Selective disclosure
Selective disclosure is a privacy-preserving approach that lets a person reveal only the identity attributes or payment details needed for a specific interaction. Instead of sharing an entire identity record, credential or payment profile, the person shares a narrower set of claims, such as an age threshold, account ownership status or authorization for a transaction.
For financial institutions, selective disclosure connects privacy with stronger decision-making. It can reduce unnecessary exposure of personal data while still giving a bank, merchant or payment service enough evidence to authenticate a customer, assess an action and meet its obligations. Entersekt places this principle within a wider approach to authentication, risk and customer experience.
Key takeaways: selective disclosure
- Selective disclosure lets a customer share only the identity attributes or proofs needed for a specific decision.
- It limits unnecessary data exposure while preserving the evidence required to establish trust.
- It does not replace authentication, fraud assessment or regulatory obligations.
What is selective disclosure?
Selective disclosure is the controlled sharing of specific attributes from a larger set of identity or transaction data. The holder of the data chooses which information to present, while the recipient verifies that information without automatically receiving every other attribute in the underlying record.
For example, a digital identity credential may contain a person's full name, address, date of birth and nationality. A service checking an age requirement may need proof that the person is over a defined age, but not the person's exact birth date or home address. Selective disclosure supports that narrower proof.
In payments, the same principle can apply to the information exchanged during authorization. A merchant may need confirmation that a payment instrument is valid and authorized, but it does not necessarily need to handle the customer's full account or card details. Tokenization, payment cryptography and network-specific controls can help limit the data exposed to each participant.
How does selective disclosure work?
Selective disclosure works by separating a credential or data record into verifiable claims and allowing only the required claims to be presented. The exact mechanism depends on the credential format, cryptographic scheme and trust model.
- An issuer creates evidence. An organization such as a bank, government authority or employer issues a signed credential or attestation containing claims about a person, account or authorization.
- A holder stores the evidence. The person or organization receiving the credential keeps it in a wallet, application or another controlled environment.
- A verifier requests specific information. The service states which attributes or proof are needed for the transaction or decision.
- The holder creates a limited presentation. The holder shares only the requested claims or a cryptographic proof that a claim is true.
- The verifier checks authenticity and integrity. Where the credential uses digital signatures, public-key verification helps confirm its trusted origin and detect alterations. The verifier also checks that the presented evidence satisfies the request.
Some systems disclose a claim directly. Others support derived proofs. A derived proof can establish a fact, such as meeting an age threshold, without revealing the underlying value. RFC 9901 defines a selective disclosure mechanism for individual elements in a JSON Web Token, while the W3C Verifiable Credentials Data Model defines the broader issuer, holder and verifier model.
What information can be selectively disclosed?
The information depends on the credential and the service request. Common examples include:
| Use case | Information that may be shared | Information that may remain undisclosed |
|---|---|---|
| Age verification | Proof that the person meets an age threshold | Exact date of birth and address |
| Account ownership | Proof that the person controls a named account | Unrelated account balances and transaction history |
| Payment authorization | Confirmation that a payment is approved and meets the required conditions | Unnecessary account or card details |
| Identity verification | Specific attributes required for onboarding or recovery | Attributes unrelated to the risk decision |
| Eligibility checks | Proof that a person meets a defined criterion | The complete underlying identity record |
Selective disclosure does not mean that data is never collected or that every transaction can be completed anonymously. A financial institution may still need additional information for know-your-customer checks, anti-money laundering controls, sanctions screening, fraud prevention, recordkeeping or regulatory reporting. The principle is to match collection and disclosure to a defined purpose.
Why does selective disclosure matter in financial services?
Selective disclosure matters because identity and payment journeys often involve several parties. Sharing an entire data record with every participant increases the number of systems that hold sensitive information and expands the consequences of a breach or misuse.
Data minimization can reduce unnecessary exposure, support privacy obligations and make customer consent more meaningful. It can also improve customer experience when a service can verify a required fact instead of repeatedly asking for documents or unrelated personal information. A related privacy-focused approach is explored in The invaluable role silent authenticators play in privacy protection, which discusses cryptographic browser recognition without cross-domain tracking.
Selective disclosure is one layer of a financial-services control environment. It does not replace customer authentication, transaction monitoring, device intelligence, identity proofing or fraud decisioning. A customer can present a valid credential and still be manipulated into approving a scam payment. The institution must therefore assess identity, intent, device, behavior and transaction context together.
Selective disclosure and authentication
Authentication helps verify who or what is interacting with the service. Selective disclosure addresses a related privacy question: which evidence needs to be revealed to support that decision?
A modern authentication journey can request an appropriate level of evidence for the action. A routine login may rely on an enrolled device and contextual signals. A high-risk payment or account change may require stronger verification and a more detailed audit trail. Context-aware authentication helps financial institutions align the decision with the risk and circumstances of the interaction.
The two ideas should be designed together. Asking for excessive information can create privacy risk and customer friction. Asking for too little evidence can leave an institution unable to establish trust or investigate a disputed action.
Selective disclosure and payment security
Payment security uses several techniques to limit the data exposed during a transaction. Tokenization substitutes a payment token for sensitive account data. Strong customer authentication verifies the payer through permitted factors. Payment cryptography protects the integrity and authenticity of messages. Selective disclosure focuses on the attributes or claims each participant needs to receive.
