skip to content

Under the CCPA regulations, how should a business verify requests to know, delete and correct from account holders, non-account holders and authorized agents?

level: seniorimportance: should knowfreq 38%

answer

  1. match what you already hold
  2. rigour scales with sensitivity and harm
  3. re-authenticate before acting
  4. two points versus three plus declaration
  5. agent: signed permission, not a POA

basics

~20 s

Under the CCPA regulations, a business matches a requester against data it already holds, scaling rigour to sensitivity and risk: re-authentication for account holders, two or three matched data points for others, and signed permission for authorized agents (11 CCR 7060-7063).

solid answer

~50 s

Intake first: Civil Code 1798.130(a)(1) requires **two or more designated methods**, including a toll-free number (an exclusively online business with a direct relationship may offer just an email address), plus the website if there is one, and the business may not force account creation. Verification follows 11 CCR 7060: a documented, reasonable method that **matches information already held**, gets stricter as sensitivity, harm and fraud risk rise, and costs the consumer nothing. **Account holders** use existing authentication but must **re-authenticate** before data is disclosed, deleted or corrected (7061). **Non-account holders** need a *reasonable degree of certainty* (e.g. two matched data points) for categories, and a *reasonably high* one (three points plus a signed declaration under penalty of perjury) for specific pieces (7062). **Authorized agents** may be asked for signed permission, with the consumer verifying or confirming directly (7063). Verification data is used only for verification.

go deeper

for a junior

Recall that verification matches what the business already holds, and that a business offers two or more request methods, one a toll-free number unless it is exclusively online.

for a middle

Explain the reasonable versus reasonably high certainty standards, what re-authentication adds for account holders, and what may be asked of an authorized agent.

for a senior

Show how you would set verification per request type and data sensitivity, detect fraudulent requests, and purge verification artefacts after use.

for a principal

Balance fraud risk against access: a verification flow so strict that genuine consumers fail it is itself a compliance and trust problem.

## Intake: the designated methods Before anything can be verified it has to be received. Civil Code **1798.130(a)(1)** and 11 CCR **7020** set the intake rules for requests to know, delete and correct under the CCPA as amended by the CPRA: - **Two or more designated methods**, one of which must be a **toll-free telephone number**. A business that operates **exclusively online** and has a direct relationship with the consumer need only provide an **email address**. - If the business has a **website**, the website must be one of the methods, for example a web form (1798.130(a)(1)(B); 7020(b)). - The methods should reflect how the business primarily interacts with consumers; a business that deals with people in person should consider an in-person option (7020(c)). - The business **may not require the consumer to create an account** to make a request, though an existing account holder may be asked to use it (1798.130(a)(2)(A)). - A request sent the wrong way, or deficient for reasons unrelated to verification, must either be treated as if properly submitted or answered with instructions to fix it (7020(e)). ## The verification standard 11 CCR **7060(a)** requires a business to **establish, document and comply with a reasonable method** for verifying that the requester is the consumer the data is about. In choosing it, the business must match identifying information against what it **already maintains** whenever feasible, avoid collecting high-risk identifiers (the types in Civil Code 1798.81.5(d)) unless needed, and weigh the factors in 7060(c)(3): the sensitivity and value of the data, the harm an unauthorized deletion, correction or disclosure would cause, the likelihood of fraud, how robust the offered proof is, how the business interacts with the consumer, and the technology available. | Request | Non-account holder standard (7062) | Illustration | |---|---|---| | Know **categories** | reasonable degree of certainty | match at least two reliable data points | | Know **specific pieces** | reasonably high degree of certainty | match at least three pieces plus a signed declaration under penalty of perjury | | Delete or correct | reasonable or reasonably high, depending on sensitivity and harm | deleting browsing history vs deleting family photos | If the business cannot verify a request for specific pieces, it must deny that request (7062(f)). If no reasonable method exists at all for some data, it says so and explains why; if it has no reasonable method for any consumer, it explains that in its privacy policy and re-evaluates at least once every 12 months (7062(g)). ## Account holders For a **password-protected account**, the business may rely on its **existing authentication**, provided it follows 7060, and it must require the consumer to **re-authenticate** before deleting, correcting or disclosing data (7061(a)). If it suspects fraud on the account, it must not act until further verification confirms the requester (7061(b)). ## Authorized agents A consumer may act through an **authorized agent**. Under 7063(a) the business **may** require the agent to show the consumer's **signed permission**, and may also require the consumer to verify their own identity directly or confirm directly that they gave the permission. Those steps do not apply when the agent holds a **power of attorney** under Probate Code 4121-4130, and the business may **not demand** a power of attorney as the price of using an agent (7063(b)). The agent must secure the consumer's information and use it only to fulfil the request, verify, or prevent fraud. ## Handling the verification data itself 1. Ask for additional information only when existing data cannot verify the consumer, and use it only for verification, security or fraud prevention (7060(d)). 2. Delete newly collected verification data as soon as practical after processing, except what record-keeping requires (7060(d)); Civil Code 1798.130(a)(7) bars using it for unrelated purposes. 3. Charge **no fee** for verification; a notarized affidavit may be required only if the business pays for the notarization (7060(e)). 4. For a **correction**, verify with data other than the data being corrected (7060(h)). 5. Keep reasonable security measures that detect fraudulent verification attempts (7060(f)). ## Scope of the verification rule These standards cover requests to **know, delete and correct**. Requests to opt out of sale or sharing and requests to limit are handled differently: 7060(b) forbids requiring identity verification for them. Deidentified data need not be re-identified to verify a request (7060(g)). ## Design pitfalls - One verification level for everything: too weak for specific pieces, needlessly heavy for categories. - Emailing a full data export on the strength of an email match alone. - Requiring an account, a notarized form at the consumer's cost, or a power of attorney. - Keeping the photo ID uploaded for verification in the customer profile indefinitely.

  • Under the CCPA regulations, a consumer asks to correct their postal address. Can you verify them against the address on file?
    No. 11 CCR 7060(h) requires the business to make an effort to verify using personal information **other than the data being corrected**; the regulation's own example is an address dispute, where the address must not be the verification factor.
  • Under the CCPA regulations, may a business require a notarized affidavit to verify a requester?
    Only if it **compensates the consumer** for the notarization. 11 CCR 7060(e) forbids charging the consumer or an authorized agent any fee for verification, and gives the notarized affidavit as the example.
  • Under the CCPA regulations, what happens when the business cannot verify a request for specific pieces of personal information?
    It must **deny** that request (11 CCR 7062(f)). If it has no reasonable method to reach the required certainty, it says so in the response and explains why; if no consumer could be verified, the explanation belongs in the privacy policy (7062(g)).

saying these in an interview costs you the question

  • Requiring every requester to create an account is acceptable verification.
  • Opt-out of sale requests need the same verification as deletion.
  • Verification data can be merged into the marketing profile afterwards.
  • An authorized agent must always produce a power of attorney.
  • A matching email address is enough to release specific pieces.