Artifact GuideUSDSAR Verification

US CCPA DSAR Verification

DSAR verification under the US CCPA confirms the requester with a reasonable, documented method, uses only information needed for that purpose, and denies or escalates requests that cannot be verified.

Match verification to the request and risk; minimize new identity data, handle authorized agents and households explicitly, and do not verify sale-or-sharing opt-outs, limit requests, or automated decisionmaking technology (ADMT) opt-outs.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

US CCPA applies to requests to know, delete, correct, access automated decisionmaking technology (ADMT), and appeal an ADMT significant decision, but not to sale-or-sharing opt-outs, limit requests, or ADMT opt-outs. Use a documented, risk-based method, start with information the business already holds, collect no more identity data than necessary, and keep the 45-calendar-day response clock running from receipt.

Section 1

What should teams decide about DSAR verification under the US CCPA?

Start by deciding how the business will confirm that the requester is the consumer, or a person authorized to act for the consumer, using a reasonable, documented method. The workflow should explain what information may be requested, what sources can be matched, what happens if the business cannot verify the request, and which rights follow a different path.

For know, deletion, correction, ADMT-access, and ADMT-appeal requests, the business may ask for information needed to verify identity. New information collected for verification may be used only for verification, security, or fraud prevention and must be deleted as soon as practical after the request is processed, except for required request records.

  • Define the exact request type: know, delete, correct, or another verifiable consumer request.
  • Collect only the identity details needed to match the requester to records the business already holds.
  • Use a reasonable, documented method to verify the consumer or the consumer's authorized agent.
  • Deny or hold the request if the business cannot verify the requester or if the request is submitted to the wrong party, such as a service provider or contractor.
  • Record the reason for the verification outcome and keep verification data separate from unrelated records.
Section 2

Match verification strength to the request and risk

For a password-protected account, use the business's existing account authentication and require reauthentication before disclosure or deletion. For non-accountholders, requests for categories require a ; requests for specific pieces or ADMT access require a .

The regulations give possible methods, not mandatory universal data-point counts. Two reliable matches may support a . Three reliable matches plus a signed declaration under penalty of perjury may support a reasonably high degree, but the business must select a reasonable method from the facts and risk.

  • For deletion or correction, choose the certainty level from the sensitivity of the information and harm from unauthorized action.
  • Do not verify a correction request with the same disputed data element.
  • Use reasonable security measures against fraudulent verification and unauthorized access, deletion, or correction.
  • Delete newly collected verification information as soon as practical after processing, subject to required request records.
Section 3

Which edge cases should teams check before relying on a DSAR verification decision?

Check edge cases where the requester is an authorized agent, a parent or guardian, or a consumer who uses an account that the business cannot confidently match to the record set. Also check whether the request was sent to a service provider or contractor instead of the business itself.

The business should also consider whether the request is for a right that requires a verifiable consumer request and whether the consumer has already been identified through a reasonable authenticated channel.

  • Verify authorized-agent submissions using the proof the business is allowed to request.
  • Treat service-provider and contractor intake as a routing problem unless the business relationship allows action on the request.
  • Do not over-collect identity data when the business already has enough information to verify the request.
  • If the request cannot be verified, send a clear denial reason and explain what the consumer can do next.
Section 4

Decision outcomes, deadlines, and records

Capture the request type, receipt date, verification standard, method, minimum identity information, result, and denial or escalation reason. Confirmation is due within 10 business days and the substantive 45-calendar-day response period runs from receipt even while verification is pending. When necessary, the business may extend once for up to 45 additional calendar days if it gives notice and explains the reason within the first 45 days.

The outcome is a verified request, a limited follow-up for necessary information, a reasoned denial, or an escalation. If no reasonable method exists, explain why, disclose the absence of a method in the privacy policy when it applies to every consumer, and reassess at least every 12 months.

  • Map each request type to the required certainty level, method, owner, reviewer, and decision date.
  • Keep verification records distinct from substantive response records where possible.
  • Tell the requester when identity cannot be verified and give the next available step.
  • Review the method after fraud, unauthorized disclosure, product, account, or request-channel changes.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Section 1798.130 requires reasonable authentication and limits the use of verification data.
"The business may require authentication of the consumer that is reasonable in light of the nature of the personal information requested"
oag.ca.gov
Referenced sections
  • The FAQ says verification data may be used only for verification and that businesses may deny requests they cannot verify.
"If the business asks for personal information to verify your identity, it can only use that information for this verification purpose."
cppa.ca.gov
Referenced sections
  • Official historical rulemaking page for the regulations approved in March 2023; later amendments took effect January 1, 2026.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
cppa.ca.gov
Referenced sections
  • Section 7060 requires a documented, reasonable verification method for covered requests.
"A business shall establish, document, and comply with a reasonable method for verifying that the person making a request to delete, request to correct, request to know, or request to access ADMT is the consumer about whom the business has collected information."
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.