Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Consumer Privacy Rights

Verified Consumer Request

Also known as: VCR, Verifiable Consumer Request
Simply put

A verified (or verifiable) consumer request is a privacy rights request that a person submits to a business under California's privacy law, which the business must confirm actually comes from that person before acting on it. This typically covers requests to access, delete, or correct personal information. The idea is to make sure a business does not hand over or change someone's data based on a request from an impostor.

Formal definition

Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), a verifiable consumer request is a consumer rights request, generally a request to know (access), delete, or correct personal information, that the business has taken reasonable steps to confirm originates from the consumer who is entitled to make it, or that consumer's authorized agent. Verification obligations are intended to prevent unauthorized access to or manipulation of personal information, and the permitted scope of verification is generally limited to what is reasonably necessary to establish the requester's identity. Note that the statute itself does not exhaustively define what qualifies as adequately 'verified,' leaving businesses to apply reasonable verification methods consistent with applicable regulations and guidance; the details and interpretation of these standards may evolve. This concept is specific to California law and should not be assumed to apply identically under the EU or UK regimes, or under other US state privacy laws, which set their own verification and rights-request rules. Verification standards for other jurisdictions are out of scope for this entry.

Why it matters

Verification sits at the center of any workable consumer privacy rights program under California law. The CCPA, as amended by the CPRA, gives consumers rights to know, delete, and correct their personal information, but those same mechanisms create a risk: an impostor who submits a fraudulent request could gain unauthorized access to someone else's data or trigger the deletion or alteration of records that should have been preserved. Requiring a business to confirm that a request genuinely originates from the consumer (or their authorized agent) before acting is intended to guard against exactly this kind of abuse. Getting verification wrong in either direction carries consequences, over-verifying can obstruct a legitimate consumer from exercising a right, while under-verifying can expose personal information to the wrong party.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for operationalizing CCPA/CPRA rights need to design verification workflows that reliably confirm a requester's identity without collecting excessive information. Because the statute does not spell out exactly what counts as 'verified,' these teams must exercise reasoned judgment, document their methods, and revisit them as regulations and guidance evolve.
Legal counsel and compliance teams
Counsel advising businesses subject to California law must interpret the reasonable-steps standard for verifying requests to know, delete, and correct, and calibrate it to the sensitivity of the data involved. They should also flag that California's approach differs from other US state privacy laws and from the EU and UK regimes, so verification practices cannot simply be copied across jurisdictions.
Web developers and engineers building request-intake systems
Teams implementing request forms and identity-matching logic translate verification requirements into technical controls, confirming that submissions can be tied back to the correct consumer while avoiding the collection of more identifying data than is reasonably necessary.
Marketing and customer-data teams
Because access, deletion, and correction requests can affect the personal information used for marketing and analytics, these teams need to understand that no data should be handed over, deleted, or changed until a request has been properly verified, and that authorized agents may submit requests on a consumer's behalf.

Inside VCR

Consumer Rights Request
A request submitted by an individual seeking to exercise privacy rights granted under applicable law, such as the rights to access, delete, correct, or opt out of the sale or sharing of personal information. In the US, such requests are central to state privacy laws like the CCPA/CPRA in California, though the specific rights and terminology vary by state.
Identity Verification
The process by which a business confirms that the person making the request is the consumer whose data is at issue (or an authorized agent). Verification is intended to prevent unauthorized disclosure or deletion of personal information. The required degree of verification generally scales with the sensitivity of the data and the nature of the request.
Verification Standard
The level of certainty a business must reach before acting. Under frameworks such as the CCPA/CPRA, requests are often described using tiered standards (for example, a reasonable degree versus a reasonably high degree of certainty), with more sensitive actions typically calling for stronger assurance. Practitioners should consult the specific regulatory text and guidance applicable to their jurisdiction, as terminology and thresholds differ.
Authorized Agent
A person or entity a consumer may designate to submit a request on their behalf. Businesses may generally require proof of the agent's authority and, in some cases, verification of the underlying consumer's identity, subject to the requirements of the relevant law.
Response Obligations
Once a request is verified, businesses are typically required to respond within defined timeframes and to take the requested action or explain why they cannot. The applicable deadlines and permissible extensions depend on the specific statute and jurisdiction, so the governing law should be consulted rather than assumed.
Record-Keeping
Businesses commonly need to log requests received, verification steps taken, and how each request was handled. Such records support accountability and may be expected to demonstrate compliance, though the precise retention and documentation requirements vary by regime.

Common questions

Answers to the questions practitioners most commonly ask about VCR.

