- Section 1798.130 requires reasonable authentication and limits the use of verification data.
"The business may require authentication of the consumer that is reasonable in light of the nature of the personal information requested"
DSAR verification under the US CCPA confirms the requester with a reasonable, documented method, uses only information needed for that purpose, and denies or escalates requests that cannot be verified.
Match verification to the request and risk; minimize new identity data, handle authorized agents and households explicitly, and do not verify sale-or-sharing opt-outs, limit requests, or automated decisionmaking technology (ADMT) opt-outs.
Structured answer sets in this page tree.
Cited legal and guidance references.
US CCPA applies to requests to know, delete, correct, access automated decisionmaking technology (ADMT), and appeal an ADMT significant decision, but not to sale-or-sharing opt-outs, limit requests, or ADMT opt-outs. Use a documented, risk-based method, start with information the business already holds, collect no more identity data than necessary, and keep the 45-calendar-day response clock running from receipt.
Start by deciding how the business will confirm that the requester is the consumer, or a person authorized to act for the consumer, using a reasonable, documented method. The workflow should explain what information may be requested, what sources can be matched, what happens if the business cannot verify the request, and which rights follow a different path.
For know, deletion, correction, ADMT-access, and ADMT-appeal requests, the business may ask for information needed to verify identity. New information collected for verification may be used only for verification, security, or fraud prevention and must be deleted as soon as practical after the request is processed, except for required request records.
For a password-protected account, use the business's existing account authentication and require reauthentication before disclosure or deletion. For non-accountholders, requests for categories require a ; requests for specific pieces or ADMT access require a .
The regulations give possible methods, not mandatory universal data-point counts. Two reliable matches may support a . Three reliable matches plus a signed declaration under penalty of perjury may support a reasonably high degree, but the business must select a reasonable method from the facts and risk.
Check edge cases where the requester is an authorized agent, a parent or guardian, or a consumer who uses an account that the business cannot confidently match to the record set. Also check whether the request was sent to a service provider or contractor instead of the business itself.
The business should also consider whether the request is for a right that requires a verifiable consumer request and whether the consumer has already been identified through a reasonable authenticated channel.
Capture the request type, receipt date, verification standard, method, minimum identity information, result, and denial or escalation reason. Confirmation is due within 10 business days and the substantive 45-calendar-day response period runs from receipt even while verification is pending. When necessary, the business may extend once for up to 45 additional calendar days if it gives notice and explains the reason within the first 45 days.
The outcome is a verified request, a limited follow-up for necessary information, a reasoned denial, or an escalation. If no reasonable method exists, explain why, disclose the absence of a method in the privacy policy when it applies to every consumer, and reassess at least every 12 months.
Record the request type, certainty level, verification method, matched data, result, denial reason, authorized-agent proof, and deletion of added verification data.
Turn DSAR Verification into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"The business may require authentication of the consumer that is reasonable in light of the nature of the personal information requested"
"If the business asks for personal information to verify your identity, it can only use that information for this verification purpose."
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
"A business shall establish, document, and comply with a reasonable method for verifying that the person making a request to delete, request to correct, request to know, or request to access ADMT is the consumer about whom the business has collected information."