Identity guide · 9 min read
DSAR identity verification without creating a new data risk
Verification should prevent an improper disclosure without turning every access request into a demand for more sensitive data. Start with the evidence and risk already available, document reasonable doubt and ask only for what is necessary.
When may you ask a DSAR requester for identity information?
Only where the controller has reasonable doubts about the requester’s identity. GDPR Article 12(6) then permits requesting the additional information necessary to confirm it. Start from evidence the organisation already holds, record the doubt, and ask for the minimum extra information the specific case requires.
The governing question
When may a controller ask for more identity information?
Article 12(6) GDPR says that where the controller has reasonable doubts concerning the identity of the person making a request under Articles 15 to 21, it may request additional information necessary to confirm identity. That is a conditional power, not a rule that every requester must send an identity document.
The European Commission’s guidance on individual requests confirms that an organisation can ask for additional information to confirm identity. The EDPB Guidelines 01/2022 on the right of access provide the detailed official framework.
Operational principle: first ask whether the organisation can reasonably authenticate the person through the existing account or relationship. Escalate only the unresolved doubt, and avoid collecting a richer identity document than the case needs.
Verification and identification are not the same task
Source discovery asks which records concern the person. Verification asks whether the requester is entitled to receive the response. A matching email can be useful for discovery without being sufficient for secure disclosure. Keep the two decisions separate in the case.
The risk runs in both directions
Weak verification can disclose personal data to the wrong person. Excessive verification can collect unnecessary identity data, create a new high-risk copy and obstruct the exercise of a right. The case owner should record the doubt, the disclosure risk and why the selected step addresses both.
A proportionate decision path
Move from known context to necessary evidence.
The right step depends on the account, request channel, sensitivity of the expected response, signs of compromise and reasonable doubts in the specific case.
What does the organisation already know?
Account state, authenticated session, established contact channel and prior verified interactions may reduce uncertainty.
Is there a reasonable identity doubt?
Record the concrete inconsistency or risk signal. Avoid generic labels such as “policy requires ID.”
What could the response expose?
The type, volume and sensitivity of the expected records affect the consequence of a mistaken disclosure.
What is the least intrusive effective step?
Prefer a trusted account route or existing channel before asking for new documentation.
How will verification data be protected?
Define the secure transfer, viewer permissions, decision record, retention and deletion path before collection.
Who approves the result?
An authorised person records whether doubt is resolved, more is necessary or the case needs legal escalation.
Match the method to the doubt
Verification options, from lower to higher friction.
Use an authenticated account workflow
Where the person has a functioning account and there are no compromise signals, an in-product request or challenge inside the authenticated session may use existing assurance without creating a new identity-document copy. The exact sufficiency still depends on the case and response risk.
Confirm through an established contact route
A message to an already verified email or phone number can confirm control of that channel. It does not resolve every identity question, especially where the account may be shared, compromised or changed.
Ask for targeted account knowledge
A limited, non-secret fact already held by the service may help resolve a mismatch. Do not ask for passwords, one-time codes intended for another flow, complete payment credentials or information the organisation cannot validate.
Request additional documentation only where necessary
If reasonable doubt remains and documentation is necessary, define what fields are required, how unnecessary fields can be obscured, who can view the document and when the copy will be deleted. Avoid retaining the image merely because it was received.
Do not send identity documents through an ordinary support thread by default. Select and document a secure route appropriate to the sensitivity and make the retention rule clear to the requester.
Evidence, not document hoarding
What the case should retain.
Retain enough to explain the decision under the organisation’s approved policy. Do not assume that means keeping every verification artefact.
Why and how
The reasonable doubt, risk considered, method selected, outcome, reviewer and timestamp.
What happened to the evidence
Fields requested, secure channel, viewers, storage location, approved retention and confirmed deletion where applicable.
What the person was told
The information needed, why it was necessary, how to provide it and what happens next.
Trace product boundary
Trace records identity state; a person owns the decision.
The proposed case workflow distinguishes not assessed, no additional step currently required, verification requested, verified for this response and escalated. Those labels should always carry the method, reviewer and rationale.
Trace does not claim biometric verification, automated identity judgement or autonomous approval. The accepted pilot must name the customer-side or qualified reviewer responsible for the decision and set the secure channel and retention procedure before live identity evidence is handled.
Official EU references
Sources used for legal statements.
- EUR-Lex — Regulation (EU) 2016/679, Article 12, including Article 12(6)
- European Data Protection Board — Guidelines 01/2022 on the right of access, final version
- European Commission — Dealing with individuals’ requests
Editorial method: legal statements are paraphrased from official EU materials. The workflow examples are Trace operational commentary and require adaptation to the controller’s facts, policies and applicable law.