As a Data Protection Officer for a small bank in the European Union, you receive a data subject access request from one of your customers. The customer provides you with his
name, and has used the email address registered in your system.
What would be the most appropriate way to confirm the identity of the customer?
According to the CIPP/E study guide, data controllers should use the least intrusive means of verifying the identity of data subjects who make requests under the GDPR. Asking for a copy of an ID document or a bank account statement may be disproportionate and excessive, as they contain more personal data than necessary for authentication. Asking for the bank account number may not be sufficient, as it may be easily obtained by third parties. Therefore, the most appropriate way to confirm the identity of the customer is to ask additional security questions that only the customer would know, such as the date of the last transaction, the amount of the last deposit, or the name of the beneficiary of a recurring payment.
Nelida
10 months agoRodolfo
10 months agoRosendo
10 months agoKimberlie
10 months agoHelga
11 months agoPhil
11 months agoSheridan
11 months agoSanda
11 months agoDaryl
11 months agoJacki
11 months agoRebbecca
11 months agoDonette
11 months agoEmerson
12 months agoGolda
2 years agoGoldie
2 years agoReyes
2 years agoCaitlin
2 years agoNell
2 years agoArlette
2 years agoStefanie
2 years agoLaila
2 years agoXochitl
2 years agoMariann
2 years agoEdelmira
2 years agoCaitlin
2 years agoReid
2 years agoKenneth
2 years agoGianna
2 years agoMicah
2 years agoSabra
2 years agoAvery
2 years agoAvery
2 years agoMadelyn
2 years ago