Guide · Data & Privacy

SAR identity checks

When an organisation may ask for ID and why the request should be reasonable and proportionate.

An organisation can verify identity, but it should ask only for what is reasonable and proportionate.

Identity checking protects against disclosing personal data to the wrong person. The controller can ask for information needed to be satisfied about identity, but the request should reflect the risk and information it already holds.

A company that has communicated with you securely for years may need less additional evidence than a controller receiving a request from a new email address for highly sensitive records.

Key points

  • ID is not automatically required for every SAR.
  • The controller should avoid collecting more identification data than necessary.
  • The time limit is affected where further ID is genuinely required under the current rules.
  • You can challenge disproportionate ID demands.

A risk-based check

The question is whether the controller can reasonably verify that the requester is the data subject or authorised representative. Account authentication, known email address, security questions or existing records may be enough in lower-risk situations. A passport may be justified in some contexts but excessive in others.

Protecting the ID you provide

Identification documents are themselves personal data. Ask why a full copy is needed, how it will be transmitted, what can be redacted and how long it will be retained. Do not send high-risk identity documents through an insecure channel merely because a frontline employee asked.

Representatives

Where someone acts for another person, the controller can verify both the identity of the data subject and the representative’s authority. A signed authority or other evidence may be needed.

In practice

  • Offer proportionate alternatives if the requested ID is excessive.
  • Use a secure channel and redact irrelevant fields where appropriate.
  • Keep the date the organisation first asked for ID to test whether the request was made promptly.

Evidence worth keeping

Original SAR
Identity-information request
Reason given for needing extra ID
What identity evidence was supplied and when
Any delay attributed to ID
Final response date

Push back constructively on excessive demands.

RequestPossible response
Full passport where you are logged into an authenticated accountAsk why existing authentication is insufficient and what additional risk the passport addresses.
Multiple documents with unrelated informationAsk which fields are necessary and whether redaction is acceptable.
ID request weeks after SARSupply proportionate evidence if needed, but record the delay and ask why verification was not sought promptly.

Useful wording.

“I am willing to provide proportionate evidence needed to verify identity. Please explain why [document/data] is necessary for this request, whether existing account authentication or a less intrusive document is sufficient, and provide a secure method for submission.”

Protect the new identity data you are being asked to send.

A SAR should not create a fresh security problem. Where a passport, driving licence or other sensitive proof is genuinely necessary, ask for a secure submission method and whether unnecessary fields can be obscured. The controller should collect only what it needs for verification and handle that material under the same data-protection principles.

The controller should ask for necessary ID promptly.

Current ICO SAR guidance treats the response period as starting once necessary identity information has been received. That makes delay in asking for ID important. A controller should not wait until the original deadline is nearly over and then use a predictable ID request to restart the timetable. Keep the date of the SAR, the date ID was requested and the date you supplied it.

ID checks must be necessary and proportionate to the risk.

A controller is entitled to be satisfied that it is disclosing personal data to the correct person, particularly where records are sensitive or the requester is not already authenticated. But it should not demand excessive identity material by default. Ask why the documents requested are necessary and whether less intrusive evidence or an existing authenticated account can establish identity.