Design requirement R5.1: Need to know principle
An essential and fairly universal principle in this context is compliance with the "need to know" principle: only the customers themselves and entities relevant to the KYC process must have access to customers' personal data. This is also a general recommendation for information systems from a security perspective.
Source paper
This design requirement is proposed by Designing a Framework for Digital KYC Processes Built on Blockchain-Based Self-Sovereign Identity (Vincent Schlatt, Johannes Sedlmeir, Simon Feulner, Nils Urbach, 2022).