This document defines the identification and authentication processes used by DCKAP to verify the identity of data subjects submitting access requests or other privacy rights requests. It ensures that personal information is provided only to authorised individuals.
2. Identity Verification Framework
DCKAP applies a risk-proportionate approach to identity verification. The level of verification required is commensurate with the sensitivity and volume of personal data that would be disclosed.
3. Verification Methods by Request Channel
Request Channel
Primary Verification Method
Secondary Verification (if needed)
Portal (logged in)
Active authenticated session (SSO/MFA already completed)
None required — session is sufficient
Portal (SAR form, not logged in)
Email link to registered account email address
Last 4 of phone number on account OR account ID
Email to privacy@dckap.com
Reply from registered account email + confirm account details
Government ID if email not on record
Written postal request
Signed letter + copy of government-issued photo ID
Second form of ID if address not on record
Via authorised representative
Letter of authority signed by data subject + their government ID
Notarised if cross-border
4. Verification Record Template
Field
Description
Example
SAR Reference Number
Unique identifier assigned to request
SAR-2026-0042
Request Date
Date request was received
2026-06-27
Requestor Name
Name as provided by data subject
Jane Smith
Verification Method Used
Which verification method was applied
Email verification + account ID
Verification Date
Date identity was confirmed
2026-06-29
Verified By
DCKAP staff member who confirmed identity
[Staff Name]
Verification Outcome
Pass / Fail / Pending
Pass
Notes
Any additional context
Government ID provided
5. Failed Verification Handling
If identity cannot be verified within 14 days of the initial request, DCKAP will inform the data subject of the specific information needed to complete verification.
If verification fails (e.g., details provided do not match records), DCKAP will decline the request and inform the data subject of their right to complain to the relevant supervisory authority.
All failed verifications are logged in the privacy request register.
6. Fraud Prevention
DCKAP staff are trained to identify social engineering attempts to obtain personal data by impersonating data subjects.
Unusual verification requests (multiple SARs for same account, overseas ID documents) are escalated to the Privacy Lead.
Verification records are retained for 2 years to provide evidence of due diligence.
7. Placement in Product
Product Location
Screen / Page
Audience
Internal Wiki
Legal → Privacy Ops → Identity Verification
Privacy Team, Support
Compliance Folder
SOC 2 Evidence → SAR Verification Records
External Auditors, CISO
Internal Only
Not publicly disclosed — operational internal document