CompTIA Project+ (PK0-005)Basics of IT and GovernanceHard

A project is establishing a new data retention policy for customer information. The policy dictates that customer data must be deleted after 7 years of inactivity, unless legal requirements mandate longer storage. This is a direct measure to comply with principles related to data minimization and storage limitation. Which aspect of data privacy and compliance is this policy primarily addressing?

  1. ARight to be Forgotten
  2. BConsent Management
  3. CData Portability
  4. DData Lifecycle Management
Show answer & explanation

Correct answer: D. Data Lifecycle Management

Data Lifecycle Management encompasses all stages of data handling from creation to deletion, including setting retention policies and ensuring data is appropriately removed when no longer needed, directly addressing the scenario.

Why the other options are wrong

  • A. The Right to be Forgotten (or Erasure) allows individuals to request deletion of their personal data under certain circumstances.
  • B. Consent Management deals with obtaining and managing user permissions for data processing, not the duration of data storage.
  • C. Data Portability allows individuals to obtain and reuse their personal data for their own purposes across different services.

Data Lifecycle Management (DLM)

Data Lifecycle Management (DLM) is a comprehensive approach to managing the flow of an information system's data from creation and initial storage to its obsolescence and eventual deletion.

  • Covers data creation, storage, use, sharing, archiving, and destruction.
  • Ensures compliance with regulatory requirements and internal policies.
  • Aims to optimize data value, reduce risks, and control costs.

Memory trick: DLM: Data Lives, Managed from Start to End.

More Basics of IT and Governance questions