These controls address different risks. Tokenization can reduce the value of payment data stored by a merchant. Authentication can help establish who is approving an action. Risk analysis can identify unusual behavior or a suspicious recipient. Together, they support a payment flow that shares enough evidence for authorization while limiting unnecessary data movement. Glenbrook Partners' white paper, Tokenization and 3-D Secure: Complementary Components of Modern Risk Management, explains why protecting payment credentials and authenticating the payer are complementary controls.
Payment authentication should also account for user intent. A valid customer may approve a transfer after being deceived by a criminal. For that reason, selective disclosure should sit alongside transaction risk assessment and scam prevention, rather than being treated as proof that a payment is safe.
What standards support selective disclosure?
Several standards and regulatory initiatives are relevant to selective disclosure:
- W3C Verifiable Credentials Data Model 2.0: Defines a model for credentials and presentations involving issuers, holders and verifiers. The specification includes security and privacy considerations for digital credential ecosystems.
- IETF RFC 9901: Defines Selective Disclosure for JSON Web Tokens, including a mechanism for disclosing individual elements of a signed JSON data structure.
- JOSE and COSE for verifiable credentials: W3C's credential security specification describes how established signing and encryption formats can secure verifiable credentials and presentations, including SD-JWT-based approaches.
- European Digital Identity Framework: EU digital identity materials describe selective disclosure of attributes, data minimization and user control as privacy features of digital identity wallets.
- Privacy and data protection principles: Data minimization, purpose limitation, transparency and accountability are important design considerations when institutions collect or share personal data.
Standards do not remove the need for governance. A production design still needs clear definitions of issuer trust, verifier permissions, consent, revocation, key management, auditability, retention and recovery.
What are the limits of selective disclosure?
Selective disclosure reduces unnecessary data sharing, but it does not solve every identity or fraud problem. Important limitations include:
- Trust still matters. A verifier must know which issuers and credential formats it accepts. A cryptographically valid credential from an untrusted issuer may not be useful.
- Metadata can reveal information. Timing, account relationships, device data and transaction patterns may expose sensitive context even when the payload is limited.
- Revocation and updates require design. A verifier may need to confirm that a credential remains valid and has not been suspended or replaced.
- Wallet and key security remain critical. If a holder's device or signing key is compromised, an attacker may misuse otherwise valid evidence.
- Fraud can involve valid users. Selective disclosure can establish a claim without proving that a customer understood the transaction or intended the recipient. This distinction underpins the ATO prevention shift from identity to intent, which explains why identity checks must be complemented by contextual assessment.
- Interoperability is still evolving. Different ecosystems may use different credential formats, trust registries, presentation rules and consent experiences.
How should financial institutions evaluate selective disclosure?
Financial institutions should evaluate selective disclosure as part of an end-to-end identity and payment control strategy. The most important question is not how much data a system can share. It is what evidence is necessary for a particular decision and how that evidence will be protected throughout its lifecycle.
- Map the decision and its purpose, such as onboarding, login, payment approval or account recovery.
- Define the minimum attributes or proofs needed to reach the required assurance level.
- Separate identity evidence from transaction and behavioral risk signals.
- Confirm issuer, verifier, consent, revocation and audit requirements.
- Test how the experience works when the customer declines to share information, loses a device or needs account recovery.
- Measure privacy, fraud, approval, abandonment and operational outcomes together.
For many institutions, the practical objective is a risk-aware journey that asks for stronger evidence when the action warrants it and avoids unnecessary disclosure during lower-risk interactions. Silent authentication is one example of how trusted endpoint signals can support low-interruption journeys while high-risk actions receive additional scrutiny.
Frequently asked questions about selective disclosure
➡️ Is selective disclosure the same as data minimization?
Selective disclosure is one technical way to apply data minimization. Data minimization is the broader privacy principle of collecting, processing and retaining only the information needed for a defined purpose. Selective disclosure focuses specifically on what a holder reveals to a verifier during an interaction.
➡️ Does selective disclosure make payments anonymous?
No. Selective disclosure can limit the payment and identity information shared with a participant, but regulated payment providers may still need to identify customers, screen activity, keep records and investigate fraud. Privacy-preserving payment design is different from removing accountability.
➡️ Can selective disclosure prevent identity theft?
Selective disclosure can reduce the amount of personal data exposed, which may reduce the value of data captured by an attacker. It cannot prevent every identity theft scenario. Secure wallets, issuer controls, authentication, device protection, fraud monitoring and recovery processes remain necessary.
➡️ Selective disclosure vs. zero-knowledge proof?
Selective disclosure may reveal selected signed attributes from a credential. A zero-knowledge proof can establish that a statement is true without revealing the underlying value. Some credential systems use zero-knowledge techniques, but the terms describe different levels of privacy and different technical mechanisms.
➡️ Why is selective disclosure relevant to banks?
Selective disclosure helps banks control how identity and payment evidence moves across digital journeys. It can support privacy, reduce unnecessary data exposure and improve consent, while authentication and risk analysis determine whether the requested action should be allowed.