Skip to content
Enforcement · Tietosuojavaltuutetun toimisto (Finland) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023

Summary

Facts — A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022. The data subject made an access request in November 2022 – they suspected the misuse of their personal data as they had not submitted the loan application themselves. The data subject provided their name, phone number, and email address as identifying information in connection with the access request. The controller did not provide the requested information; instead, it asked the data subject to disclose their residential address and personal identification number as well as to sign the access request electronically using strong authentication in order to verify their identity. The data subject refused to comply with this request and filed a complaint with the DPA, stating that the controller’s procedure for verifying the identity of the data subject in connection with an access request violated Articles 5(1)(c), 12(2) and (6), and 25(2) GDPR. The controller considered the additional information necessary to identify the correct individual and avoid providing the data subject’s information to an unauthorised third party. Holding — The DPA found no GDPR violation and held that the controller was entitled to request the data subject to provide additional information necessary to verify their identity pursuant to Article 12(6) GDPR. The controller’s procedure was also in line with the principle of data minimisation laid down in Article 5(1)(c) GDPR. According to the DPA, the personal data originally provided by the data subject when making the access request could not be considered sufficient identifying information since several people might have the same name and the email address and the phone number of the data subject could also be known to third parties. The DPA considered that the controller had a legitimate reason to request that the data subject provide additional information to verify their identity, as the controller processes personal data concerning the financial status of its customers.

