Last updated: 2 October 2026
Quick answer: DSAR identity verification means taking reasonable, proportionate steps to confirm a requester is who they claim to be before disclosing personal data. Under the GDPR and UK GDPR you may ask for additional information only where you have reasonable doubts, should use existing authentication first, and should not demand ID documents by default.
Every data subject access request (DSAR) carries two risks. Ask for too little proof and you may hand someone else’s personal data to an impostor, which is itself a personal data breach. Ask for too much and you create a barrier to a fundamental right, collect extra data you now have to protect, and risk missing the response deadline.
This guide explains what the law says about DSAR identity verification in the EU and UK, how EDPB and ICO guidance differ on timing, and how to build a risk-based verification procedure your team can apply consistently. If you need a refresher on the basics, start with our guide to what a DSAR is.
What does the law say about DSAR identity verification?
The GDPR allows, but does not require, extra identity checks. Where a controller has reasonable doubts about the identity of the person making a request, it may ask for additional information necessary to confirm it.
The key provisions of the GDPR, mirrored in the UK GDPR, are:
- Article 12(6): where the controller has reasonable doubts concerning the identity of the natural person making a request under Articles 15 to 21, it may request additional information necessary to confirm the identity of the data subject.
- Article 12(2): the controller must facilitate the exercise of data subject rights, and in cases covered by Article 11(2) must not refuse to act unless it demonstrates it is not in a position to identify the data subject.
- Article 12(3): information on action taken must be provided without undue delay and in any event within one month of receipt, extendable by two further months where necessary for complex or numerous requests.
- Recital 64: the controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular for online services and online identifiers, but should not retain personal data solely to be able to react to potential requests.
Two words do most of the work: “reasonable” and “necessary”. Verification is justified by genuine doubt and limited to what resolves that doubt.
When should you ask for proof of identity?
Ask only when you have a genuine reason to doubt the requester’s identity. If you already know who they are, further checks add delay without reducing risk.
The ICO’s right of access guidance gives practical examples. Asking a current employee who you know and work with for a utility bill would be unreasonable. Checking identity is justified where, for example, an online retailer receives a request from an address that does not match its records. Stricter checks are appropriate for highly sensitive information such as medical records.
Signals that justify extra checks
- The request comes from an email address, phone number or postal address you do not hold for that person.
- The requester asks for data to be sent to a new address or account.
- The data is sensitive, such as health, financial or special category data.
- The request is made by a third party, such as a solicitor, relative or claims firm.
- There are signs of fraud, such as account takeover attempts or urgency to bypass normal channels.
Common mistake: sending every requester a standard demand for a passport copy and two utility bills. This treats the lowest-risk requests like the highest-risk ones, collects far more data than needed and generates complaints.
What verification methods are proportionate?
Use the lightest method that removes your doubt, starting with authentication you already rely on. The EDPB Guidelines 01/2022 on the right of access say that using a copy of an identity document as part of authentication creates a risk for the security of personal data and should generally not be considered appropriate, unless it is strictly necessary and suitable.
| Risk level | Typical situation | Proportionate verification |
|---|---|---|
| Low | Request from a logged-in account or known email address; routine data | Existing login or reply from the email address already on file |
| Medium | Request from an unknown channel; ordinary personal data | Confirmation code to known contact details, or questions based on data you already hold (for example a recent order reference) |
| High | Sensitive data, new delivery address, or signs of fraud | Additional checks such as a video call or, where strictly necessary, sight of an ID document with non-essential details redacted |
| Third party | Solicitor, relative or other representative | Evidence of authority (signed authorisation or legal document) plus a proportionate check of the data subject’s identity |
In practice: where an ID document is justified, the EDPB suggests the controller can accept a copy with details such as the photo, nationality and serial number redacted, keeping only what is needed. Record that the check was done, then delete the copy rather than keeping it on the case file.
When does the response clock start? EU vs UK
This is where EU and UK practice diverge. In the UK the time limit starts once you receive the information needed to confirm identity; the EDPB treats receipt of the request as the trigger as a rule.
| Question | EU (GDPR, EDPB) | UK (UK GDPR, ICO) |
|---|---|---|
| When does the one-month period start? | Date of receipt of the request triggers the period “as a rule” (EDPB Guidelines 01/2022, para. 57) | From the latest of receipt of the request, receipt of information requested to confirm identity, or payment of any fee (UK GDPR Article 12A) |
| Can the clock be paused for clarification? | No general pause in the GDPR text; ask for clarification promptly | Yes, where clarification is reasonably required, under changes made by the Data (Use and Access) Act 2025 |
| Search standard | Guided by proportionality in EDPB guidance | Reasonable and proportionate searches, now written into law |
| Guidance | EDPB Guidelines 01/2022, version 2.1 (2023) | ICO right of access guidance, updated August 2026 |
The UK changes to subject access in the Data (Use and Access) Act 2025 came into force on 5 February 2026. The UK government’s DUAA factsheet describes them as clarifying the time limits and allowing organisations to pause the clock when they need the requester to clarify or provide more information. Since 19 June 2026, UK controllers must also have a process for handling data protection complaints, and a disputed identity check is a common trigger for one.
