Website representations

Verify a privacy requester without collecting a new identity dossier

Start from the relationship you already hold: a request arriving through the account's signed-in area or from the contact already on file is one confidence input, though a shared or compromised channel can weaken it. The ICO's UK guidance says identity checks for access requests should be reasonable and proportionate, and formal identification is not automatically required. Name the specific doubt you actually have, then ask for the least additional evidence that settles it through an approved channel, recording the method and outcome with only the minimal evidence your authorized process justifies retaining. Keep documents and codes out of this worksheet and the public inquiry form, and leave any request you cannot verify with the merchant's designated privacy owner rather than bypassing the check or building a dossier by default.

For: An authorized staff member at a research-only merchant who must decide how much identity confidence is needed before disclosing a customer's records.

Updated 2026-10-01

Connect the request to a relationship you already hold

The arrival channel is the first confidence input, not a conclusion. A request submitted while signed in to the customer's account, or sent from the email address already associated with that account and matching its history, connects the requester to records the business already controls, but a shared mailbox, a compromised account or a forwarded address can weaken that connection. Record which existing contact point the request arrived through, whether it matches the relationship on file, and anything that limits the confidence it provides.

A request from an unknown channel carries no such connection. A new email address claiming to act for a long-standing customer, or a message that knows an order number but nothing else, is unverified rather than suspicious; knowledge of an order reference is not the same as control of the relationship. Label the channel confidence honestly before deciding what more to ask.

Ask for the least evidence that settles the actual doubt

The ICO's UK GDPR guidance on responding to access requests says identity checks should be reasonable and proportionate, and that formal identification is not automatically required. The guidance is specific to the UK regime, but its operational logic is general: the size of the check should follow the risk of wrong disclosure, not a fixed habit of demanding photo ID from everyone. Name the doubt you actually hold, then choose the smallest step that resolves it.

Proportionate steps draw on the existing relationship first: confirming through the address already on file, using the account's own recovery or confirmation flow, or asking the requester to respond through a channel the business already trusts. Where those steps cannot settle the doubt and the disclosure risk justifies more, a stronger check may be proportionate; it should run through the approved channel, with only the minimal evidence retained under the protected handling the business has authorized. What proportionality rules out is the default: demanding identity documents from every requester regardless of doubt. If your process currently does that, the default is the thing to review.

Record the method and outcome, not the documents

The verification record needs four things: the method used, who performed it, the date, and the result. If a check involved viewing a document or completing an account flow, record a pointer to where the authorized evidence lives and the fact of the outcome. Keep document images and confirmation codes out of this worksheet, shared inboxes and any public form; where the authorized process justifies retaining evidence, it stays in the protected case handling the business has approved, not copied into working notes.

Recording the method matters because a later reviewer must be able to distinguish 'verified through the on-file channel on this date' from 'assumed because the requester seemed plausible.' A disclosure made on an unrecorded assumption cannot be reconstructed, defended or corrected.

Handle doubt without bypassing or over-collecting

When the proportionate check fails or the requester cannot use the existing channels, the case goes to the merchant's designated privacy owner with the verification state clearly labeled: unverified, partially verified or verified with a stated limit. The owner decides the next step, which may be a lawful alternative the requester suggested, a narrower disclosure, or a refusal. Refusals and their required explanations are legal questions for qualified review in the applicable jurisdiction.

Never resolve doubt by skipping the check because the request seems friendly, and never resolve it by demanding a full identity file because the check feels uncomfortable. If repeated requests expose that your public-facing privacy page promises a verification or request process your team does not actually operate, a Prism website review can examine that public wording within an agreed scope; responsibilities, fees and terms are confirmed before work.

Proportionate verification decision sheet

Complete one sheet per request, recording methods, outcomes and internal pointers only. Never paste identity documents, confirmation codes, passwords or customer records into this sheet; unresolved verification stays with the designated privacy owner.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Proportionate verification decision sheet. The last column is for temporary notes.
Verification itemWhat it decides before disclosureYour finding
Arrival channelWhether the request came through the signed-in account, the on-file contact or an unknown channel, and what confidence that channel already provides.
Existing relationship matchWhether the requester's stated identity matches the account and order history the business already holds, recorded as a comparison result.
Named residual doubtThe specific uncertainty that remains after the channel and relationship checks; a check with no named doubt is habit, not verification.
Least-evidence step chosenThe smallest additional step that resolves the named doubt, such as the on-file address or the account's own confirmation flow, and why larger steps were not needed.
Method and outcome recordWho performed the check, the date, the result and a pointer to authorized evidence; the record contains no document copies.
Failure or limitation handlingThe verification state passed to the designated privacy owner if the check fails, and any narrower disclosure or alternative under consideration.
Disclosure gateConfirmation that no records leave the business until the owner accepts the verification state, and the date that acceptance was recorded.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • Verification rules and lawful alternatives depend on jurisdiction; this page cites UK ICO guidance for proportionality and refers refusal decisions and legal conclusions to qualified review.
  • This sheet does not prescribe a universal ID requirement, does not authorize skipping ownership checks, and does not establish what any requester is legally entitled to receive.
  • Keep identity documents, authentication codes, passwords and payment details out of this worksheet and the public inquiry form; where a proportionate check justifies retaining evidence, it belongs only in the authorized case handling your approved process defines.
  • Verification of identity and the scope of the eventual disclosure are separate decisions; passing this check does not determine what may be withheld.

Sources

  • ICO: Responding to a subject access request — checked 2026-10-01. Under the UK guidance, identity checks should be reasonable and proportionate and formal identification is not automatically required; the guidance is UK-specific and does not remove the need for verification.
  • Prism contact — checked 2026-09-21. The consultation form excludes payment card details, passwords and customer records, and a request leads to email follow-up rather than a booking or service purchase.

Request a website review

Want a second look at your own storefront pages?