🔥 3-day streak
ISACA CDPSE — Certified Data Privacy Solutions Engineer89 / 147
Question 89 of 147
A privacy engineer is reviewing a new mobile banking app that integrates with a third-party budgeting service via OAuth 2.0. Currently, the integration requests a broad scope granting full read access to all account transaction history and personal profile data, and the issued refresh tokens have no expiration. The budgeting feature only needs monthly spending categories. Which design change best applies privacy by design and data minimization to the authorization flow?
Reviewed for accuracy · Report an issueNext question