Skip to main content
The state of ai impact assessment
Category: Consumer Privacy Rights

Authorized Agent

Also known as: Authorised Agent
Simply put

An authorized agent is a person or organization that a consumer designates to submit privacy rights requests on their behalf, such as requests to access, delete, or correct their personal information. This concept appears in certain US state privacy laws, notably California's CCPA. Using an authorized agent lets someone exercise their privacy rights without contacting a business directly themselves.

Formal definition

In the context of privacy rights, an authorized agent is a delegate a consumer legally empowers to submit and manage privacy rights requests (for example access, deletion, or correction requests) on the consumer's behalf. The role is recognized under US state privacy frameworks such as the California Consumer Privacy Act (CCPA); businesses receiving such requests may generally be permitted to require verification of the agent's authority and, depending on the request type and applicable rules, verification of the consumer's identity. The precise mechanics, permitted verification steps, and scope of what an agent may request vary by jurisdiction and statute, and this definition does not address the corresponding position under EU or UK data protection law, where representation of data subjects is treated differently.

Why it matters

The authorized agent mechanism matters because it lowers the practical barrier to exercising privacy rights. Not every consumer has the time, technical fluency, or confidence to navigate a business's request process directly. By allowing a person or organization to be designated to submit access, deletion, or correction requests on a consumer's behalf, frameworks such as California's CCPA make these rights more accessible, particularly to individuals who may rely on a service or intermediary to manage requests across many businesses at once.

For businesses, the concept introduces an operational and verification challenge. When a request arrives from a purported agent rather than the consumer directly, the business generally needs a way to confirm that the agent is genuinely authorized to act, and, depending on the request type and applicable rules, may also need to verify the underlying consumer's identity. Getting this balance wrong in either direction carries risk: over-demanding verification can frustrate legitimate rights requests, while under-verifying can expose personal information to someone acting without proper authority. The precise steps a business may require vary by jurisdiction and statute.

Because this role is recognized under US state privacy frameworks rather than uniformly across all regimes, teams operating internationally should not assume the same mechanics apply everywhere. Representation of data subjects under EU or UK data protection law is treated differently and is outside the scope of the authorized agent concept as described here.

Who it's relevant to

Privacy and compliance teams
Teams responsible for handling consumer rights requests need processes to recognize requests submitted by authorized agents, verify the agent's authority, and, where applicable, verify the consumer's identity in line with the specific state privacy law that applies. They should build these workflows around the requirements of the relevant statute rather than a single assumed standard.
Legal counsel and data protection advisors
Counsel advising businesses subject to US state privacy laws such as the CCPA must interpret how agent-submitted requests should be handled, what verification the business may require, and how the permitted mechanics differ across jurisdictions. They should also flag that the authorized agent concept is distinct from how representation of data subjects is treated under EU or UK data protection law.
Consumers and their designated agents
Individuals who prefer not to contact a business directly can empower a person or organization to submit and manage access, deletion, or correction requests on their behalf where the applicable law recognizes this role. Both the consumer and the agent should expect that the business may request proof of the agent's authority, and possibly the consumer's identity, before acting.
Organizations offering agent services
Organizations that act as authorized agents for consumers should understand that businesses may generally require verification of their authority to act and, depending on the request and applicable rules, the consumer's identity. Because the permitted verification steps and scope of requests vary by jurisdiction and statute, agent services should tailor their processes accordingly.

Inside Authorized Agent

Authorized Agent (definition)
A third party that a consumer designates to submit privacy requests, such as opt-out or deletion requests, on the consumer's behalf. The concept features prominently in certain US state privacy laws, notably the California Consumer Privacy Act (CCPA) as amended by the CPRA, and its availability and precise requirements vary by jurisdiction.
Designation and authorization
The mechanism by which a consumer empowers the agent to act, which may involve a signed permission, a power of attorney, or another form of verifiable authorization. The specific proof a business may require depends on the applicable law and the type of request.
Scope of requests
Authorized agents are typically used for opt-out requests (for example, opting out of the sale or sharing of personal information) and may also submit other consumer rights requests where the relevant law permits. In cookie and tracking contexts, this can relate to opt-out of targeted advertising or the sharing of data collected via cookies, pixels, SDKs, or similar technologies.
Verification obligations
Businesses generally may take steps to verify both the identity of the consumer and the authority of the agent before honoring a request, subject to the limits and standards set by the applicable law. Overly burdensome verification can itself raise compliance concerns.
Relationship to opt-out signals
Some frameworks allow browser-based mechanisms, such as Global Privacy Control (GPC) signals, to communicate opt-out preferences. This can overlap conceptually with agent-submitted requests, though the two are distinct mechanisms with different technical and legal treatment.
Geographic and legal scope
The authorized agent concept is primarily associated with US state privacy laws that operate on an opt-out model. It does not map neatly onto the EU or UK regimes, where the ePrivacy rules govern the placing of and access to cookies and the GDPR governs subsequent processing on an opt-in basis for non-essential technologies.

Common questions

Answers to the questions practitioners most commonly ask about Authorized Agent.

