Authentication Verification Records


FieldValue
Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II — Security, Availability, Confidentiality

1. Purpose and Scope

This document defines the identification and authentication processes used to verify the identity of data subjects making access requests, correction requests, or other Data Subject Requests (DSRs) to QA Touch. It ensures that personal information is released, corrected, or deleted only for the verified data subject and not disclosed to unauthorised parties. Supports SOC 2 Privacy criteria P6.1, P7.1, and P8.1.

2. Identity Verification Principles

  • No personal data is released, corrected, or deleted in response to a DSR without prior identity verification of the requestor.
  • Verification methods must be proportionate to the sensitivity of the data requested — higher-sensitivity data requires stronger verification.
  • QA Touch does not require more identification than is reasonably necessary to confirm identity.
  • All verification steps and outcomes are documented in the DSR tracking record.
  • Verification documents (where collected) are stored securely, used only for verification, and deleted within 30 days of request completion.

3. Verification Methods by Requestor Type

Requestor TypeStandard Verification MethodEnhanced Verification (high-sensitivity requests)Evidence Retained
Active registered user — own account dataRequest submitted from registered email; OR user authenticated in QA Touch when submitting form.One-time verification code (OTP) sent to registered email; requestor must confirm receipt within 24 hours.Verification method used; OTP confirmation timestamp; verification outcome logged in DSR record.
Former user — account closedEmail to last registered address on file; requestor must respond confirming identity details.If email inaccessible: requestor provides government-issued ID (redacted copy showing name and photo only); reviewed by Privacy Officer.Redacted ID copy stored securely; deleted within 30 days of request closure; verification outcome logged.
Individual in employer-managed workspace (B2B)Requestor provides: full name, work email, and name of the QA Touch customer workspace (employer organisation).QA Touch verifies provided details against workspace user records. If workspace data requested (vs. platform account data), may refer to employer as data controller.Verification method; matching user record confirmation; referral decision logged.
Authorised third party (parent, guardian, legal representative)Written, signed authorisation from the data subject (letter or scanned document) must be received and reviewed.Power of attorney or guardianship documentation accepted for individuals who cannot act independently; Legal Officer reviews.Authorisation document retained in DSR record for 3 years; data subject notified that third party acted on their behalf.
Deceased data subject (estate representative)Proof of relationship or legal authority (e.g., grant of probate, letters of administration) reviewed by Legal Officer.Applicable law determines what data may be provided posthumously; Legal Officer consulted on jurisdiction-specific rules.Supporting documents retained per legal hold requirements.

4. Verification Record Template

FieldExample ValueNotes
DSR IDDSR-2025-00142Unique identifier assigned on request receipt
Request TypeRight of Access (GDPR Art. 15)Access / Correction / Erasure / Portability / Objection
Requestor NameJane SmithAs provided; verified against platform record
Requestor Emailjane.smith@example.comEmail used for verification OTP or response
Requestor TypeActive registered userSelect from types in Section 3
Verification Method UsedOTP sent to registered email; confirmed at 14:32 UTC 2025-03-10Describe method and outcome
Verification OutcomeVERIFIEDVerified / Unable to Verify / Referred to Employer / Pending
Verification Date2025-03-10ISO 8601 date
Identity Documents CollectedNone (email OTP used)If documents collected: type, storage location, deletion date
Verified By[Privacy Officer Name]QA Touch employee who reviewed and confirmed verification
NotesRequestor confirmed OTP within 2 hours of issue; all details matched platform records.Any additional context

5. Failed Verification Handling

  • If the requestor cannot be verified within 14 calendar days: the request is placed on hold and the requestor is notified of the information needed to complete verification.
  • If verification cannot be completed within 30 calendar days of the original request: the request is closed; the requestor is informed of the reason and their right to complain to the supervisory authority.
  • Failed verification attempts are logged with detail; multiple failed attempts from the same requestor may indicate a fraudulent access attempt and are flagged to the Security team.
  • Identity documents collected during the process are securely deleted within 30 days of request closure regardless of outcome.

6. Record Retention

  • All verification records retained for 3 years after DSR completion as evidence of lawful processing.
  • Verification records are confidential; access restricted to the Privacy/Compliance team and Legal Officer.