When to use this template
Before responding to an access request, deletion request, or correction request, you must ensure that the request is genuinely from the right person. Otherwise you risk sharing data with someone who has no right to it.
Use this template as your first response when you cannot verify the requester’s identity based on the available information.
The template
Alternative verification methods
Not everyone wants to send an ID copy, and they don’t have to. Other options:
- Logged-in account - if the request comes via a logged-in customer portal, identity is already verified
- Verified email address - if the request comes from an email address already in your system
- Security questions - ask questions that only the data subject can answer
- Video call - for sensitive requests, a brief video call may help
The goal is reasonable certainty, not a perfect match. Choose the method appropriate to the risk.
Important
- Delete the ID copy immediately after verification - do not retain it
- Never ask for more information than necessary for verification
- Verification should not unreasonably delay the request; try to confirm within a week
GDPRWise automatically tracks which requests you have received, how you handled them, and whether you responded within the deadline.