Verifiable Consumer Request
A verifiable consumer request is a formal request made under California's consumer privacy laws where a person asks a business to act on their privacy rights, such as accessing, deleting, or correcting their personal information. Before acting, the business must take reasonable steps to confirm the request actually comes from the person it claims to be, so that data is not released to the wrong party. This verification step exists because releasing a consumer's file to an impostor can enable fraud, stalking, or other harm.
Under the California Consumer Privacy Act (CCPA) and its amendments under the California Privacy Rights Act (CPRA), a verifiable consumer request (VCR) is a consumer rights request that a business has taken reasonable steps to confirm originates from the consumer (or their authorized agent) who is the subject of the personal information. In the evidence provided, VCRs include requests to delete, requests to correct, and requests to know, and verification is characterized as permitted only to the extent necessary to confirm the requester's identity in connection with exercising a right. Verification is a gating obligation on the business (the entity acting on the request) and is intended to prevent disclosure of a consumer's file to an unauthorized party. This entry is scoped to the California framing reflected in the evidence and does not address the specific verification procedures, timelines, exemptions, or authorized-agent mechanics that may be set out in regulation, nor does it describe how analogous request-verification obligations are treated under other regimes such as the EU or UK GDPR, where terminology, lawful bases, and identity-verification standards differ.
Why it matters
The verification step in a consumer rights request is where a privacy program's good intentions meet real risk. If a business acts on an access or deletion request without confirming who is actually making it, it can hand a consumer's personal information to an impostor. As the IAPP has noted, a consumer file released to the wrong party can be misused for tax, insurance, and other financial frauds, as well as spear phishing and stalking. In other words, the harm from mis-verification is not abstract regulatory exposure alone; it is direct harm to the individual whose data is disclosed.
This creates a genuine tension that compliance and privacy engineering teams must manage. The California framework grants consumers rights to know, delete, and correct their personal information, but it also requires the business to take reasonable steps to confirm the request originates from the consumer or their authorized agent before acting. Under-verifying risks wrongful disclosure; over-verifying can burden the consumer, and the evidence here characterizes verification as permitted only to the extent necessary to confirm identity in connection with exercising a right. Getting this balance right is a design and process problem, not merely a policy statement.
Because verification is a gating obligation on the business, accountability sits with the entity acting on the request. Demonstrating that reasonable verification steps were applied consistently, and evidencing that decision-making, matters more than simply asserting that a verification policy exists. This entry does not address the specific verification procedures, response timelines, exemptions, or authorized-agent mechanics that may be set out in regulation, nor does it quantify enforcement outcomes.
Who it's relevant to
Inside VCR
Common questions
Answers to the questions practitioners most commonly ask about VCR.