Is a verified consumer request the same thing as cookie consent?
No. A verified consumer request is a mechanism found primarily in US state privacy laws such as the CCPA and CPRA, through which a consumer exercises rights like access, deletion, or correction and the business confirms the requester's identity before responding. Cookie consent, by contrast, is the prior permission mechanism most closely associated with the EU ePrivacy rules and GDPR, governing the placing of and access to information on a device and the processing of any resulting personal data. The two operate under different legal regimes and serve different functions, so satisfying one does not satisfy the other.
Does receiving a verified consumer request mean I must delete every cookie or tracker associated with that person?
Not automatically. The scope of what a business must do in response depends on the specific right invoked and the applicable law. A deletion request under a US state law may reach personal data the business holds about the consumer, but the precise treatment of cookie-related identifiers, exemptions, and retained data varies and can depend on facts not covered by a general definition. Verification confirms who is making the request; it does not by itself dictate the substantive outcome, which turns on the applicable statute, the request type, and any recognized exceptions. Legal judgment is generally required to determine the correct response.
How can a business verify a consumer's identity when the request relates to cookie-based or pseudonymous data?
Verification methods generally vary with the sensitivity of the data and the nature of the request, and US state laws typically expect the level of certainty to be proportionate. Where a business interacts with a consumer only through pseudonymous identifiers such as cookie IDs rather than an account, matching a request to a specific individual can be difficult, and some frameworks contemplate that a business may not be able to verify in such cases. The appropriate approach depends on the applicable law and the data actually held, so businesses commonly document their verification standards and assess them against current regulatory guidance rather than relying on a single fixed method.
What records should we keep when handling a verified consumer request?
As a general practice, businesses often maintain records of the request received, the verification steps taken, the response provided, and the relevant timing, because several US state privacy regimes impose response deadlines and record-keeping expectations. Maintaining an auditable trail can support demonstrating that requests were handled consistently. The specific retention periods and documentation obligations differ by jurisdiction and may evolve, so the exact requirements should be confirmed against the applicable law rather than assumed to be uniform.
How do consent management platforms and privacy signals relate to handling verified consumer requests?
Consent management platforms and mechanisms such as the Global Privacy Control are typically oriented toward capturing preferences and opt-out signals, whereas a verified consumer request is a distinct rights-exercise process that often requires identity confirmation. Some tools offer workflows that intake, route, and log such requests, which can support operational handling. However, these tools support compliance rather than guarantee it; they do not replace the legal judgment needed to determine whether verification is sufficient and how to respond under the applicable regime.
Do the same verification requirements apply to consumers in the EU and the UK?
Not necessarily in the same form. The verified consumer request concept is most closely associated with US state privacy laws. The EU GDPR and the UK data protection regime provide their own data subject rights and require controllers to take reasonable steps to confirm the identity of a person making a request, but the terminology, standards, and procedures differ from the US framing. Because obligations vary between the EU, the UK, and individual US states, the geographic scope of any request should be identified and assessed against the law that actually applies.

Common misconceptions

A verified consumer request is the same concept as GDPR consent or a cookie consent record.
They address different things. A verified consumer request concerns an individual exercising data subject or consumer rights (such as access or deletion), which requires confirming who the requester is. Cookie consent, whether under the EU ePrivacy rules and GDPR or under US opt-out frameworks, concerns permission to place or read information on a device and to process the resulting data. Handling a rights request does not by itself establish or replace a valid consent basis, and consent records are not a substitute for a verification process.
Verification rules for consumer requests are the same everywhere.
Requirements differ by jurisdiction. US state privacy laws such as the CCPA/CPRA in California describe verification and often rely on an opt-out model, while the EU and UK GDPR frameworks address data subject requests under their own identity-confirmation expectations. Practitioners should not assume that one jurisdiction's verification standard, terminology, or timeframe applies universally.
A business can demand extensive additional personal data to verify any request.
Verification is generally expected to be proportionate, and collecting excessive information solely to verify a request can itself raise privacy concerns. The appropriate level of verification typically depends on the sensitivity of the data and the action requested, and the specific limits are set by the applicable law and regulatory guidance.

Best practices

Map which privacy laws apply to your organization and users, and document the verification standard, response deadlines, and rights each regime requires rather than applying a single jurisdiction's rules across the board.
Adopt a tiered, proportionate verification approach so that more sensitive requests (such as deletion or access to sensitive data) receive stronger identity assurance, while avoiding collection of more personal information than necessary to verify the requester.
Establish a clear process for authorized agent requests, including how you confirm the agent's authority and, where permitted, the underlying consumer's identity.
Maintain records of each request received, the verification steps taken, and how the request was resolved, to support accountability and demonstrate your handling of requests.
Keep consumer rights request handling distinct from cookie consent management, and confirm that verifying a request does not create any assumption about consent status for cookies or tracking technologies.
Consult current regulatory guidance and legal counsel when defining verification thresholds and timeframes, since enforcement positions evolve and tooling alone does not guarantee compliance.
Promotional banner for the Penetration Report Template Kit