---
title: How do I verify the identity of a data subject? - TrueVault
description: Recital 64 states that the data controller should verify the identity of a data subject using “all reasonable means”. A description of data subject identity verification is available in our FAQs about GDPR.
---

<https://safe.truevault.com/?hsLang=en>

- [CCPA](https://safe.truevault.com/learn/ccpa/what-is-the-ccpa)
- [GDPR Compliance](https://safe.truevault.com/gdpr-guide)
- [Personal Data](https://safe.truevault.com/learn/what-is-personal-data)
- [DSAR](https://safe.truevault.com/learn/explaining-gdpr-data-subject-requests)
- [HIPAA](https://safe.truevault.com/learn/hipaa)
- [HIPAA Compliance](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [Personally Identifiable Information](https://safe.truevault.com/blog/what-is-phi)
- [PHI](https://safe.truevault.com/protected-health-information)

- [Resources](https://safe.truevault.com/learn/) 
    - [Resource Center](https://safe.truevault.com/learn/)
    - [TrueVault Safe](https://safe.truevault.com/help/truevault-safe)
- [About](https://safe.truevault.com/about-us)
- [Contact](https://safe.truevault.com/contact-us)
- [Careers](https://careers.truevault.com/)

- Solutions 
    - [GDPR Compliance](https://safe.truevault.com/solutions/gdpr-compliance)
    - [HIPAA Compliance](https://safe.truevault.com/hipaa-compliance)
    - [For Applications](https://safe.truevault.com/solutions/application-compliance)
    - [For Data Exchanges](https://safe.truevault.com/solutions/data-exchange-compliance)
- [Developers](https://safe.truevault.com/resources/index)
- [Pricing](https://safe.truevault.com/safe-pricing)
- [Blog](https://safe.truevault.com/blog)
- [Login](https://console.truevault.com/login)
- [Get Started](https://safe.truevault.com/get-started)

# How do I verify the identity of a data subject?

[GDPR has certain rules about how DSARs](https://safe.truevault.com/learn/what-gdpr-says-about-data-subject-requests?hsLang=en) are to be fulfilled. [Recital 64](https://gdpr-info.eu/recitals/no-64/) states that the [data controller](https://safe.truevault.com/learn/what-is-the-difference-between-a-data-controller-and-a-data-processor?hsLang=en) should verify the identity of a data subject using “all reasonable means”. The standard for what is reasonable is not yet established in the law but organizations are encouraged to consider proportionality when verifying data subjects. In practice this means the criteria for verifying a data subject’s identity when an organization only collects demographic information should be different from an organization that collects credit card + demographic information.

Organizations need to also remember that the response window for a DSAR begins once an organization receives a request, not once an organization verifies someone’s identity.

Remember, if the data subject requests that the DSAR be executed orally, you must take additional steps to verify their identity.

## Real World Example

Susan calls your company to request access to her data subject profile. Susan has a visual impairment, and therefore requests that her DSAR be fulfilled orally via the telephone. Prior to fulfilling this DSAR, the company may request that Susan confirm additional identifying details beyond her name and birthdate (for instance). Once her identity is confirmed, and the DSAR executed, the DSAR manager may call Susan within 30 days to fulfill this request. 

[![Download the GDPR Guide](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4693513/6cb8f5e6-c632-48b6-a820-a0072af7a56b.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4693513/6cb8f5e6-c632-48b6-a820-a0072af7a56b)

### **Disclaimer**

### *This article is provided for general informational purposes only and is not intended to be legal advice.  By using the article, you agree that the information on this article does not constitute legal or other professional advice. The article is not a substitute for obtaining legal advice from a qualified attorney licensed in your state. The information on the article may be changed without notice and is not guaranteed to be complete, correct or up-to-date, and may not reflect the most current legal developments.*

### Latest Posts

## [Should Utah's Privacy Law Be on Your Radar?](https://safe.truevault.com/blog/utah-privacy-law-does-it-apply?hsLang=en)

 Phillip Walters  / November 17, 2022

## [Connecticut’s Privacy Law: Does It Apply to Your Business?](https://safe.truevault.com/blog/connecticut-privacy-law-does-it-apply?hsLang=en)

 Phillip Walters  / November 10, 2022

## [Global Privacy Control: A New Requirement for Compliance](https://safe.truevault.com/blog/global-privacy-control?hsLang=en)

 Phillip Walters  / November 7, 2022

### Blog Subscription

### Company

- [Blog](https://safe.truevault.com/blog)
- [Contact Us](https://safe.truevault.com/contact-us-2019)
- [Careers](https://truevault.workable.com)
- [HIPAA Compliance Checklist](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [PDF: Developers Guide to HIPAA compliance](https://my.leadpages.net/leadbox/14472b173f72a2%3A131fd12f8b46dc/5760820306771968/)

### Developers

- [Patterns](https://safe.truevault.com/patterns)
- [Documentation](https://docs.truevault.com/)
- [Quick Start Guide](https://safe.truevault.com/quick-start-guide)
- [Secure Infrastructure](https://safe.truevault.com/secure-infrastructure)
- [API Overview](https://safe.truevault.com/api-overview)

### Latest Posts

### Contact Us

201 Mission Street, 12th Floor  
 San Francisco, CA 94105  
 Email: [hello@truevault.com](mailto:hello@truevault.com)

2021 © All Rights Reserved. [Privacy Policy](https://privacy.truevault.com/privacy-policy) | [Terms of Service](https://safe.truevault.com/terms-of-service?hsLang=en)

- <https://www.facebook.com/truevault?fref=ts>
- <https://www.linkedin.com/company/truevault>
- <https://twitter.com/truevault>