§1798.135(c) Authorized Agent Requests
A consumer may use an authorized agent to submit requests on the consumer's behalf. A business may require the agent to provide written permission and may require the consumer to verify their identity directly or confirm
4
artefacts
1
held by a system
1
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Agent request log · SIEM / log platform
periodic reviewEvidence produced at each review
- Consumer direct verification records where required · Document repository
governing documentDocuments that govern the control
- Authorized agent verification procedure · Policy repository / GRC workspace
- Written permission and POA acceptance criteria · Policy repository / GRC workspace
First move
Start with the 1 of 4 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- No agent workflow
- Verification standards exceed regulation
- POA not recognized as substitute for direct verification
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet§1798.135(b) Opt-Out Preference Signals (Global Privacy Control) · §1798.150 Private Right of Action for Data Breaches