Definition
Controllers must verify identity to avoid misusing rights. Identity checks must not over-ask or delay unnecessarily.
Best Practices
- Use proportionate verification for access requests.
- Keep identity evidence only as long as needed.
- Document your verification approach.
Was this useful?
Related Glossary Terms
Anonymized Data
Anonymized data is email subscriber or interaction data that has been stripped of personally identifiable information so individuals cannot be re-identified.
Consent Banner
A consent banner is an on-site notice that informs visitors about data collection and allows them to agree to or manage email marketing preferences.
Consent Expiry (Email Marketing)
Consent expiry is the time period after which a subscriber's permission to send marketing emails legally expires and must be re-obtained, varying by jurisdiction and consent type.
Cookieless Tracking in Email
Cookieless tracking in email is the measurement of email-driven behavior using methods that do not rely on third-party browser cookies.
Data Retention Schedule (Email Marketing)
A data retention schedule defines how long subscriber personal data is stored after unsubscribing or becoming inactive, ensuring compliance with GDPR, CCPA, and similar privacy laws.
Email Account Health Score
A composite metric that evaluates the overall health of an email sending programme based on deliverability, engagement, list quality, and compliance factors.
Frequently Asked Questions
To prevent unauthorised access or abuse of data rights.
Enough to be sure, without blocking legitimate requests.
Yes, proof of who you are before acting on data.