CompTIA DataSys+ (DS0-001)Data and Database SecurityHard

A company is subject to GDPR regulations and needs to ensure that customer data is deleted upon request ('right to be forgotten'). However, certain historical transaction records must be retained for seven years for financial auditing purposes. Which compliance strategy best balances these conflicting requirements for data lifecycle management?

  1. AUse pseudonymization for customer data to fulfill deletion requests while retaining anonymized transaction records.
  2. BDelete all customer data immediately upon request, regardless of other retention requirements.
  3. CEncrypt all customer data and delete the encryption keys upon request.
  4. DImplement a data retention policy that archives customer data after deletion requests, keeping it encrypted.
Show answer & explanation

Correct answer: A. Use pseudonymization for customer data to fulfill deletion requests while retaining anonymized transaction records.

Pseudonymization allows organizations to replace direct identifiers in customer data with artificial identifiers (pseudonyms). This fulfills the 'right to be forgotten' for identifiable information while allowing the retention of transaction records in an anonymized form for auditing, thus balancing GDPR requirements with financial regulations.

Why the other options are wrong

  • B. Deleting all data immediately would violate the financial auditing requirement to retain records for seven years.
  • C. Deleting encryption keys makes the data permanently inaccessible, which would violate the financial auditing requirement to retain records.
  • D. Archiving encrypted data still means the identifiable data exists and could potentially be decrypted, which might not fully satisfy a 'right to be forgotten' request unless the data is truly unlinked.

Pseudonymization

A data protection technique where personally identifiable information (PII) is replaced with artificial identifiers (pseudonyms) to reduce data's linkability to an individual.

  • Differs from anonymization by retaining the possibility of re-identification with additional information.
  • Helps comply with privacy regulations like GDPR.
  • Balances privacy with data utility for analysis or retention.

Memory trick: Privacy techniques are like different ways to hide or disguise identity.

More Data and Database Security questions