As a Data Protection Officer for a small bank in the European Union, you receive a data subject access request from one of your customers. The customer provides you with his
name, and has used the email address registered in your system.
What would be the most appropriate way to confirm the identity of the customer?
According to the CIPP/E study guide, data controllers should use the least intrusive means of verifying the identity of data subjects who make requests under the GDPR. Asking for a copy of an ID document or a bank account statement may be disproportionate and excessive, as they contain more personal data than necessary for authentication. Asking for the bank account number may not be sufficient, as it may be easily obtained by third parties. Therefore, the most appropriate way to confirm the identity of the customer is to ask additional security questions that only the customer would know, such as the date of the last transaction, the amount of the last deposit, or the name of the beneficiary of a recurring payment.
Golda
10 months agoGoldie
11 months agoReyes
10 months agoCaitlin
10 months agoNell
10 months agoArlette
11 months agoStefanie
9 months agoLaila
9 months agoXochitl
10 months agoMariann
10 months agoEdelmira
11 months agoCaitlin
11 months agoReid
11 months agoKenneth
11 months agoGianna
11 months agoMicah
11 months agoSabra
11 months agoAvery
11 months agoAvery
11 months agoMadelyn
11 months ago