🔥 3-day streak
ISACA CDPSE — Certified Data Privacy Solutions Engineer82 / 147
Question 82 of 147
A development team is building a new REST API that returns customer records to internal microservices. By default, the API response includes every field stored on the customer object, including national ID, date of birth, and full address, because the framework auto-serializes the entire entity. Most consuming services only need the customer's name and account status. As the privacy engineer embedded in the team, which approach BEST applies privacy by default to the API design?
Reviewed for accuracy · Report an issueNext question