Authentication Verification Records
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II — Security, Availability, Confidentiality |
1. Purpose and Scope
This document defines the identification and authentication processes used to verify the identity of data subjects making access requests, correction requests, or other Data Subject Requests (DSRs) to QA Touch. It ensures that personal information is released, corrected, or deleted only for the verified data subject and not disclosed to unauthorised parties. Supports SOC 2 Privacy criteria P6.1, P7.1, and P8.1.
2. Identity Verification Principles
- No personal data is released, corrected, or deleted in response to a DSR without prior identity verification of the requestor.
- Verification methods must be proportionate to the sensitivity of the data requested — higher-sensitivity data requires stronger verification.
- QA Touch does not require more identification than is reasonably necessary to confirm identity.
- All verification steps and outcomes are documented in the DSR tracking record.
- Verification documents (where collected) are stored securely, used only for verification, and deleted within 30 days of request completion.
3. Verification Methods by Requestor Type
| Requestor Type | Standard Verification Method | Enhanced Verification (high-sensitivity requests) | Evidence Retained |
|---|---|---|---|
| Active registered user — own account data | Request submitted from registered email; OR user authenticated in QA Touch when submitting form. | One-time verification code (OTP) sent to registered email; requestor must confirm receipt within 24 hours. | Verification method used; OTP confirmation timestamp; verification outcome logged in DSR record. |
| Former user — account closed | Email to last registered address on file; requestor must respond confirming identity details. | If email inaccessible: requestor provides government-issued ID (redacted copy showing name and photo only); reviewed by Privacy Officer. | Redacted ID copy stored securely; deleted within 30 days of request closure; verification outcome logged. |
| Individual in employer-managed workspace (B2B) | Requestor provides: full name, work email, and name of the QA Touch customer workspace (employer organisation). | QA Touch verifies provided details against workspace user records. If workspace data requested (vs. platform account data), may refer to employer as data controller. | Verification method; matching user record confirmation; referral decision logged. |
| Authorised third party (parent, guardian, legal representative) | Written, signed authorisation from the data subject (letter or scanned document) must be received and reviewed. | Power of attorney or guardianship documentation accepted for individuals who cannot act independently; Legal Officer reviews. | Authorisation document retained in DSR record for 3 years; data subject notified that third party acted on their behalf. |
| Deceased data subject (estate representative) | Proof of relationship or legal authority (e.g., grant of probate, letters of administration) reviewed by Legal Officer. | Applicable law determines what data may be provided posthumously; Legal Officer consulted on jurisdiction-specific rules. | Supporting documents retained per legal hold requirements. |
4. Verification Record Template
| Field | Example Value | Notes |
|---|---|---|
| DSR ID | DSR-2025-00142 | Unique identifier assigned on request receipt |
| Request Type | Right of Access (GDPR Art. 15) | Access / Correction / Erasure / Portability / Objection |
| Requestor Name | Jane Smith | As provided; verified against platform record |
| Requestor Email | jane.smith@example.com | Email used for verification OTP or response |
| Requestor Type | Active registered user | Select from types in Section 3 |
| Verification Method Used | OTP sent to registered email; confirmed at 14:32 UTC 2025-03-10 | Describe method and outcome |
| Verification Outcome | VERIFIED | Verified / Unable to Verify / Referred to Employer / Pending |
| Verification Date | 2025-03-10 | ISO 8601 date |
| Identity Documents Collected | None (email OTP used) | If documents collected: type, storage location, deletion date |
| Verified By | [Privacy Officer Name] | QA Touch employee who reviewed and confirmed verification |
| Notes | Requestor confirmed OTP within 2 hours of issue; all details matched platform records. | Any additional context |
5. Failed Verification Handling
- If the requestor cannot be verified within 14 calendar days: the request is placed on hold and the requestor is notified of the information needed to complete verification.
- If verification cannot be completed within 30 calendar days of the original request: the request is closed; the requestor is informed of the reason and their right to complain to the supervisory authority.
- Failed verification attempts are logged with detail; multiple failed attempts from the same requestor may indicate a fraudulent access attempt and are flagged to the Security team.
- Identity documents collected during the process are securely deleted within 30 days of request closure regardless of outcome.
6. Record Retention
- All verification records retained for 3 years after DSR completion as evidence of lawful processing.
- Verification records are confidential; access restricted to the Privacy/Compliance team and Legal Officer.