A dual-framework guide to identity verification under the California Consumer Privacy Act (CCPA/CPRA) and the EU General Data Protection Regulation (GDPR), including the CPPA’s implementing regulations and EDPB guidance.
I. Introduction: Why Verification Is a Two-Sided Legal Problem
Identity verification sits at the intersection of two competing legal obligations. On one side is the individual’s legally enforceable right to access personal information, correct inaccuracies, and have it deleted. On the other side is the organization’s obligation not to disclose, alter, or destroy personal data in response to a request made by someone who is not the data subject. Organizations that impose unnecessarily burdensome verification requirements impede the exercise of legal rights. Conversely, honoring requests without adequate identity confirmation risks disclosing sensitive personal information to an unauthorized party.
Under the CCPA, the right to opt out of sale or sharing is expressly excluded from the verifiable consumer request framework. This page focuses exclusively on access, correction, and deletion requests.
II. CCPA: The “Verifiable Consumer Request” Framework
Statutory Definition
A “verifiable consumer request” is a request made by a consumer or their authorized representative for which the business can reasonably verify — using commercially reasonable methods — that the person making the request is the consumer about whom personal information was collected or a person authorized to act on their behalf. (§ 1798.140(ak))
The Core Verification Obligation
Every CCPA-subject business must establish, document, and comply with a reasonable method for verifying consumer identity. The method must be calibrated to the sensitivity of the personal information at issue and the risk of harm from unauthorized disclosure, deletion, or correction. (§ 1798.130(a); 11 CCR § 7060(a))
The Data Minimization Constraint
Verification should wherever possible use personal information the business already holds about the consumer. Where additional information must be requested, it may be used only for verification, security, or fraud prevention and must be deleted as soon as practicable after the request is processed. It may not be retained, analyzed, disclosed, or used for any other purpose. (11 CCR § 7060(b))
When Verification Cannot Be Completed
If a business cannot verify the consumer’s identity using a commercially reasonable method, it is not required to comply with the request, but must inform the consumer that it cannot verify their identity and explain what additional information may allow verification to be completed. (11 CCR § 7060(f))
III. CCPA: Tiered Standards of Certainty by Request Type
The CPPA’s verification regulations establish a tiered system calibrated to the nature and risk level of the particular request. (11 CCR § 7062)
- Reasonable Degree of Certainty: Matching at least two data points provided by the consumer against reliable data points already maintained by the business.
- Reasonably High Degree of Certainty: Matching at least three data points, plus a signed declaration under penalty of perjury that the requestor is the consumer whose information is at issue.
Request to Know — Categories of Personal Information (11 CCR § 7062(b))
Requires verification to a reasonable degree of certainty. Matching two reliable data points will ordinarily satisfy this standard.
Request to Know — Specific Pieces of Personal Information (11 CCR § 7062(c))
Requires a reasonably high degree of certainty: matching at least three data points plus a signed declaration under penalty of perjury.
Request to Delete (11 CCR § 7062(d))
Context-dependent. The governing factors are the sensitivity of the personal information and the risk of harm from unauthorized deletion. Deletion of sensitive financial, medical, or biometric data should require a reasonably high degree of certainty.
Request to Correct (11 CCR § 7062(e); § 7060(c))
Requires a reasonable degree of certainty. Where the consumer seeks to correct the very information used for verification, the business should use alternative data points not subject to the correction request.
IV. CCPA: Accountholders vs. Non-Accountholders
Password-Protected Account Holders (11 CCR § 7061)
Submission through an authenticated session constitutes a verifiable consumer request for most request types. However, for disclosure of specific pieces of personal information, deletion, or correction of sensitive fields, re-authentication before proceeding is required. Where the business has grounds to suspect fraudulent or malicious activity, it shall not comply until additional verification is completed.
Non-Accountholders (11 CCR § 7062)
The tiered data-point matching framework applies. Reliable data points include email address, mailing address, telephone number, date of last transaction, or account number already on file. Government-issued identity documents are not prohibited but should be reserved as a last resort, not a default requirement.
V. CCPA: Authorized Agents
A consumer may designate any natural person or California Secretary of State-registered business entity as an authorized agent. The business may require proof of authority: either written permission signed by the consumer or a power of attorney under California Probate Code Sections 4000–4465. Where a valid power of attorney is presented, additional verification from the consumer is not required. Authorized agents may not use consumer information for any purpose beyond fulfilling the request, completing verification, or preventing fraud. (11 CCR § 7063)
VI. CCPA: Response Timelines and Procedural Requirements
A business must respond within 45 calendar days of receiving a verifiable consumer request. The clock starts on the date the request is received, not when verification is completed. A single 45-day extension is available where genuinely necessary, provided the consumer is notified before the initial period expires.
2026 Update: Under amended CPPA regulations effective January 1, 2026, if a business retains personal information for longer than 12 months, it must provide a mechanism for consumers to request personal information going back to January 1, 2022, to the extent retained.
The CPPA regulations permit an optional two-step confirmation process for deletion requests. If used, both steps must be easy to complete and the two-step process does not extend the 45-day response clock.
VII. GDPR: The Proportionality Framework
The Legal Architecture
The GDPR does not prescribe a specific verification procedure. Article 12(6) permits controllers to request additional information where they have reasonable doubts about the requestor’s identity. Article 12(2) establishes the overriding obligation to facilitate the exercise of data subject rights. The EDPB’s Guidelines 01/2022 on the Right of Access and the January 2025 CEF Report confirm that the right of access exists without any general reservation to proportionality regarding the controller’s compliance efforts — proportionality limits the burden on the data subject, not on the controller.
