That is correct and that is also crucially why all these consent modals that have a second toggle for "legitimate interest" from partners are also blatantly non-compliant: you can only use ONE legal basis for processing and if consent is sufficient to opt out, that means it can not be "legitimate interest" as defined by the GDPR.
The definitions for all these exemptions are EXTREMELY narrow and court cases have demonstrated this repeatedly. If you have a legitimate interest to verify someone's ID to establish identity that does not mean you are allowed to do the ID verification yourself (rather than relying on a third party) nor that you're allowed to use a service outside the EU (e.g. Israel) nor that you (nor they) are allowed to store that ID any longer than necessary to process it exactly once.
The GDPR dictates data minimization. If your business model is incompatible with that and it's not because of regulatory requirements, I'm sorry but we have a word for that and it's "criminal enterprise".