CDPSE · Question #274
A data subject has requested the personal data an organization has collected on them. Which of the following should be done FIRST when responding to this request?
The correct answer is A. Verity the identity of the requestor. Identity verification must happen before any other step. Disclosing personal data to an unverified requestor risks exposing it to an impersonator, which would itself constitute a data breach and privacy violation. Only after confirming the requester is who they claim to be can…
Question
A data subject has requested the personal data an organization has collected on them. Which of the following should be done FIRST when responding to this request?
Options
- AVerity the identity of the requestor.
- BDetermine the legal validity of the request.
- CVerify which rights are involved in the request.
- DDetermine whether other parties' privacy may be impacted.
How the community answered
(20 responses)- A90% (18)
- B5% (1)
- C5% (1)
Explanation
Identity verification must happen before any other step. Disclosing personal data to an unverified requestor risks exposing it to an impersonator, which would itself constitute a data breach and privacy violation. Only after confirming the requester is who they claim to be can the organization safely proceed to assess the legal validity of the request, determine which rights apply, or evaluate third-party impacts. This sequencing is consistent with guidance from regulators such as the UK ICO and the EDPB, which require organizations to take reasonable steps to verify identity before fulfilling subject access requests.
Topics
Community Discussion
No community discussion yet for this question.