ID Proofing - Attribute Collection - Minimum Necessary Collection of PII, v1.0

Credential Service Providers must limit the collection of PII to the minimum necessary to uniquely identify a given subject. This may include attributes that correlate identity's to authoritative sources and to provide RPs with authorization attributes.

Assessment Step

1
CSP Attribute Collection Minimization (CSPAttributeCollectionMinimization)
Does the CSP limit the collection of PII to an acceptable minimum given the level of assurance at which the CSP operates and the attribute requirements of their trusted partners?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that make it clear what types of PII is collected by the CSP.

Conformance Criteria (1)

C1
Collection of PII SHALL be limited to the minimum necessary to validate the existence of the claimed identity and associate the claimed identity with the applicant providing identity evidence for appropriate identity resolution, validation, and verification. This MAY include attributes that correlate identity evidence to authoritative sources and to provide RPs with attributes used to make authorization decisions.
Citation
NIST SP 800-63A
Sections 4.2 (2), 4.4.1.1, and 4.5.1