What should teams do about DSAR Verification under the US CCPA?
Start by classifying the right. For a password-protected account, the regulations generally allow verification through the business's existing authentication practices, but the business must reauthenticate the consumer before deleting or correcting data or disclosing the requested data. It must also use reasonable security safeguards.
For a non-accountholder, match data supplied by the consumer against reliable information the business already maintains. A request for categories of personal information requires a ; a request for specific pieces or access to ADMT requires a . A deletion or correction request uses the assurance level appropriate to the sensitivity of the information and risk of harm from unauthorized action.
- Classify the request before asking for identity information.
- Use existing account authentication or existing records when reasonably possible.
- Document the assurance level, matching points, reliability, sensitivity, fraud risk, and consequence of unauthorized action.
- If verification fails, explain the result and any available way to provide additional information without disclosing whether specific data exists.
- Treat an 's authority and the consumer's identity as separate checks where both apply.
Sections 7060-7063 set the verification rules for accounts, non-accountholders, deletion, and authorized agents.
Agency guidance on applying data minimization when selecting and operating verification methods.