GDPR) and write that assessment down, because the controller must be able to demonstrate compliance (Article 5(2) GDPR).

Consent hardly ever works here. Where the service is made conditional on consent to processing the code although the code is not necessary for the contract, the consent is presumed not freely given (Article 7(4) and Recital 43 GDPR). Where the code really is necessary for the contract, the basis is the contract, not consent. One rental firm asked customers for consent so that it could check their creditworthiness. Our attorney advised asking for consent only for marketing and assessing creditworthiness on the basis of legitimate interest. The reason is simple: a customer who refuses consent must not suffer for it. On the basis of legitimate interest, however, a refusal to allow a credit check can be a lawful reason not to provide the service.

Shop, rental, club: when you may and when you may not

A purchase and an invoice. The Law on Financial Accounting sets the mandatory content of an accounting document. For a natural person, the name and surname are stated. A code is named only for a legal person (Article 7(1) FAĮ). Tax rules can add further requirements, so check them. But asking a consumer for their personal code just “to issue an invoice” usually has no basis.

An enquiry, not yet a contract. A person asked whether a service provider could ask for their personal code while they were only enquiring about a service. In our view, the code may be needed to conclude a contract, but asking for it at the enquiry stage is excessive collection.

More than needed. Another person, buying goods, was asked for both their personal code and their ID document number. In our view, the document number was not needed for that purpose. Every extra field needs its own purpose.

Loyalty programmes and clubs. A name, a contact or a membership number is usually enough to recognise a member. The personal code may not be used for direct marketing on any basis (Article 3(3) ADTAĮ).

Rental and credit. Where expensive equipment is entrusted to a customer or deferred payment is offered, the code may be needed for a credit check. This has to be justified and written down, as described above.

Copies of documents

A document copy holds far more than you need to check identity: the photo, the signature, the document number, the expiry date, sometimes the code as well. In its guidelines on the right of access, the EDPB notes that national laws may restrict the scanning or copying of ID cards and the processing of official personal identification numbers, including on the basis of Article 87 GDPR (01/2022, paragraph 78). Keeping a copy of an identity document may breach the principles of purpose limitation and storage limitation (Article 5(1)(b) and (e) GDPR). The EDPB recommends checking the document and making a note, such as “ID card was checked”, instead of copying it (paragraph 79).

These guidelines are about checking identity when a person asks for their data. In our view, the same logic applies to customers: if the only aim is to be sure who the person is, seeing the document is enough. When you may ask for proof of identity after receiving an access request is covered in Subject access request: deadline and answer.

A copy is justified where a specific law requires or permits making or keeping it. Where a law only requires identity to be checked, seeing the document is usually enough. Then do only what that law requires, and keep the copy only as long as it allows.

What most often goes wrong

Copies “just in case”. Photos of passports in emails, chat apps and shared folders. Nobody knows how many there are or who can access them. The EDPB notes that a breach involving identity documents, especially combined with other data, can help to steal a person’s identity (Guidelines 9/2022, paragraph 108). When such a breach must be reported is covered in our article on personal data breaches.

A code entered without checking. In one business, someone else’s personal code was entered when a customer was registered. The record ended up in that other person’s data, and they asked how the business had their code. Data must be accurate (Article 5(1)(d) GDPR). The fix is simple: check the data entered against the document shown, rather than copying it.

A code made public. Lists of winners, lists of debtors, documents on a website. Article 3(2) ADTAĮ prohibits making the personal code public.

A code in the marketing database. Even where it was lawfully collected for a contract, it may not be used for direct marketing (Article 3(3) ADTAĮ).

The consequences are first of all legal. The person can lodge a complaint with the State Data Protection Inspectorate (Article 77(1) GDPR). A breach of the basic principles and of lawfulness falls in the highest fine bracket: up to twenty million euros or, for an undertaking, up to 4 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(a) GDPR). The same cap applies to breaches of obligations under Member State law adopted under Chapter IX GDPR (Article 83(5)(d) GDPR). Article 87 GDPR on the national identification number belongs to that chapter. VDAI fines breaches of the ADTAĮ under the GDPR and the ADTAĮ (Article 32(1) ADTAĮ); lower caps apply to public authorities and bodies that do not carry on commercial activity (Article 33 ADTAĮ). A person who suffers damage has the right to compensation (Article 82(1) GDPR).

When to call a lawyer

  • when you are preparing a contract, registration or order form and want to ask for the personal code in it;
  • when you assess customers’ creditworthiness and need a legitimate interest assessment;
  • when you hold copies of customers’ documents and do not know which you may keep;
  • when a code or a copy reached the wrong person or was made public;
  • when a customer asks why you need their code, or lodges a complaint.

Frequently asked questions

Can a shop ask for a personal code for an invoice?

Usually not. For a natural person, Article 7(1) FAĮ requires the name and surname on an accounting document, and names a code only for a legal person. Tax rules can add further requirements, but without such a specific requirement a consumer’s code is not needed for an invoice.

Can we photograph a customer’s passport when renting out an item?

Usually not. It is enough to see the document, check the details in the contract and note that the document was checked. The EDPB recommends this practice when checking identity for a data access request (Guidelines 01/2022, paragraph 79). In our view it fits rentals too. A copy is usually justified only where a law requires it.

Can we use the personal code in a loyalty programme?

Not for direct marketing. Article 3(3) ADTAĮ prohibits processing the personal code for direct marketing. It is usually not needed to recognise a member either, as a membership number or a contact is enough.

What should we do with copies we already hold?

List where they are and why they were made. If the purpose has ended, or was only to check identity, the copies must be deleted, because data is kept no longer than the purpose requires (Article 5(1)(e) GDPR). If a law requires the copy, keep it for as long as that law sets.

How to start

Send us your order, registration or contract form. We will tell you which fields have a legal basis, which are excessive and what to do with the codes and copies you have already collected.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and consultations.

Get a free assessment

Related articles