Skip to main content
Category: Data Subject Rights

Verifiable Consumer Request

Also known as: VCR, Verified Consumer Request
Simply put

A verifiable consumer request is a formal request made under California's consumer privacy laws where a person asks a business to act on their privacy rights, such as accessing, deleting, or correcting their personal information. Before acting, the business must take reasonable steps to confirm the request actually comes from the person it claims to be, so that data is not released to the wrong party. This verification step exists because releasing a consumer's file to an impostor can enable fraud, stalking, or other harm.

Formal definition

Under the California Consumer Privacy Act (CCPA) and its amendments under the California Privacy Rights Act (CPRA), a verifiable consumer request (VCR) is a consumer rights request that a business has taken reasonable steps to confirm originates from the consumer (or their authorized agent) who is the subject of the personal information. In the evidence provided, VCRs include requests to delete, requests to correct, and requests to know, and verification is characterized as permitted only to the extent necessary to confirm the requester's identity in connection with exercising a right. Verification is a gating obligation on the business (the entity acting on the request) and is intended to prevent disclosure of a consumer's file to an unauthorized party. This entry is scoped to the California framing reflected in the evidence and does not address the specific verification procedures, timelines, exemptions, or authorized-agent mechanics that may be set out in regulation, nor does it describe how analogous request-verification obligations are treated under other regimes such as the EU or UK GDPR, where terminology, lawful bases, and identity-verification standards differ.

Why it matters

The verification step in a consumer rights request is where a privacy program's good intentions meet real risk. If a business acts on an access or deletion request without confirming who is actually making it, it can hand a consumer's personal information to an impostor. As the IAPP has noted, a consumer file released to the wrong party can be misused for tax, insurance, and other financial frauds, as well as spear phishing and stalking. In other words, the harm from mis-verification is not abstract regulatory exposure alone; it is direct harm to the individual whose data is disclosed.

This creates a genuine tension that compliance and privacy engineering teams must manage. The California framework grants consumers rights to know, delete, and correct their personal information, but it also requires the business to take reasonable steps to confirm the request originates from the consumer or their authorized agent before acting. Under-verifying risks wrongful disclosure; over-verifying can burden the consumer, and the evidence here characterizes verification as permitted only to the extent necessary to confirm identity in connection with exercising a right. Getting this balance right is a design and process problem, not merely a policy statement.

Because verification is a gating obligation on the business, accountability sits with the entity acting on the request. Demonstrating that reasonable verification steps were applied consistently, and evidencing that decision-making, matters more than simply asserting that a verification policy exists. This entry does not address the specific verification procedures, response timelines, exemptions, or authorized-agent mechanics that may be set out in regulation, nor does it quantify enforcement outcomes.

Who it's relevant to

Privacy program and DSAR/consumer request teams
Teams that operate consumer rights intake and fulfillment must build verification into the workflow for requests to know, delete, and correct. They are responsible for taking reasonable steps to confirm the requester's identity before acting, and for scoping that verification to what is necessary rather than collecting more information than the request requires.
Privacy engineers and product teams
Those designing request intake systems, such as verified consumer request forms and identity-confirmation flows, must balance preventing wrongful disclosure to an impostor against imposing undue friction on legitimate consumers. Design decisions here directly affect whether verification is both reasonable and proportionate to the right being exercised.
Compliance and legal counsel
Counsel advising businesses subject to the CCPA and CPRA need to ensure verification obligations are met and evidenced, since accountability for acting on a request sits with the business. They should also recognize that this California framing differs from request-verification treatment under other regimes, and that specific procedures, timelines, and authorized-agent mechanics may be governed by regulation not addressed here.
Security and fraud teams
Because a file released to the wrong party can enable fraud, spear phishing, or stalking, security and fraud functions have a stake in the verification standard applied to consumer requests. Their controls and threat expertise can inform what constitutes reasonable identity confirmation without conflating verification governance with broader authentication security.

Inside VCR

Requesting Individual
A verifiable consumer request originates from a consumer (or, where permitted, an authorized agent acting on the consumer's behalf) seeking to exercise rights such as access, deletion, or correction. The concept is primarily associated with the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA); treatment of consumer rights requests differs under other regimes such as the EU GDPR or UK GDPR, which use different terminology and procedures.
Identity Verification
The core function of the request is that the business can reasonably verify that the person making the request is the consumer about whom the personal information relates, or an authorized agent. The degree of verification generally scales with the sensitivity of the information and the risk of harm from unauthorized disclosure. This entry does not specify exact verification methods or thresholds, which depend on regulatory guidance and implementation context.
Scope of the Request
The request identifies which right the consumer is exercising and, where applicable, the categories or specific pieces of personal information involved. The obligation to respond and the manner of response fall on the business receiving the request.
Authorized Agent Handling
Where a request is submitted by an agent on the consumer's behalf, additional steps may be needed to confirm the agent's authority and the consumer's identity. Requirements for agent authorization are specific to the applicable regime and are not uniform across jurisdictions.
Business Response Obligation
The business (analogous but not identical to a data controller under GDPR terminology) bears the obligation to authenticate and respond to a verifiable consumer request within the timeframes set by the applicable law. This entry does not cover specific statutory response deadlines, retention rules, or enforcement penalties.

