QuestionQ43

Foundational Principles

Which of the following is not relevant when a user exercises their data-portability rights?

  • A Notice and consent for the downloading of data.
  • B Detection of phishing attacks against the portability interface.
  • C Re-authentication of an account, including two-factor authentication as appropriate.
  • D Validation of users with unauthenticated identifiers (e.g. IP address, physical address).
Explanation

Data-portability requests require reliable authentication and safeguards against unauthorized disclosure, such as re-authentication, appropriate multi-factor authentication, and protection against phishing. Unauthenticated identifiers such as an IP address or a physical address do not reliably validate the requester’s identity for releasing portable personal data.

Community Discussion

No comments yet. Be the first to start the discussion!