Back to the hub

What is a verifiable consumer request under the CCPA?

Under Cal. Civ. Code Section 1798.140(ak), a verifiable consumer request is one made by the consumer, their minor child's parent, an authorized agent, or a conservator, which the business can verify by commercially reasonable methods to be the consumer whose data it holds. Without verification, disclosure, deletion, and correction duties do not apply.

Applies to: Businesses covered by the CCPA that receive requests to know, delete, correct, or opt out, and must decide whether a request is verifiable before acting on it.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Every CCPA right that touches a consumer's actual data runs through one gate: whether the request is verifiable. Get the definition wrong in either direction and you have a problem. Verify too loosely and you hand someone else's data to a stranger. Verify too strictly and you are denying rights the law grants.

Cal. Civ. Code Section 1798.140(ak) sets the definition, and it has two halves: who may make the request, and what you must be able to establish.

Who can make a verifiable consumer request?

The statute names four categories. A request may come from the consumer. It may come from a consumer on behalf of the consumer's minor child. It may come from a natural person, or a person registered with the Secretary of State, whom the consumer has authorized to act on their behalf. And it may come from someone who has power of attorney or is acting as a conservator for the consumer.

That third category is the one businesses forget. Authorized agents are part of the definition, not an optional courtesy, and privacy services that submit requests in bulk generally operate through it.

What does the business have to establish?

That the person making the request is the consumer about whom it has collected personal information, or someone authorized to act for that consumer. The standard is what the business can verify using commercially reasonable methods, pursuant to the regulations adopted under paragraph (6) of subdivision (a) of Section 1798.185.

Commercially reasonable is a proportionality test in practice. Confirming an email address may be enough to disclose the categories of data you hold. It is not enough to hand over the contents of a file that includes government identifiers.

What happens when verification fails?

Section 1798.140(ak) is explicit about the consequence. A business is not obligated to provide information to the consumer under Sections 1798.110 and 1798.115, to delete personal information under Section 1798.105, or to correct inaccurate personal information under Section 1798.106, if it cannot verify that the requester is the consumer or an authorized person.

That is a genuine limit, not a loophole. A verification process designed to fail is its own compliance risk, and the Delete Act shows the direction of travel: for data brokers, an unverifiable deletion request must instead be processed as an opt-out of sale or sharing rather than dropped.

Does verification pause the clock?

No, and this trips up teams that treat verification as step one and the response as step two. Section 1798.130(a)(2)(A) requires you to disclose and deliver the information, correct inaccurate personal information, or delete personal information within 45 days of receiving a verifiable consumer request. It then adds that the business shall promptly take steps to determine whether the request is a verifiable consumer request, but that this shall not extend the duty to respond within 45 days of receipt of the consumer's request.

The period may be extended once by an additional 45 days when reasonably necessary, provided you give the consumer notice of the extension within the first 45-day period.

Can you make people create an account to ask?

No. Section 1798.130(a)(2)(A) says a business may require authentication that is reasonable in light of the nature of the personal information requested, but shall not require the consumer to create an account in order to make a verifiable consumer request. If the consumer already has an account with you, you may require them to use it.

What period does the answer cover?

Section 1798.130(a)(2)(B) sets the default at the 12-month period preceding your receipt of the request. Following a regulation adopted under Section 1798.185(a)(8), a consumer may ask you to go back further, and you must comply unless doing so proves impossible or would involve a disproportionate effort. That extended right applies only to personal information collected on or after January 1, 2022, and nothing in the subparagraph requires you to keep data for any length of time.

How ComplyFine helps

Most CCPA request failures are operational rather than legal: no owner, no clock, no record of what verification was attempted. ComplyFine's free Obligation Scan tells you whether the CCPA applies to your business at all, then maps the request-handling duties you actually carry, including the 45-day response and the evidence to keep. If you would rather fix the process than read Section 1798.130 again, start there.

Compliance checklist

  • Accept requests from all four categories in Section 1798.140(ak): the consumer, a parent for a minor child, an authorized agent, and someone with power of attorney or acting as a conservator.
  • Verify using commercially reasonable methods proportionate to the sensitivity of the information requested, following the regulations adopted under Section 1798.185(a)(6).
  • Start the 45-day clock when the request arrives, not when verification completes, as Section 1798.130(a)(2)(A) requires.
  • Do not force a consumer to create an account to make a request, although you may require an existing account holder to submit through that account.
  • Log what you did to verify and why a request failed, so a denial can be explained later.
  • Remember the opt-out of sale or sharing under Section 1798.120 does not carry the same verification gate as access, deletion, and correction.

Sources

Last verified: 2026-08-23

Informational, not legal advice.