CompTIA Project+ (PK0-005)Basics of IT and GovernanceHard

A financial services company is implementing a new customer relationship management (CRM) system that will store highly sensitive client financial data. The project manager is tasked with ensuring the system meets stringent data privacy and compliance requirements, including GDPR. Which of the following is the MOST critical consideration during the system design phase?

  1. AIntegrating with existing marketing automation tools for targeted campaigns.
  2. BOptimizing database queries for faster report generation.
  3. CEnsuring the system architecture supports data minimization and pseudonymization by default.
  4. DDesigning a user interface with intuitive navigation and customizable dashboards.
Show answer & explanation

Correct answer: C. Ensuring the system architecture supports data minimization and pseudonymization by default.

GDPR emphasizes 'Privacy by Design' and 'Data Protection by Design and by Default.' Data minimization (collecting only necessary data) and pseudonymization (processing personal data so it can no longer be attributed to a specific data subject without additional information) are core principles for meeting these requirements. Integrating these into the system architecture from the design phase is critical for GDPR compliance.

Why the other options are wrong

  • A. Marketing integration is a functional requirement, not a core data privacy or compliance control for sensitive data.
  • B. Query optimization is for performance, not primarily for data privacy or compliance.
  • D. UI design improves user experience but does not inherently ensure data privacy or compliance with regulations like GDPR.

GDPR Data Principles

Core tenets of the General Data Protection Regulation (GDPR) that dictate how personal data must be processed and protected.

  • Lawfulness, fairness, and transparency.
  • Purpose limitation, data minimization.
  • Accuracy, storage limitation, integrity, and confidentiality.
  • Accountability.

Memory trick: GDPR: 'My Data' is 'My Right' – Protect it by Design.

More Basics of IT and Governance questions