Asking out of real curiousity. I am German citizen, but have not lived there after the first government office got a PC.
Asking out of real curiousity. I am German citizen, but have not lived there after the first government office got a PC.
The document number in the upper right corner in the picture, I imagine.
One motivation is that you want to travel to Israel and to some Arab country, which do not accept passports with stamps of the "enemy" in it.
I don't know if they verify the motivation in any way or whether it's enough to say so.
Seems like motivation enforcement is quite strict, as they do state that you can't even get two passports for the "enemy visa" reason when the visits are just planned, but you can't prove it yet (palne tickets etc.) you won't get it, and you'll have to go to the German embassy after you can prove it...
[1]https://www.bmi.bund.de/SharedDocs/faqs/DE/themen/moderne-ve...
There’s also another one which changes every time you move across financial administrative districts.
Germany has had a constitutional restriction in place explicitly prohibiting an SSN equivalent.
These days, the tax ID can supposedly be used for that purpose, but I haven’t seen much use of that yet.
Very interesting! Thank you for this
FWIW, I think in this age of massive databases that can be effortlessly joined on fuzzy matching criteria, the lack of a unique person identifier is more of a hurdle for legitimate use cases than a safety measure against government or corporate overreach.
One good thing about it is the complete lack of the horrible "SSN as both primary key and bearer authentication token" pattern that's commonplace in the US, though – but the alternatives are pretty annoying, in my experience.
TIL. My last and current number had the first 4 characters the same, so I didn’t even realize that (and the times before I never thought of it).
Of course it'd be complicated if e.g. the 2 Hanses were born in a foreign country with no such checks, and moved to Germany later on...
> This online service compares the name read from your ID card, your electronic residence permit or eID card for citizens of the European Union with the name specified in your OpenPGP key. If the names match, your public key is electronically signed by Governikus, confirming the match.
See https://www.bmi.bund.de/SharedDocs/pressemitteilungen/DE/202...
Is it allowed to use the Steuer-ID for non-government purposes?
The number is only intended to be used by government entities. The law restricts usage to census and communication with government entities (as well as already established tax-related use).
In any case, Germany does not have one, yet Schufa (the German credit scoring agency) still exists and still is able to build profiles on everybody living in Germany. So what's the gain?
Data mining operations like them will be able to perform good-enough matching based on fuzzy data like current and previous address; it just makes it more likely for errors to happen due to non-unique names and incorrectly merged or split credit profiles, and makes legitimate requests for your own data more difficult than necessary.
Creating one that is shared between private instances would require explicit consent by the citizen to every company to use it according to GDPR. Well, of course Schufa requires consent too, which is not truly a decision a citizen can make. If you don't agree I don't think you'd find any bank opening an account. But I do hope there will such a public outcry if anybody tried to start such surveillance again today, it would fail in the beginning. Like Google Streetview did.
I am not convinced the Schufa score data quality is always very good. (Not living there I cannot request my own one, just a feeling.)
That still does not make it "government information". It's a primary key that (currently) may not be used by the industry. But by itself, it does not identify anything or anyone. In that sense, it's even less sensitive than a name; realistically though, if it's widely stored next to the associated name anyway, it's effectively the same as a name in terms of sensitivity.
A credit score is effectively a database shared across the financial industry. As such, it needs some sort of primary key. That can be either be something globally unique, like an SSN or equivalent, or a wonky composite primary key (first_name, last_name, date_of_birth, last_known_address) which will cause lots of false positives and false negatives:
What if you change your name? What if you move? What if there's somebody with the same name born on the same day in the same city? What if the spelling of your city has changed between your birth and your time of requesting a loan/credit card?
You may object to the idea of credit scoring in general, but being ok with credit scoring, yet objecting to the usage of a sane primary key to do it, makes no sense to me.
I don't want to live in such society. Yes, bad things can and have be done before. But making them simpler, cheaper, and more scalable needs to be avoided.
The much more effective solution here is to regulate businesses in when they can request/use somebody's primary key and/or other PII, and to simply not allow it in any case where a pseudonymous identifier or partial information (e.g. only somebody's approximate age rather than their full date of birth) would do just as well.
And Germans arguably aren’t “forgetting their history”, they are just regulating to achieve desired outcomes (no government and corporate privacy invasion; strong authentication where necessary), not mechanisms (no unique identifiers).
Times and technology change, so why uphold an old (interpretation of) law that is neither necessary nor sufficient to achieve the desired outcome in the present day?
An identifier is issued by the government for legally-specified government uses is government information.
Other identifiers may or may not be, but other identifiers aren’t the issue here.
Overgeneralizing the issue in dispute to obscure relevant context is not productive.
(At the moment I am citizen, but not a resident so I have no Steuer-ID yet. But a) it might become a resident some day again and b) as a citizen I occasionally have interact with various authorities anyway. So on top of being interested what happens in Germany in general it might affect me personally.)
An increasing number of previosly public administrative functions have been privatized. Does that immediately mean that data exchange stops there?
I can't think of a service like the ones on the list that has been privatized. The law as written would not extend to that but who knows what would be enacted in that case.
Anyway, this is all theory so far as they are still in the stage of drawing up a technical architecture.
The Steuerindentifikationsnummer used to be strictly limited to tax purposes. Against original political promises the legislation has been changed 2 years ago, weakening the limitations. I am not familiar with the details.