CIPP-E · Question #246
As a Data Protection Officer for a small bank in the European Union, you receive a data subject access request from one of your customers. The customer provides you with his name, and has used the…
The correct answer is B. Request that the customer answer additional security questions. According to the CIPP/E study guide, data controllers should use the least intrusive means of verifying the identity of data subjects who make requests under the GDPR. Asking for a copy of an ID document or a bank account statement may be disproportionate and excessive, as they…
Question
As a Data Protection Officer for a small bank in the European Union, you receive a data subject access request from one of your customers. The customer provides you with his name, and has used the email address registered in your system. What would be the most appropriate way to confirm the identity of the customer?
Options
- ARequest that the customer provide his bank account number.
- BRequest that the customer answer additional security questions.
- CRequest a copy of the customer's last bank account statement.
- DRequest a copy of the customer's government-issued ID document.
How the community answered
(41 responses)- A15% (6)
- B71% (29)
- C5% (2)
- D10% (4)
Explanation
According to the CIPP/E study guide, data controllers should use the least intrusive means of verifying the identity of data subjects who make requests under the GDPR. Asking for a copy of an ID document or a bank account statement may be disproportionate and excessive, as they contain more personal data than necessary for authentication. Asking for the bank account number may not be sufficient, as it may be easily obtained by third parties. Therefore, the most appropriate way to confirm the identity of the customer is to ask additional security questions that only the customer would know, such as the date of the last transaction, the amount of the last deposit, or the name of the beneficiary of a recurring payment.
Topics
Community Discussion
No community discussion yet for this question.