How it connects

Full text

Data Protection Ombudsman July 22, 2026 Finlex Authorities Data Protection Ombudsman 2023 July 22, 2026 Data Protection Ombudsman Decisions by the Data Protection Ombudsman on the interpretation of the EU General Data Protection Regulation, the Act on the Protection of Personal Data in Criminal Matters, and the Personal Data Act Table of Contents Click to restore the table of contents Collapse all Expand all Decision of the Deputy Data Protection Ombudsman Case Data controller The data subject’s claims and supporting arguments Statement received from the data controller The data subject’s response Applicable legislation Legal issue Decision and reasoning of the Deputy Data Protection Ombudsman Decision Reasoning Appeal Notification Additional information Verification of the Data Subject’s Identity in Connection with the Exercise of the Right of Access Keywords Right of access to personal data, Verification of the data subject’s identity Year of the case 2023 Date Issued July 22, 2026 Case Number TSV/4630/2023 Legal Basis Decision pursuant to the EU General Data Protection Regulation Decision of the Deputy Data Protection Ombudsman Subject Additional information requested to verify the data subject’s identity and the right of access to data Data controller Loan and financial product comparison platform The data subject’s claims and their grounds On November 24, 2022, a case was initiated at the Office of the Data Protection Ombudsman concerning the data subject’s right of access to data. The data subject’s request is based on the fact that a loan application was submitted using the data subject’s information on the data controller’s service on October 12, 2022. The data subject suspects misuse of their data because they did not submit the application themselves. On November 24, 2022, the data subject submitted a request via email to the data controller to access their data. In connection with the request, the data subject provided their name, phone number, and email address as identifying information. According to the data subject, the data controller did not provide him with the information but instead requested additional information from him to verify his identity. In addition to the identifying information provided by the data subject on the data request form, the data controller requested the data subject’s home address and personal identification number. The data controller also asked the data subject to sign the request electronically using strong authentication. The data subject did not wish to provide the controller with the requested information because he suspects that his data may be misused and does not want to provide the controller with any additional information about himself. Statement Received from the Data Controller A statement was requested from the data controller regarding this matter. The data controller submitted a written statement on May 11, 2023, and September 20, 2023. The data controller states that it has not yet been able to respond to the data subject’s request to access the data, as the identity of the person making the request could not be verified. According to the data controller, the identity of the person making the request is verified using a form that requires an electronic signature and strong electronic authentication. The data controller does not consider this authentication request to be an unreasonable requirement, given that, in the present case, the data subject has suspected that their data has fallen into the wrong hands. The data controller sent the form to the data subject twice, on November 28, 2022, and November 22, 2022. The data controller has not received the completed form back from the data subject, nor has it received any other response to the request to complete the form. The data controller notes that it operates in the financial sector and that customer data may be subject to a statutory duty of confidentiality. The data controller therefore states that it takes particularly seriously the obligation under the General Data Protectionto identify data subjects and verify their identity before granting access to their data. According to the data controller, it has established a process to reliably verify the identity of individuals requesting information and thereby prevent situations in which data could be unlawfully disclosed to third parties. The data controller considers that the data subject’s name alone is not sufficient to identify the correct person, as there are many people with the same name. Furthermore, individuals’ address information is not always up to date. For this reason, the data controller also needs the personal identification number to identify the customer. If the customer has not been correctly identified, the data controller states that there is a risk of providing the wrong person’s information to the requester, which constitutes a personal data breach. In addition to the identification information on the form, the data controller requires the form to be signed electronically after authenticating the user’s identity, since other individuals may also have access to the same identification information. Based on the electronic signature, the data controller can see the person’s name and confirmation of strong authentication. According to the data controller, this allows it to reliably verify the requester’s identity. The information on the form, on the other hand, is still necessary, according to the data controller, to distinguish the individual from others. Taking into account the data processed by the data controller and its sensitive nature, the data controller considers that strong electronic authentication is necessary to verify identity and to prevent potential risks to the data subject and, ultimately, data breaches. According to the data controller, it is prepared to provide the data subject with the information requested after verifying their identity. Response from the Data Subject The data subject was asked to submit a response regarding the matter. The data subject submitted a response on May 17, 2023, and September 21, 2023. The data subject stated that they had provided the data controller with the following identifying information to facilitate the request: name, phone number, and email address. The data subject believes that, under the law, they have the right to access the data based on the identifying information they provided. The data controller should process the request submitted by the data subject via email. The data subject does not wish to fill out a form that would disclose their personal identification number and address to the data controller. Applicable Legislation The General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation) applies in this matter. As a regulation, it is directly applicable law in the Member States. The General Data Protection Regulation is supplemented by the National Data Protection Act (1050/2018). Pursuant to Article 12(6) of the General Data Protection Regulation, if the controller has reasonable grounds to doubt the identity of the natural person who has made a request under Articles 15–21, the controller may request additional information necessary to verify the identity of the data subject, without prejudice to the application of Article 11. According to paragraph 2 of this Article, the controller shall facilitate the exercise of the data subject’s rights under Articles 15–22. In the cases referred to in Article 11(2) of the General Data Protection Regulation, the controller may not refuse to act on a data subject’s request to exercise their rights under Articles 15–22, unless the controller demonstrates that it is unable to identify the data subject. Pursuant to Article 11(2) of the General Data Protection Regulation, the data subject may, in such situations, provide additional information to enable identification. Pursuant to Article 5(1)(c) of the General Data Protection Regulation, personal data must be appropriate, relevant, and limited to is necessary in relation to the purposes for which they are processed (“data minimization”). According to Article 25(2) of the General Data Protection Regulation, the controller must implement appropriate technical and organizational measures to ensure that, by default, only personal data necessary for each specific purpose is processed. This obligation applies to the amounts of personal data collected, the scope of processing, the retention period, and accessibility. These measures must ensure, in particular, that personal data is not, by default, made available to an unlimited number of people without the consent of the natural person concerned. Article 58(2) of the General Data Protection Regulation sets forth the corrective powers of the Data Protection Commissioner. Legal Issue The issue to be decided in this case is whether the controller’s procedure for verifying the data subject’s identity in connection with a request for access to data was in violation ofRegulation. If the controller’s conduct has been in violation of the provisions of the General Data Protection Regulation, the matter must be decided as to whether a sanction under Article 58(2) of the General Data Protection Regulation should be imposed on the data controller. Decision and Rationale of the Deputy Data Protection Ombudsman Decision The data controller’s procedure for verifying the identity of the data subject in connection with a request for access to data has not been in violation ofRegulation. Reasons The General Data Protection Regulation does not contain provisions on how the identity of a data subject must be verified in connection with the exercise of the data subject’s rights. However, the data controller has an obligation to verify the identity of the person making the request in order to ensure the proper protection of personal data and to minimize the risks of personal data being disclosed to third parties. Pursuant to Article 12(6) of the General Data Protection Regulation, if the controller has reasonable grounds to doubt the identity of the natural person making the request, the controller may request that the data subject provide additional information necessary to verify the data subject’s identity. Although the controller is obligated to verify the data subject’s identity before the data subject’s right is exercised,, the controller also has an obligation to facilitate the exercise of the data subject’s rights. If the controller imposes conditions on the exercise of a data subject’s rights that require additional steps from the data subject, the controller should be able to adequately justify the conditions imposed and take into account not only the principle of data minimization but also the rules governing the exercise of the data subject’s rights. Based on the information obtained in this matter, the data subject has submitted a request to the data controller to access their personal data. When submitting the request, the data subject provided their name, phone number, and email address. The data controller has asked the data subject for additional information to verify their identity. The data controller has asked the data subject for their home address and personal identification number. In addition, the data controller has asked the data subject to sign the data request form electronically using strong authentication. The additional information requested by the data controller is of a nature that the data controller already processes regarding its customers. The data subject has refused to provide the controller with the requested information because he suspects that his data may be misused and does not wish to provide the controller with any additional information about himself. Considering that the data controller provides comparison services for loan and financial products and processes data concerning the financial status of data subjects, the Deputy Data Protection Ombudsman considers that the data controller had a legitimate reason to request that the data subject provide additional information to verify his or her identity. Careful verification of the data subject’s identity can also be considered important because the data subject suspects that their data has been misused. The Deputy Data Protection Ombudsman notes that a name alone, email address, and phone number cannot, in this case, be considered sufficient identifying information to identify the data subject as presented by the data subject, since several people may share the same name, and such information may also be known to parties other than the data subject. This would create a risk that a third party could relatively easily gain access to the data subject’s processed personal data by utilizing the aforementioned identifying information. The Deputy Data Protection Ombudsman considers that, given the nature of the personal data processed by the data controller, the data controller’s approach to fulfilling the data subject’s request can be deemed appropriate. For the sake of clarity, it should also be noted that the data collected via the form and through strong authentication is of a nature that the controller already processes regarding its customers. Appeal Pursuant to Section 25 of the Data Protection Act (1050/2018), an appeal against this decision may be filed with the administrativeCourt in accordance with the provisions of the Act on Proceedings in Administrative Matters (808/2019). The appeal must be filed with the Administrative Court. Service of Notice The decision will be served by mail with a return receipt in accordance with Section 60 of the Administrative Procedure Act (434/2003). Additional Information The decision was presented by Senior Inspector Emma Särkkä. The decision was issued by Deputy Data Protection Ombudsman Heljä-Tuulia Pihamaa. The decision is not yet final.

Similar Content