Does an authorized agent mechanism apply to cookie consent everywhere, including the EU?
No. The authorized agent concept is primarily associated with certain US state privacy laws, such as California's CCPA/CPRA, which allow a consumer to designate another person or business to submit privacy requests (for example, opt-out or deletion requests) on their behalf. The EU and UK regimes governing cookies do not use this specific construct; instead, the ePrivacy rules and the GDPR generally rely on the individual giving or withdrawing consent directly, though the GDPR does recognize representation and third-party involvement in more limited ways. Because obligations vary between jurisdictions, you should confirm whether authorized agent rules apply to your particular users and how your relevant state or national framework defines them.
If a user's authorized agent submits an opt-out, does that automatically satisfy all my consent obligations?
Not necessarily. Acting on a valid authorized agent request typically addresses the specific right being exercised, such as an opt-out of sale or sharing under an applicable US state law, but it does not by itself resolve separate obligations you may have under other frameworks. For example, EU and UK rules generally require prior consent for non-essential cookies before they are placed, which is a distinct obligation from processing an opt-out. Honoring an agent request supports compliance with the request itself; whether your broader consent and cookie practices are compliant depends on the applicable legal regimes and the facts of your processing, and remains a matter for legal judgment.
How should we verify that an authorized agent is genuinely acting on the user's behalf?
Applicable US state laws generally permit businesses to take reasonable steps to verify both the identity of the consumer and the agent's authority to act, which may include requiring written permission from the consumer or verification directly with the consumer. The exact verification steps that are permitted or required depend on the specific request type and the governing law, and guidance can evolve. This definition does not prescribe a particular verification procedure; you should confirm the requirements under the relevant framework and document the steps you rely on.
How do agent-submitted requests interact with our consent management platform (CMP)?
A CMP typically captures and records consent choices and opt-out preferences made through the interface, but authorized agent requests may arrive through separate channels, such as a designated request intake process, rather than through the on-site banner. In practice, organizations often need a way to reconcile an agent-submitted preference with the state recorded in the CMP so that the user's choice is reflected consistently across cookies and tracking technologies. How this is implemented depends on your CMP's capabilities and your internal processes; a CMP supports this workflow but does not by itself guarantee compliance.
Can automated opt-out signals like Global Privacy Control substitute for an authorized agent request?
They are related but distinct mechanisms. Some US state frameworks treat a recognized opt-out preference signal, such as Global Privacy Control, as a valid way for a user to communicate certain choices, and in some cases such signals may be sent by a service acting for the user. An authorized agent request, by contrast, generally refers to a designated person or business submitting a request on the consumer's behalf, often with verification requirements. Whether and how each mechanism must be honored depends on the applicable law; you should not assume that one is interchangeable with the other without checking the governing framework.
What records should we keep when we act on an authorized agent request?
Consistent with general record-keeping and accountability expectations, it is common practice to retain evidence of the request, any verification performed, the date received, the action taken, and the response provided. Maintaining such records can help demonstrate that you handled the request appropriately if questioned by a regulator. The specific retention obligations and permissible verification records depend on the applicable state or national framework and may change as guidance develops, so the details here should be confirmed against the law that governs your processing.

Common misconceptions

An authorized agent is a concept that applies uniformly across all privacy regimes, including the EU and UK.
The authorized agent mechanism is most closely associated with certain US state privacy laws, such as California's CCPA/CPRA. EU and UK law address cookies and personal data through the ePrivacy rules and the GDPR, which rely on a different (generally opt-in) model for non-essential cookies and do not frame consumer rights around this same agent structure. Requirements and availability differ by jurisdiction.
A business must accept any agent request without verification.
Depending on the applicable law, a business may be permitted to verify the consumer's identity and confirm that the agent is genuinely authorized, for example through a signed permission or power of attorney, before acting. The exact standard varies, and verification must not be so burdensome that it defeats the consumer's rights.
Using an authorized agent or an opt-out signal automatically satisfies all cookie consent obligations.
Agent-submitted opt-out requests and signals such as GPC address rights under opt-out-based regimes; they do not replace the prior-consent requirements that generally apply to non-essential cookies and similar technologies in the EU and UK. Compliance still depends on the applicable legal regime and the specific facts.

Best practices

Confirm which jurisdictions' laws apply to your users, since the authorized agent concept and its requirements are tied to specific US state privacy laws and do not translate directly to EU or UK cookie consent obligations.
Establish a documented process for receiving agent-submitted requests and for verifying, within the limits the applicable law allows, both the consumer's identity and the agent's authorization.
Map agent requests to the correct request types, distinguishing opt-out of sale or sharing from other consumer rights, and account for tracking technologies beyond cookies, such as pixels, SDKs, and similar tools.
Coordinate agent-request handling with browser-based opt-out signals like Global Privacy Control where relevant, while treating them as distinct mechanisms rather than interchangeable ones.
Maintain records of agent requests and how they were handled to support accountability and record-keeping obligations, recognizing that tooling supports but does not replace legal judgment.
Consult qualified legal counsel on contested or unresolved questions, since verification standards and enforcement positions evolve and depend on facts outside the scope of a general definition.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.