What actually happens to our ID and biometric data after testing?
When we do ID verification testing, payment testing, opening accounts on casino apps, and other tasks that we normally wouldn't do in real-life scenarios, what happens to all the personal data we provide?
I'm talking about biometrics, ID documents, payment details, and other PII. Do clients delete this data immediately after the test is completed, or is it stored somewhere separately for a certain period of time?
And is there any way for us as testers to know what happens to it afterward? I sometimes wonder whether a task I'm doing today could somehow create a risk years later, like identity theft, data leaks, or some other consequences.
This is something that always bothers me whenever I see tasks of this kind, so I'm curious how others here look at it.