Anyone verifying their identity digitally, whether to open a bank account, pass through the passport gates at Schiphol, or soon to gain access to a football stadium, will encounter an authenticity check of their identity document. A key part of this process is reading the NFC chip in the passport, ID card, or driver's license. Because questions have arisen about this, we are explaining what this check entails and how Siip handles it.
September 22, 2026
A common international practice
Reading the chip for authenticity verification has been standard practice for years, used by both public and private organizations. Banks use it when activating their apps and for remote customer onboarding. The DigiD app reads the chip for ID verification. The Royal Netherlands Marechaussee uses it for automated border crossings. The RDW offers its own app to verify the authenticity of a driver's license, and the Social Insurance Bank and various municipalities also make use of it. You may also recognize it from checking into a hotel or renting a car or shared scooter. Siip is no exception and applies this same proven method.
This method is called passive authentication and is defined in international standards ICAO 9303 (for passports and ID cards) and ISO/IEC 18013-3 (for driver's licenses). This check verifies the digital signature applied by the issuing authority to the data within the chip. This confirms that the document is genuine and that its contents have not been altered. This is not a design choice by Siip, but a mandatory security mechanism that verifies the integrity of the chip as a whole.
Why this is currently in the spotlight
The introduction of Personal Digital Access at professional football organizations has brought this topic into the spotlight. Privacy is a fundamental right, and a critical approach is therefore entirely justified. It is important to receive accurate and clear information.
How Siip performs the authenticity check
The authenticity check takes place during registration, before an account is created on the phone to be used for Personal Digital Access. For this check, the data in the chip is verified as a single entity. The issuing authority has applied one digital signature to all the data combined. The check can only confirm that the document is genuine by verifying that signature against the complete set. You cannot select a few fields and leave the rest out. The authenticity lies in the whole, not in the individual fields.
The authenticity check is performed on a server because the authenticity of a document cannot be reliably determined on the phone itself. It is a transient process. After the authenticity check, no document data remains: it is destroyed. There is no storage, no logging, and no caching of the raw chip data. This has been independently verified from a technical perspective.
Data on your mobile
What remains is a small set of only the necessary validated data: first name, last name, date of birth, and passport photo. This is stored in an encrypted vault on the user's own phone, under their own control. The football organization only receives these four pieces of data when someone accepts a ticket, and only with the user's consent. They are automatically deleted twenty-eight days after the event. The club never receives the BSN (Citizen Service Number).
Older documents containing a BSN
In the chips of older documents, the government included the Citizen Service Number (BSN). This concerns a small and phasing-out portion of the documents currently in circulation in the Netherlands: passports issued before August 31, 2021, and ID cards issued before August 1, 2021. Newer passports and ID cards no longer contain the BSN in the chip, and for driver's licenses, Siip has configured the system so that the data group containing the BSN is not read.
For older documents where the BSN is still in the chip, that number is processed in an encrypted state for a fraction of a second during the authenticity check, solely to establish that the document is genuine. It is not read as a separate data point, nor is it used, linked, or stored. The state advocate, Pels Rijcken, has ruled that this method complies with laws and regulations. Anyone who would prefer that the BSN is not included at all can register using a newer document or a driver's license. The club's fan desk can assist with how to handle older documents.
Independently audited, with positive results
Siip’s methodology has been independently assessed, both legally and technically, on behalf of Sportinnovator, part of the Ministry of Health, Welfare and Sport, and the KNVB.
Law firm Pels Rijcken conducted a legal privacy analysis and concluded: “We see no significant legal issues, though we do have a few recommendations.” Siip is adopting these recommendations, which include informing users with older documents in advance about the short-term processing of their BSN (citizen service number).
In parallel, The S-Unit performed an independent technical assessment. This confirmed that the authenticity check is double-encrypted, that subsequently only the first name, last name, date of birth, and passport photo are stored decentrally in the user’s wallet, and that the data read via the NFC chip is destroyed immediately after the check.
Regarding the BSN, The S-Unit states that it “is not stored in a database or processed into hash values” and “is not used as an identification number.”
Looking ahead
Siip is prepared for the future. Control over one’s own data, data minimization, privacy-by-design, and security-by-design remain our core principles. We are always open to further improving these processes.
