As a Data Protection Officer for a small bank in the European Union, you receive a data subject access request from one of your customers. The customer provides you with his
name, and has used the email address registered in your system.
What would be the most appropriate way to confirm the identity of the customer?
According to the CIPP/E study guide, data controllers should use the least intrusive means of verifying the identity of data subjects who make requests under the GDPR. Asking for a copy of an ID document or a bank account statement may be disproportionate and excessive, as they contain more personal data than necessary for authentication. Asking for the bank account number may not be sufficient, as it may be easily obtained by third parties. Therefore, the most appropriate way to confirm the identity of the customer is to ask additional security questions that only the customer would know, such as the date of the last transaction, the amount of the last deposit, or the name of the beneficiary of a recurring payment.
Golda
1 months agoGoldie
1 months agoReyes
13 days agoCaitlin
15 days agoNell
22 days agoArlette
1 months agoStefanie
2 days agoLaila
3 days agoXochitl
24 days agoMariann
30 days agoEdelmira
1 months agoCaitlin
2 months agoReid
1 months agoKenneth
1 months agoGianna
1 months agoMicah
2 months agoSabra
2 months agoAvery
1 months agoAvery
1 months agoMadelyn
2 months ago