Verifying Identity Before Fulfilling a GDPR Request
The UK GDPR allows companies to request ID if they have reasonable doubts about the identity of the requester.
But be careful — asking for too much ID or failing to protect it can create its own risks.
Best practice:
- Only ask when necessary (e.g. requests from non-company emails)
- Set a clear retention policy for ID documents
- Avoid collecting more information than needed
💡 Tip:
Use secure portals or encrypted email to exchange ID documents. Never request personal data over open email.
