An organisation can verify identity, but it should ask only for what is reasonable and proportionate.
Identity checking protects against disclosing personal data to the wrong person. The controller can ask for information needed to be satisfied about identity, but the request should reflect the risk and information it already holds.
A company that has communicated with you securely for years may need less additional evidence than a controller receiving a request from a new email address for highly sensitive records.
Key points
- ID is not automatically required for every SAR.
- The controller should avoid collecting more identification data than necessary.
- The time limit is affected where further ID is genuinely required under the current rules.
- You can challenge disproportionate ID demands.
A risk-based check
The question is whether the controller can reasonably verify that the requester is the data subject or authorised representative. Account authentication, known email address, security questions or existing records may be enough in lower-risk situations. A passport may be justified in some contexts but excessive in others.
Protecting the ID you provide
Identification documents are themselves personal data. Ask why a full copy is needed, how it will be transmitted, what can be redacted and how long it will be retained. Do not send high-risk identity documents through an insecure channel merely because a frontline employee asked.
Representatives
Where someone acts for another person, the controller can verify both the identity of the data subject and the representative’s authority. A signed authority or other evidence may be needed.
In practice
- Offer proportionate alternatives if the requested ID is excessive.
- Use a secure channel and redact irrelevant fields where appropriate.
- Keep the date the organisation first asked for ID to test whether the request was made promptly.
What to do
A practical next-step plan
- Ask what identity concern needs to be resolved.
- Provide the minimum information reasonably needed.
- Use a secure upload or account channel.
- Record when ID was requested and supplied.
- Challenge repeated or escalating ID requests that appear unnecessary.
Common traps
Things that often confuse the issue
- Refusing all ID on principle can delay a legitimate request.
- Sending a complete identity document without checking necessity creates its own data risk.
- A controller should not wait until the deadline is almost over before asking for obvious ID it needed from day one.
Evidence worth keeping
Push back constructively on excessive demands.
| Request | Possible response |
|---|---|
| Full passport where you are logged into an authenticated account | Ask why existing authentication is insufficient and what additional risk the passport addresses. |
| Multiple documents with unrelated information | Ask which fields are necessary and whether redaction is acceptable. |
| ID request weeks after SAR | Supply proportionate evidence if needed, but record the delay and ask why verification was not sought promptly. |
Useful wording.
“I am willing to provide proportionate evidence needed to verify identity. Please explain why [document/data] is necessary for this request, whether existing account authentication or a less intrusive document is sufficient, and provide a secure method for submission.”
Protect the new identity data you are being asked to send.
A SAR should not create a fresh security problem. Where a passport, driving licence or other sensitive proof is genuinely necessary, ask for a secure submission method and whether unnecessary fields can be obscured. The controller should collect only what it needs for verification and handle that material under the same data-protection principles.
The controller should ask for necessary ID promptly.
Current ICO SAR guidance treats the response period as starting once necessary identity information has been received. That makes delay in asking for ID important. A controller should not wait until the original deadline is nearly over and then use a predictable ID request to restart the timetable. Keep the date of the SAR, the date ID was requested and the date you supplied it.
ID checks must be necessary and proportionate to the risk.
A controller is entitled to be satisfied that it is disclosing personal data to the correct person, particularly where records are sensitive or the requester is not already authenticated. But it should not demand excessive identity material by default. Ask why the documents requested are necessary and whether less intrusive evidence or an existing authenticated account can establish identity.
Official sources
Check the rules behind this guide
These are official or primary sources for this topic. Rules, scheme terms and deadlines can change, so check the live source before relying on a formal time limit or procedure.