Share Your ID Without Losing Control

ShareKYC TeamUpdated Jun 20, 2026 6 min read

Every time you send an ID copy, you make a permanent, uncontrolled copy of yourself. The moment the file leaves your outbox it lives in someone else's inbox, their backups, maybe a shared drive, possibly a screenshot. If you share your ID regularly — opening accounts, onboarding with a new PSP, sitting across from a notary — the question is not whether to share, but how to share your ID without losing control of what happens next.

Control is not a single feature. It is five separate levers, and most "secure" methods give you one or two and call it a day. Email gives you none. A password-protected ZIP gives you a brittle password and nothing else. Below is what real control looks like, lever by lever, and how to decide which ones a given situation actually needs.

The five levers of control

Think of every share as a set of dials, not an on/off switch. You rarely need all five at maximum, but you should consciously set each one.

Lever What it controls When it matters most
Expiry How long the link works Anything where the recipient only needs a one-time look
Access limit How many opens are allowed Replay risk, forwarded links, shared inboxes
Download on/off Whether a permanent copy can be saved When the law doesn't require them to retain a copy
Instant revocation Killing access after the fact Deals that fall through, wrong recipient, second thoughts
Watermark / redaction What's visible and how traceable it is Casual requests, brokers, anything outside hard GwG duties

The mistake is treating sharing as binary: either they have my ID or they don't. The practitioner's version is granular: this recipient gets these fields, for this long, this many times, without a download, watermarked to them.

Expiry: shrink the window

A copy that works forever is a copy you've lost. Most legitimate KYC checks need your data for minutes to days, not indefinitely. A notary verifying identity at signing needs a live look during the appointment. A PSP's onboarding team needs a few hours to run their check.

Set the shortest expiry the workflow tolerates. If the recipient says they need it open for a week, ask why — and if the answer is "so we have it on file," that's a retention question, not an access one, and it's negotiable. Pair expiry with a calendar reminder to confirm the check completed before the link dies on its own.

Access limit: cap the opens

Expiry handles time; the access limit handles repetition. A link set to a single open behaves like a sealed envelope: the recipient looks once, and a forwarded or leaked URL is already spent. This is the lever that defends against shared mailboxes and the "let me CC my colleague" reflex that quietly multiplies who sees your passport.

For most one-to-one checks, two or three opens is a sane ceiling — enough for the recipient to reload the page, not enough for the link to become a circulating asset.

Download off: don't hand over a permanent copy

This is the lever people forget. You can let someone view your ID without letting them keep it. With downloads disabled, the recipient sees what they need to verify on screen, but no file lands on their disk, their cloud, or their backup rotation.

There's a legal nuance here worth internalising. Banks and obliged entities under the Geldwäschegesetz often must retain a record of the identification — but "a record" is not always "a full unredacted copy of your ID forever." For casual requests outside those hard duties (a broker, a marketplace, a landlord), there is frequently no legal basis to retain a copy at all. Default downloads to off and make the other side justify needing more. For where the line actually sits, see what banks are actually allowed to require for KYC.

Instant revocation: the undo you'll eventually need

Deals fall through. You send to the wrong address. A vendor you onboarded with turns out to be sketchy. Without revocation, none of that matters — the copy is gone and you're just hoping. With it, you kill access in one action and the link goes dark.

Be honest about what revocation can and can't do. It stops future access cleanly. It does not erase what a recipient already viewed or — if you forgot to disable downloads — already saved. That's exactly why the levers stack: revocation is your safety net, but download-off and a short access limit are what keep the net from needing to catch much. The mechanics, and what to do when a recipient has already saved a copy, are covered in how to revoke access after sharing.

Watermark and redaction: control what's visible and traceable

The last lever splits in two.

Redaction controls what the recipient sees. If a request only needs to confirm your name and date of birth, your document number, machine-readable zone, and photo may be none of their business. Field-level and document-level scoping means you share the minimum, not the whole laminated card. What you can legally black out — and the diagonal Sperrvermerk note that limits how a copy may be used — is its own topic in redacting ID copies.

Watermarking controls traceability. A visible overlay binding the copy to a purpose, date, and recipient ("For account opening at X, 12 Jan 2026 — not valid for other use") deters casual misuse and reuse. An invisible forensic watermark goes further: if a copy ever surfaces where it shouldn't, you can tie the leak back to the exact share. A watermark doesn't stop a determined attacker, but it changes the economics and the accountability — details in how to watermark ID documents the right way.

Putting the levers together

A decision rule that holds up in practice: set every dial deliberately, then loosen only the ones the recipient can justify.

  • Bank or notary, hard legal duty: Scope to what the GwG check needs, short expiry, low access limit, downloads on only if retention is genuinely required, watermarked to the recipient.
  • PSP or broker onboarding: Scope tightly, short expiry, downloads off, revocation ready, watermarked.
  • Casual request (marketplace, landlord, "just send a copy"): Push back first. If you proceed, redact hard, downloads off, single open, short expiry, watermarked. Often the right move is to offer a scoped link instead of a file at all.

This is precisely the model behind ShareKYC: verify your identity data once, hold it AES-256 encrypted in an EU-hosted vault, and share it through links that carry expiry, access limits, download control, instant revocation, a full audit log, an invisible forensic watermark, and field-level scope. The copy never leaves a place you control.

The shift worth making

Stop thinking of ID sharing as sending a file and start thinking of it as granting scoped, revocable access. The file is the old mental model — and the file is the thing you can't get back. Once you internalise the five levers, "can you send me a copy of your passport?" stops being a request you simply comply with and becomes a negotiation you lead.

If you share your ID more than a couple of times a year, building this into a habit pays off fast. A good place to start is mapping which fields any given request actually needs before you share anything at all — ShareKYC is built to make that the default, not the exception.

Frequently asked questions

Can I really revoke an ID link after someone has opened it?

You can revoke future access instantly, so the link stops working and any cached preview is cut off. You cannot un-see what was already viewed, which is why download-off and watermarking matter alongside revocation.

Is a secure link safer than emailing a PDF?

Yes. An emailed PDF is a permanent, uncontrolled copy sitting in at least two mailboxes and their backups. A scoped link keeps the file in one vault you control and revoke.

Does an access limit replace an expiry date?

No, use both. The access limit caps how many opens are allowed; the expiry caps how long the window stays open. Together they close off both replay and forgotten-link risk.

What scope should I share for a standard bank onboarding?

Share only the document and fields the GwG actually requires for that check. Redact or hide the rest, and switch downloads off unless retention is legally mandated.