France's data protection authority, the Commission nationale de l'informatique et des libertés, opened a public consultation for ensuring multifactor authentication solutions comply with the EU General Data Protection Regulation. The CNIL's draft recommendation includes information for data controllers to understand the conditions under which MFA is necessary for either legal or security purposes and the underlying GDPR compliance principles for MFA. The consultation ends 31 May.