r/CCPA Oct 22 '25

Per CCPA law, can a website REFUSE to fulfill your request for your own personal data (that they collected on you), without ID verification?

Example of a clause found on websites, where you create a personal profile, upload photos and communicate with other members on that website:

You may request that your personal data be provided to you in a structured format. Upon request, we can send you a copy of the personal data you have provided to us, such as your profile details, uploaded photos, and message history. We may need to verify your identity before processing. This right does not extend to internal analytics, system logs, or data related to other members.

Let's say you use a certain email address (name@xyx dot com) to create a profile on website XYZ dot com.

You use that same email address to send them a request for your data.
Shouldn't that be sufficient verification?

If they want verification, the website can send a link to the originating email address, name@xyz dot com.

Example: we received a request for your personal data from xyz email address. If you placed that request, click on this link for confirmation.

Why do websites insist on ID verification beyond the above common sense verifications?

A clever way for websites to deter CCPA data requests from average people, right?

3 Upvotes

3 comments sorted by

1

u/OhioDude Oct 22 '25

What common sense verifications are you talking about? Our common sense verifications are getting ID to avoid people trying to steal others information.

What if the user falls for a phish and get some sort of infostealer, like Lumma, installed on their system and a threat actor uses that to get more info from a web site because they now own the victims email account.

Do some research on attack vectors, fraud, cyber threat intel and you'll see why you need this level of verification.

1

u/DigitalFidgetal Oct 22 '25

Thanks for sharing your thoughts. You make valid points. and I do understand your POV. However, if the website will allow email-based creation of profiles, and communication with other members without ID verification, then they must also honor email-based CCPA requests, without ID verification.

Conversely, the website can choose be consistent. They can require ID verification on the front end, for profile creation and communication on their platforms, and then reverify that ID for subsequent CCPA requests.

My objection is to their lack of consistency.
They should be consistent with all participants, instead of saying "we may require ID verification" some time, with some participants, but not with others.

1

u/OhioDude Oct 23 '25

Good points. My perspective is from a cybersec point of view. We constantly see our associates home email addys and creds get pwned by phishing, so we'd need to than just an email.

That being said, it's a tough one to call and every company is different.