In practice: for organisations handling both EU and UK requests, the safe approach is to send any identity request on the day the DSAR arrives. That keeps you within the EU reading and avoids any argument about whether a delay was reasonable in the UK.
How should you handle requests from third parties?
Verify two things: that the third party is entitled to act, and that the person they act for is the data subject. The ICO guidance makes both checks the controller’s responsibility.
- Solicitors and representatives: ask for written authority signed by the data subject, or a legal document such as a power of attorney.
- Parents and guardians: consider whether the child is mature enough to exercise their own rights; if so, the child’s wishes matter.
- Request platforms and portals: the EDPB accepts requests made via third-party services, but you still need confidence that the platform is acting with the individual’s authority.
A step-by-step DSAR identity verification procedure
Write your procedure down so decisions are consistent and defensible. A simple version:
- Log the request on the day of receipt, including channel, requester details and any third party involved.
- Match the requester against records you already hold: account, email, phone or address.
- Assess risk using the table above: data sensitivity, channel, delivery details and fraud signals.
- Decide whether you have reasonable doubt. If not, proceed without extra checks and record why.
- Request only what is necessary, explaining what you need and why, on the same day where possible.
- Record the outcome of the check, not the documents themselves; delete copies once verified.
- Set the deadline according to the applicable regime (EU or UK) and track it.
- Deliver securely to the verified channel only, such as the existing account or a secure portal.
- Close or escalate: if identity cannot be confirmed, tell the requester and give reasons.
A data subject request management workflow can enforce these steps, record each decision and track deadlines per jurisdiction. Knowing where personal data sits also matters: an up-to-date record of processing activities makes searches faster and more complete.
To try this with your own request types, start your 14-day free trial of Enactia’s AI-powered GRC platform.
What happens if you disclose data to the wrong person?
Disclosing personal data to an impostor is a personal data breach. You would need to assess the risk to the individual and, where required, notify the supervisory authority within 72 hours under Article 33 and the individual under Article 34.
That is why verification should be one part of a wider control set, linked to your incident and data breach management process, a documented DSAR policy and regular staff training. Our article on common mistakes in GDPR compliance covers related process gaps.
Key takeaways
- Ask for extra identity information only where you have reasonable doubt, and only what resolves it.
- Start with existing authentication; ID document copies should generally be a last resort in the EU.
- In the UK the clock starts once identity information is received; in the EU, receipt of the request is the rule, so act fast.
- Verify both authority and identity for third-party requests.
- Record the check and delete the documents; a wrong disclosure is a personal data breach.
Frequently asked questions
Can we insist on a passport or driving licence for every DSAR?
No. Both the GDPR and UK GDPR limit additional requests to cases of reasonable doubt, and the EDPB says ID document copies should generally not be considered an appropriate authentication method. A blanket requirement is likely to be disproportionate, can deter requesters and creates extra data to secure. Use existing authentication first and reserve documents for genuinely high-risk cases.
Can we refuse a DSAR if the requester will not verify their identity?
If you have reasonable doubts and the requester does not provide the information needed to resolve them, you can decline to disclose until identity is confirmed. Explain what you need and why, keep a record of your reasoning, and inform the individual of their right to complain to the supervisory authority and to seek a judicial remedy.
Does asking for ID pause the one-month deadline?
In the UK, yes: the time limit runs from the latest of receiving the request, receiving information requested to confirm identity, or payment of any fee. In the EU, the EDPB treats receipt of the request as the trigger as a rule, so you should request identity information immediately to avoid losing time.
How long can we keep ID documents used for verification?
Only as long as necessary to complete the check. Once identity is confirmed, record that verification took place, the method used and the date, then delete the document. Keeping copies on the DSAR file creates security and data minimisation risks without adding evidential value beyond the verification record.
Do we need to verify employees who make a DSAR?
Usually not, where the request comes through a channel you already trust, such as a work email account, and you know the person. The ICO notes that asking a current employee you work with for documents such as a utility bill would be unreasonable. Former employees using a new email address may justify a light check.
Getting DSAR identity verification right
Good DSAR identity verification is proportionate, fast and documented. Match the check to the risk, use what you already know about the requester, request anything extra on day one, and delete verification documents once they have served their purpose. With a written procedure and a clear audit trail, you protect both the requester and your organisation.
If you would like help setting up a verified, deadline-tracked DSAR process across EU and UK requests, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
