Review before fulfillment

The team should decide whether identity evidence is sufficient before sensitive records are disclosed or changed. That decision should be visible to reviewers.

  • Track verification as a case status or checklist.
  • Ask only for information needed for the request.
  • Keep requester communications tied to the case.
A proportionate verification record
QuestionUseful recordRisk to avoid
What is being requested?Sensitivity and likely harm from misdeliveryUsing one fixed check for every request
What is already known?Authenticated session or matched account detailsAsking for identity data the business does not need
What remains uncertain?Focused follow-up and outcomeKeeping verification copies without a retention reason

Avoid oversharing

Verification workflows can accidentally collect too much personal data. Teams should prefer secure channels with access limited to the people who need it and minimize unnecessary document handling.

  • Use approved upload or response paths for sensitive materials.
  • Discourage passwords, full payment numbers, and unrelated documents.
  • Record the outcome without exposing more detail than needed.

Make edge cases reviewable

Representatives, mismatched emails, shared accounts, and unclear relationships need careful handling. The workflow should support escalation and notes.

  • Assign legal or compliance review when needed.
  • Record why additional verification was requested.
  • Keep final approval separate from evidence collection.

Example: a representative contacts the team

A person says they are acting for an account holder. Keep the claim, the requested action, and the evidence reviewed together. The person answering an email may not be the person whose records are involved.

  • Distinguish control of a contact address from authority to act for someone else.
  • Ask the responsible reviewer what evidence is appropriate before requesting documents.
  • Record the review outcome and any remaining limitations before fulfillment.

Write a verification note another responder can use

The note should explain the decision without copying unnecessary sensitive evidence into the timeline. Keep detailed materials in the approved restricted location.

  • State the method used and the relationship or account it helped establish.
  • Explain any mismatch and how the reviewer resolved it.
  • Record who reviewed the evidence and which action the outcome supports.

Sources

Sources checked September 20, 2026. These primary and regulator materials support the legal-rule summaries above; check the current rules that apply to your organization.

Common questions

Why is identity verification important for DSARs?

It helps prevent disclosing or changing personal data for someone who is not authorized to make the request.

Should verification be automated?

Automation can help assign work or send reminders, but the verification outcome should remain reviewable by the response team.

Where should verification notes live?

Verification notes should live with the case so response approval and later review have the right context.

Run privacy requests in one controlled workflow

Privacy Requests helps teams manage intake, verification, tasks, response preparation, secure delivery, and audit history without a broad enterprise suite.

Start free