DSAR Identity Verification: How to Verify a Requester Without Breaching GDPR
Verifying a DSAR requester's identity protects against data breaches — but over-asking for ID is itself a compliance risk. Here's the proportionate approach, with regulator references.
Identity verification is where many Data Subject Access Requests go wrong in both directions. Verify too little, and you risk disclosing someone’s personal data to the wrong person — a data breach. Verify too much, and you create an unlawful barrier to a fundamental right. The GDPR asks you to find the proportionate middle.
What the law actually requires
There is no rule that says “always demand a passport.” Under Article 12(6) of the GDPR, where you have reasonable doubts about the identity of the person making the request, you may request the additional information necessary to confirm their identity — no more.
The UK ICO is explicit that this must be reasonable and proportionate: you should not ask for more information than you need, and you should not request formal identification documents if it isn’t necessary — particularly where you already have an ongoing relationship with the individual and their identity is obvious (ICO — right of access). The Irish DPC similarly states that a controller must adequately identify the requester using all reasonable measures (Irish DPC).
The proportionality test in practice
Ask yourself: do I have a genuine, reasonable doubt about who this person is?
- Existing customer logged into their account? Their identity is usually already established — asking for a passport is disproportionate.
- Request from a known work email of a current employee? Often verifiable from context.
- Request from an unknown address about a sensitive record? A proportionate identity check is justified.
Match the strength of the check to the sensitivity of the data and the level of doubt — not to a one-size-fits-all policy.
Verifying authority (when someone acts for another)
Where a request is made by a third party — a solicitor, a relative, or an agent — you also need to be satisfied they have authority to act. That usually means a letter of authority or power of attorney. Verifying authority is separate from verifying the requester’s own identity, and both may be needed.
How identity verification affects your deadline
You can ask for ID, but you can’t use it to stall. The ICO’s position is that where you have reasonable doubts, the response clock does not run until you receive the information you reasonably need — but you must request it promptly. Sitting on a request and asking for ID at the last minute is not acceptable. (See our guide on DSAR deadlines.)
Record how you verified — not just that you did
If a request is ever disputed, “we checked their identity” is weak. “We verified by email one-time passcode on this date, method recorded against the case” is strong. The method and timing of verification are part of your accountability evidence under Article 5(2).
How SAR Portal handles verification
SAR Portal is a controller-side DSAR platform that makes proportionate verification — and the evidence of it — straightforward:
- Multiple verification methods to match the level of doubt: email one-time passcode (OTP), portal token, manual review, ID document, or knowledge-based checks.
- The method is recorded on the case, along with when verification took place, so your audit trail shows exactly how you satisfied yourself of identity.
- Verification is captured as part of the timeline, so you can evidence when the response clock legitimately started or paused.
- Role-based access ensures only authorised staff handle verification and disclosure, and the immutable, append-only audit log (default seven-year retention) preserves the record.
This lets you take a proportionate approach — light-touch where identity is obvious, stronger where it isn’t — without losing the paper trail.
Frequently asked questions
Can I always ask for photo ID? No. You can only ask for the information necessary to confirm identity where you have reasonable doubts. Demanding photo ID by default is disproportionate and can itself be a compliance failure.
Does asking for ID pause the deadline? Where you have reasonable doubts, the clock doesn’t run until you receive what you reasonably need — provided you ask promptly and proportionately.
How do I verify someone acting on behalf of the data subject? Confirm their authority to act (e.g. a letter of authority or power of attorney), which is separate from confirming the data subject’s identity.
Related guides:
- How Long Do You Have to Respond to a DSAR? — Deadlines explained
- Received a GDPR Data Access Request? — What you must do in one month
- GDPR DSAR Response Checklist — Step-by-step checklist
Verify requesters proportionately — and prove it. SAR Portal records how and when you verified every requester. Start a free trial or see how it works.
Sources
- UK ICO — Right of access guidance
- Irish Data Protection Commission — The Right of Access
- EDPB — Guidelines 01/2022 on the right of access
Ready to simplify your DSAR process?
SAR Portal automates GDPR compliance with AI-powered redaction, deadline tracking, and audit trails.