As a Data Protection Officer for a small bank in the European Union, you receive a data subject access request from one of your customers. The customer provides you with his
name, and has used the email address registered in your system.
What would be the most appropriate way to confirm the identity of the customer?
According to the CIPP/E study guide, data controllers should use the least intrusive means of verifying the identity of data subjects who make requests under the GDPR. Asking for a copy of an ID document or a bank account statement may be disproportionate and excessive, as they contain more personal data than necessary for authentication. Asking for the bank account number may not be sufficient, as it may be easily obtained by third parties. Therefore, the most appropriate way to confirm the identity of the customer is to ask additional security questions that only the customer would know, such as the date of the last transaction, the amount of the last deposit, or the name of the beneficiary of a recurring payment.
Nelida
3 months agoRodolfo
3 months agoRosendo
4 months agoKimberlie
4 months agoHelga
4 months agoPhil
4 months agoSheridan
5 months agoSanda
5 months agoDaryl
5 months agoJacki
5 months agoRebbecca
5 months agoDonette
5 months agoEmerson
5 months agoGolda
1 year agoGoldie
1 year agoReyes
1 year agoCaitlin
1 year agoNell
1 year agoArlette
1 year agoStefanie
1 year agoLaila
1 year agoXochitl
1 year agoMariann
1 year agoEdelmira
1 year agoCaitlin
1 year agoReid
1 year agoKenneth
1 year agoGianna
1 year agoMicah
1 year agoSabra
1 year agoAvery
1 year agoAvery
1 year agoMadelyn
1 year ago