Proportionality Is Context-Dependent
What constitutes proportionate verification depends on the nature and sensitivity of the personal data, the risk of unauthorized disclosure or modification, and the processing context. Controllers must make this assessment deliberately, document it, and be prepared to justify it to a supervisory authority.
VIII. GDPR: When Verification Is and Is Not Permitted
The “Reasonable Doubts” Trigger (Art. 12(6))
The right to request additional identity information arises only where the controller has reasonable doubts concerning the requestor’s identity based on objective, articulable grounds specific to the particular request — not as a general policy applied to all requests. The EDPB’s CEF 2024 Report found that routine supplemental verification applied as a default regardless of whether genuine doubt exists is inconsistent with Article 12.
The Benchmark Enforcement Case: Dutch AP Decision (2020)
The Dutch Autoriteit Persoonsgegevens imposed a €525,000 penalty on a controller that required a copy of a government-issued identity document for every access request as a matter of uniform policy. The AP found this violated the data minimization principle under Article 5(1)(c) and the obligation to facilitate data subject rights under Article 12. Requiring identity documents as a blanket requirement — without first assessing whether genuine doubt exists — is disproportionate and unlawful.
Proportionate Verification Measures
Proportionate measures include: confirmation of a unique identifier previously provided by the data subject; a one-time authentication code sent to an email or mobile number already on file; multi-factor authentication through existing account infrastructure; or confirmation of one or two pieces of information the controller already holds. Where identity documents are genuinely necessary, data subjects should be encouraged to redact fields not needed for the verification purpose, and documents must be handled securely and not retained beyond what is necessary.
When a Request Cannot Be Verified (Art. 12(6))
If identification is not possible, the controller must inform the data subject of what additional information would allow identification to be completed. Where the data subject fails to provide it, the controller may decline to process the request, but the data subject retains the right to resubmit with additional information.
IX. GDPR: Verification Standards by Request Type
Access Requests (Art. 15)
The primary risk is wrongful disclosure of personal data to a non-data-subject, which may itself constitute a personal data breach. Verification through information the controller already holds is appropriate. Routine requests for government-issued identity documents are not proportionate as a standard procedure.
Rectification Requests (Art. 16)
The verification standard is equivalent to or lower than for access requests. Verification (who is asking) and the substantive assessment (whether the requested change is accurate) are separate questions and should not be conflated.
Erasure Requests (Art. 17)
Because erasure is irreversible, a proportionate but robust verification process is warranted, calibrated to the sensitivity and finality of the action. The existence of a valid Art. 17(1) ground is a separately necessary condition: both questions — who is asking and whether grounds for erasure exist — must be assessed and documented.
Requests Involving Children’s Data
Where a request relates to a child’s personal data and is submitted by a parent or legal representative, the controller may require additional evidence establishing the representative relationship, proportionate to the nature and sensitivity of the data.
X. GDPR: Authorized Representatives and Third-Party Requests
The GDPR does not establish a uniform framework for requests submitted by authorized representatives; national law varies across EU Member States. Controllers are entitled to require evidence of the representative’s authority. The proportionality principle applies to verification of representative authority with the same force as to verification of the data subject’s identity.
XI. GDPR: Response Timelines and the Suspension Rule
Controllers must respond within one month of receiving the request. The one-month clock begins on the date the request is received. A two-month extension is available for complex or numerous requests, provided the data subject is notified within the initial one-month period.
Where the controller has reasonable doubts about the requestor’s identity and requests additional identifying information, the one-month response period may be suspended from the date additional information is requested until it is received. This suspension must be based on genuine, objectively grounded doubt, not manufactured to extend the response window. The basis for the doubt and the date of the request for additional information should be documented.
Where a request is manifestly unfounded or excessive — the burden of demonstrating which rests with the controller — the controller may charge a reasonable fee or refuse to act on the request. (Art. 12(5))
XII. Comparative Analysis: CCPA vs. GDPR
The CCPA establishes a structured, rule-based framework with specific data-point thresholds and tiered certainty standards. The GDPR establishes a principles-based proportionality framework requiring case-by-case judgment and documentation. Under the CCPA, the 45-day clock runs continuously through verification. Under the GDPR, the one-month clock may be suspended while additional identity information is sought. Both frameworks prohibit requiring government-issued identity documents as a standard default requirement and require that the process for exercising privacy rights not be deliberately obstructed.
XIII. Practical Compliance Considerations
Document Your Verification Method
A written verification policy should specify: which data points are used for each request type; which standard of certainty applies; how risk-calibration determinations for deletion requests are made; escalation processes for requests that cannot be straightforwardly verified; and how the business communicates with requestors when verification cannot be completed.
Avoid Systematic Use of Government-Issued Identity Documents
Identity documents should be reserved for the narrow subset of cases where other matching methods have failed, the request type warrants a high degree of certainty, and there is no less intrusive alternative. Where used, they must be handled securely and deleted promptly after the request is processed.
The Correction / Rectification Circularity Problem
Where the consumer seeks to correct the very information used for verification, identify alternative data points in advance. Document how this specific scenario will be handled. Under the CCPA, the regulations expressly direct using information that is not the subject of the correction request.
Train Staff and Build Institutional Procedures
The EDPB’s CEF 2024 Report identified inadequate staff training as a systemic challenge across controllers. Invest in staff training, documented escalation procedures, and periodic review of request-handling workflows.
Beware the Opt-Out/Verification Conflation
Under the CCPA, opt-out requests do not require a verifiable consumer request. Audit request intake workflows to ensure opt-out requests are routed through a pathway that does not trigger verification requirements.
XIV. Key Citations Quick Reference
This page is provided for general informational and educational purposes only and does not constitute legal advice. It does not create an attorney-client relationship. Organizations should consult with qualified privacy counsel to assess how these requirements apply to their specific operations.
