Handle an access request
Verify identity or representative authority
Verify the requester's identity, or a representative's authority to act for them, before releasing personal data.
What this task achieves
Before releasing personal data you must be satisfied you are dealing with the right person — or with someone genuinely authorised to act for them. This page covers deciding whether a check is needed at all, running the product's verification flow when it is, and handling requests made by a representative. The aim is confidence proportionate to the risk, reached as quickly as possible.
Before you begin
The Identity Verification panel is available to Admins, on a case at status New. Before opening it, complete the decision in the next section — verification in the product is a tool for when checks are genuinely needed, not a routine step.
Decide whether checks are needed
Often you already know who is asking. If the request came from the email address on the person's account, from a current employee's work address, or through an established customer relationship, that context may itself be enough to verify identity. In that situation, record on the case why identity is already established and move straight on to finding the data — do not ask for more evidence.
Ask for identity information only when you have real doubts about who is asking, and ask for the minimum that would resolve them. When a check is needed, request it as soon as possible.
UK GDPR context
Identity checks must be reasonable, proportionate, and necessary. Do not routinely demand identity documents, and do not ask for more information than you need to be confident — over-checking can itself unlawfully delay the response. Use the context you already hold, such as an authenticated account or an ongoing relationship, wherever it is sufficient.
This is operational guidance for UK organisations, not legal advice.
Choose a verification method
When a check is genuinely needed, the Identity Verification panel on the case offers a Verification Method:
- Email verification link — sends a one-time link to the data subject's email address. Choose this when confirming control of the known email address would resolve your doubt.
- Document upload request — asks the data subject to upload an identity document, such as a passport, driving licence, or national identity card. Choose this only when you cannot verify identity any other way. The requester can upload up to 3 files (JPEG, PNG, or PDF, 10 MB each) through a secure portal page.
Either way, the requester receives an email — "Identity verification required" with the case reference — containing a link that expires after 7 days.
Important
Never ask a requester to email identity documents or any other identity evidence, and never handle identity evidence outside the product's own verification flow. The upload link keeps documents out of inboxes and inside the case's audit trail.
Initiate verification
- Open the case and find the Identity Verification panel.
- Select the Verification Method that matches your decision above.
- Select Initiate Verification.
The case moves to Verifying Identity and the email is sent automatically. The panel then shows Awaiting Verification until the requester responds.
Approve or reject the evidence
When the requester has completed the link or uploaded documents, review the outcome in the Identity Verification panel:
- Approve Identity — records the identity as verified and moves the case to Discovering Data.
- Reject Identity — asks for a Rejection Reason, which is required and kept on the record. The requester automatically receives a resubmission email with a fresh 7-day link, so rejecting insufficient evidence does not strand the request.
Rejecting evidence is a judgement that what was supplied is not sufficient — it is not a refusal of the request itself. If evidence remains insufficient after resubmission, or you suspect the request is fraudulent, escalate to your data protection officer or legal adviser rather than releasing data or refusing outright.
Verify a representative's authority
Someone may validly make a request on another person's behalf — a solicitor acting on instructions, someone holding a written authorisation or power of attorney, or a parent or guardian for a child. DSAR Respond does not have a dedicated representative workflow, so record the representative's details and the evidence of their authority in the case's Request Description or notes, alongside the data subject's own details.
You need to be satisfied on two fronts: that the representative genuinely has authority to act, and — where appropriate — that the data subject themselves is who the representative says they are. The response goes to the person with authority to receive it, which is a decision to make deliberately, not by default.
UK GDPR context
It is your organisation's responsibility to satisfy itself that a representative is entitled to act for the data subject; a proportionate request for evidence of authority, such as a signed authorisation, is legitimate where genuine doubt exists. Where authority is unclear — especially for children, or for adults who may lack capacity — escalate to your data protection officer or legal adviser before releasing anything.
This is operational guidance for UK organisations, not legal advice.
Identity checks and the response period
Under current UK rules, when you reasonably ask for identity information or evidence of authority, the response period can start from the day you receive what you asked for, rather than the day the request arrived.
The product's due date does not move
DSAR Respond does not adjust the calculated due date when you initiate verification — the displayed date stays based on the recorded received date. When a reasonable identity or authority request changes the lawful start of the period, record the actual start event and your reasoning on the case, and confirm the statutory deadline yourself as part of assessing the request. Never rely on the displayed date after a verification exchange, in either direction.
Official sources
- ICO: Responding to a request, timing, identity, clarification, and extensions
- ICO: A guide to subject access
- UK GDPR, including Articles 12 and 15
- Data (Use and Access) Act 2025, section 76
What happens next
What happens next
Continue to Find data with Microsoft 365.
Last reviewed . UK regulatory context.