Authorized Agent
An authorized agent is a person or organization that a consumer designates to submit privacy rights requests on their behalf, such as requests to access, delete, or correct their personal information. This concept appears in certain US state privacy laws, notably California's CCPA. Using an authorized agent lets someone exercise their privacy rights without contacting a business directly themselves.
In the context of privacy rights, an authorized agent is a delegate a consumer legally empowers to submit and manage privacy rights requests (for example access, deletion, or correction requests) on the consumer's behalf. The role is recognized under US state privacy frameworks such as the California Consumer Privacy Act (CCPA); businesses receiving such requests may generally be permitted to require verification of the agent's authority and, depending on the request type and applicable rules, verification of the consumer's identity. The precise mechanics, permitted verification steps, and scope of what an agent may request vary by jurisdiction and statute, and this definition does not address the corresponding position under EU or UK data protection law, where representation of data subjects is treated differently.
Why it matters
The authorized agent mechanism matters because it lowers the practical barrier to exercising privacy rights. Not every consumer has the time, technical fluency, or confidence to navigate a business's request process directly. By allowing a person or organization to be designated to submit access, deletion, or correction requests on a consumer's behalf, frameworks such as California's CCPA make these rights more accessible, particularly to individuals who may rely on a service or intermediary to manage requests across many businesses at once.
For businesses, the concept introduces an operational and verification challenge. When a request arrives from a purported agent rather than the consumer directly, the business generally needs a way to confirm that the agent is genuinely authorized to act, and, depending on the request type and applicable rules, may also need to verify the underlying consumer's identity. Getting this balance wrong in either direction carries risk: over-demanding verification can frustrate legitimate rights requests, while under-verifying can expose personal information to someone acting without proper authority. The precise steps a business may require vary by jurisdiction and statute.
Because this role is recognized under US state privacy frameworks rather than uniformly across all regimes, teams operating internationally should not assume the same mechanics apply everywhere. Representation of data subjects under EU or UK data protection law is treated differently and is outside the scope of the authorized agent concept as described here.
Who it's relevant to
Inside Authorized Agent
Common questions
Answers to the questions practitioners most commonly ask about Authorized Agent.

