🔥 3-day streak
ISACA CDPSE — Certified Data Privacy Solutions Engineer78 / 147
Question 78 of 147

During a privacy control assessment, a CDPSE reviews the organization's data subject access request (DSAR) handling process. The documented procedure requires identity verification, a 30-day response window, and manager sign-off before disclosure. The procedure is well-designed and approved, but the assessor finds that over the past six months, 40% of DSARs were fulfilled without any recorded identity verification step. What is the MOST accurate conclusion the assessor should report?

Reviewed for accuracy · Report an issueNext question