Authentication and Verification Records

Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II

1. Purpose

This document defines the identification and authentication processes used by DCKAP to verify the identity of data subjects submitting access requests or other privacy rights requests. It ensures that personal information is provided only to authorised individuals.

2. Identity Verification Framework

DCKAP applies a risk-proportionate approach to identity verification. The level of verification required is commensurate with the sensitivity and volume of personal data that would be disclosed.

3. Verification Methods by Request Channel

Request ChannelPrimary Verification MethodSecondary Verification (if needed)
Portal (logged in)Active authenticated session (SSO/MFA already completed)None required — session is sufficient
Portal (SAR form, not logged in)Email link to registered account email addressLast 4 of phone number on account OR account ID
Email to privacy@dckap.comReply from registered account email + confirm account detailsGovernment ID if email not on record
Written postal requestSigned letter + copy of government-issued photo IDSecond form of ID if address not on record
Via authorised representativeLetter of authority signed by data subject + their government IDNotarised if cross-border

4. Verification Record Template

FieldDescriptionExample
SAR Reference NumberUnique identifier assigned to requestSAR-2026-0042
Request DateDate request was received2026-06-27
Requestor NameName as provided by data subjectJane Smith
Verification Method UsedWhich verification method was appliedEmail verification + account ID
Verification DateDate identity was confirmed2026-06-29
Verified ByDCKAP staff member who confirmed identity[Staff Name]
Verification OutcomePass / Fail / PendingPass
NotesAny additional contextGovernment ID provided

5. Failed Verification Handling

  • If identity cannot be verified within 14 days of the initial request, DCKAP will inform the data subject of the specific information needed to complete verification.
  • If verification fails (e.g., details provided do not match records), DCKAP will decline the request and inform the data subject of their right to complain to the relevant supervisory authority.
  • All failed verifications are logged in the privacy request register.

6. Fraud Prevention

  • DCKAP staff are trained to identify social engineering attempts to obtain personal data by impersonating data subjects.
  • Unusual verification requests (multiple SARs for same account, overseas ID documents) are escalated to the Privacy Lead.
  • Verification records are retained for 2 years to provide evidence of due diligence.

7. Placement in Product

Product LocationScreen / PageAudience
Internal WikiLegal → Privacy Ops → Identity VerificationPrivacy Team, Support
Compliance FolderSOC 2 Evidence → SAR Verification RecordsExternal Auditors, CISO
Internal OnlyNot publicly disclosed — operational internal documentDCKAP Privacy Team