Common questions

Answers to the questions practitioners most commonly ask about VCR.

Is a verifiable consumer request the same as consent to process personal information?
No. A verifiable consumer request is a mechanism through which a consumer exercises a right (such as access, deletion, or correction) under statutes like the CCPA as amended by the CPRA, and it triggers a business's obligation to respond after verifying identity. Consent is a separate concept concerning the lawful grounds or permissions for processing. Conflating the two is a common error: honoring a verifiable request is about acting on an exercised right, not about obtaining or relying on consent. This entry does not address the specific verification standards or response timelines, which are set out in the applicable statute and regulations.
Does the concept of a verifiable consumer request apply uniformly across all privacy regimes?
Not in an interchangeable way. The term is most closely associated with the CCPA as amended by the CPRA in California. Other regimes address analogous data subject rights requests differently; the EU GDPR and UK GDPR, for example, frame these as data subject rights and use their own approaches to identity verification and handling. You should scope any obligation to the specific instrument that applies rather than assuming a single universal standard. This entry does not detail how each regime treats such requests.
How should a business verify the identity of a consumer making a request?
Verification generally involves matching the information provided in the request against information the business already holds, with the degree of scrutiny typically calibrated to the sensitivity of the data and the nature of the request. The specific methods, evidentiary thresholds, and any distinctions for requests made through an authorized agent are governed by the applicable statute and its implementing regulations, which this entry does not reproduce. Businesses should document their verification approach as part of demonstrable accountability rather than relying on stated intent alone.
Who within an organization is responsible for handling verifiable consumer requests?
Accountability typically rests with the business acting in a controller-equivalent role, though operational handling often involves privacy, legal, and security functions working together. Governance responsibilities such as maintaining the intake process, tracking requests, and evidencing responses fall to designated stewards or a privacy program owner, while identity verification may draw on security controls. This entry does not assign roles under any specific corporate structure and does not address the distinct obligations that may apply to service providers or processors receiving forwarded requests.
What records should a business keep to demonstrate it handled a request properly?
Under accountability principles common to governance frameworks, a business should generally retain demonstrable evidence of receipt, the verification steps taken, the decision reached, and the response provided, rather than merely asserting that requests are handled. Maintaining such records supports auditability. This entry does not specify retention periods, mandated record formats, or the precise documentation requirements of any particular statute; those depend on the applicable regime and should be confirmed against it.
Can a business deny or decline to fully act on a verifiable consumer request?
In many regimes, rights are not absolute and certain requests may be denied or partially fulfilled where an exception applies, where identity cannot be adequately verified, or where competing legal obligations exist. The specific grounds for denial, the notice a business must provide, and how partial responses should be documented are defined by the applicable statute and regulations, which this entry does not enumerate. Any denial should generally be documented with its stated basis to support accountability.

Common misconceptions

A verifiable consumer request is the same concept as a data subject access request under the GDPR.
The term is primarily associated with the CCPA/CPRA framework in California, while the EU GDPR and UK GDPR use their own terminology and procedures for data subject rights requests. The verification standards, scope of rights, and applicable obligations differ between these regimes and should not be treated as interchangeable.
Once a request is verified, the business must always fulfill it in full.
Verification confirms the requester's identity or authority, but the substantive obligation to act generally remains subject to exceptions, limitations, and applicable legal constraints. Verification and the decision to fulfill are separate considerations, and the extent of fulfillment depends on jurisdiction and context.
The consumer bears responsibility for proving their identity in a specific prescribed way.
The obligation to reasonably verify the request typically rests with the business receiving it, and the appropriate verification approach generally scales with the sensitivity of the information and the risk of unauthorized disclosure rather than following a single fixed method.

Best practices

Document and apply a risk-based verification approach that scales the level of identity confirmation to the sensitivity of the personal information involved and the potential harm from disclosure to an unauthorized party.
Establish distinct handling procedures for requests submitted directly by consumers versus those submitted through authorized agents, and confirm both the agent's authority and the underlying consumer's identity where an agent is involved.
Maintain demonstrable, evidence-based records of how each request was received, verified, and actioned, since accountability generally requires documentation rather than stated intent.
Separate the verification step from the fulfillment decision, so that confirming identity does not automatically bypass applicable exceptions or limitations on the underlying right.
Confirm which regulatory regime applies before processing a request, since terminology, verification expectations, and obligations differ across the CCPA/CPRA, EU GDPR, UK GDPR, and other frameworks.
Consult current regulatory guidance for specific response timeframes, permitted exceptions, and procedural requirements, as these are outside the scope of this concept and vary by jurisdiction.