When a consumer submits a specific-information access request under the California Consumer Privacy Act (CCPA), you're required to verify their identity to a "reasonably high degree of certainty." The regulations outline a clear process: match three pieces of personal information and obtain a signed declaration under penalty of perjury. Yet, only 1% of companies disclose this declaration requirement in their privacy notices.
This gap creates risk. If your privacy notice promises one verification process but your DSAR team applies another, you're showing inconsistency to regulators. This template helps close that gap.
Purpose of the Template
This consumer identity verification declaration can be integrated into your DSAR workflow for handling specific-information access requests under CCPA. It complies with Cal. Code Regs. tit. 11, § 999.325(c) by obtaining a signed statement under penalty of perjury that the requestor is who they claim to be.
Use it when:
- The access request seeks specific pieces of personal information (not just categories).
- Your initial verification step (matching submitted data against your records) raises uncertainty.
- The request comes through an unverified channel (web form, email, phone).
- You need a defensible audit trail showing you applied a "reasonably high degree of certainty."
Don't use it as your only verification method. The regulation frames the declaration as part of a multi-factor approach, not a standalone gate.
Prerequisites
Before deploying this template, confirm three things:
Your privacy notice discloses the requirement. If you're going to ask consumers to sign under penalty of perjury, that expectation should be in your "How We Verify Your Identity" section. Springing it on requestors after they submit creates friction and signals that your public-facing documentation doesn't match your internal procedures.
Your DSAR team knows when to escalate. Not every request needs this level of scrutiny. Train your team to recognize high-risk patterns: requests from third-party agents without clear authorization, mismatches between submitted contact details and your records, or requests that arrive shortly after a credential-stuffing incident.
You've mapped your three verification points. The regulation's example uses three pieces of personal information. Decide in advance which three you'll request and which three you'll match against. Common pairs: email + phone + account number, or full name + address + last transaction date. Document your standard set so every analyst applies the same criteria.
The Template
CONSUMER IDENTITY VERIFICATION DECLARATION
California Consumer Privacy Act (CCPA)
I, [FULL LEGAL NAME], declare under penalty of perjury under the laws
of the State of California that:
1. I am the consumer whose personal information is the subject of the
access request submitted to [COMPANY NAME] on [DATE OF REQUEST].
2. The following personal information I have provided matches the
personal information maintained by [COMPANY NAME]:
• [VERIFICATION POINT 1]: ____________________
• [VERIFICATION POINT 2]: ____________________
• [VERIFICATION POINT 3]: ____________________
3. I understand that submitting false information in this declaration
may subject me to criminal penalties under California Penal Code
Section 118.
4. I am requesting access to the following categories of personal
information: [LIST CATEGORIES OR STATE "all categories collected"]
5. I understand that [COMPANY NAME] will use this declaration solely
to verify my identity in connection with my CCPA access request.
Signature: ________________________ Date: _______________
Printed Name: _____________________
Email Address: ____________________
Phone Number: _____________________
Customizing the Template
Verification points (Section 2). Replace the bracketed placeholders with the three data elements you've chosen. Be specific. "Account number" is better than "account information." "Billing ZIP code" is better than "address." The tighter your specification, the harder it is for a bad actor to guess.
If you operate multiple business lines with different data sets, create variants. Your retail division might verify with purchase history; your subscription service might use billing cycles and payment methods. One template won't fit every context.
Purpose limitation (Section 5). This statement tells the consumer you won't repurpose their signed declaration. If you plan to retain it as part of your DSAR audit log (you should), add: "We will retain this declaration as part of our compliance records for [RETENTION PERIOD]."
Delivery method. Decide whether you'll accept electronic signatures or require wet signatures. If you accept DocuSign or Adobe Sign, your template needs an addendum explaining that the electronic signature carries the same legal weight as a handwritten one. If you require a scanned PDF, state that in your initial response to the requestor.
Agent authorization. If you allow authorized agents to submit requests on behalf of consumers, add a section for agent details and proof of authorization. The declaration should come from the consumer, not the agent, unless the agent holds power of attorney.
Validation Steps
After you receive a completed declaration, validate it before you release data:
Cross-check the three verification points. Don't just confirm they're present. Match them against your source systems. If the consumer writes "123 Main St" but your CRM shows "123 Main Street, Apt 2B," that's a mismatch. Minor variations (abbreviations, formatting) are acceptable. Substantive differences are not.
Verify the signature is recent. If the declaration is dated more than 30 days before you receive it, request a new one. Stale declarations suggest the consumer copied a previous submission or the request sat in someone's inbox too long.
Document your decision. Whether you approve or deny the request, log which three points you matched, whether they aligned, and what you concluded. If you deny based on failed verification, your documentation needs to show you applied the same standard you'd apply to any similar request. Inconsistent application creates discrimination risk.
Update your privacy notice if you haven't already. If this is your first time requiring a declaration, you've just changed your verification practice. Your privacy notice should reflect that within the next review cycle. The 1% disclosure rate suggests most companies haven't closed this loop. Don't be part of that statistic.
The declaration itself is simple. The discipline is in applying it consistently, documenting your reasoning, and keeping your public commitments aligned with your internal controls. That's what "reasonably high degree of certainty" actually requires.





