Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard

A large multinational corporation is subject to the General Data Protection Regulation (GDPR) due to its operations in Europe. During an internal audit, it's discovered that customer data collected from European citizens is being stored on servers located in a country without an adequate level of data protection, and no appropriate safeguards (like Standard Contractual Clauses) are in place. Which GDPR principle is primarily being violated?

  1. APurpose limitation
  2. BLawfulness, fairness, and transparency
  3. CIntegrity and confidentiality
  4. DStorage limitation
Show answer & explanation

Correct answer: C. Integrity and confidentiality

The scenario describes a violation of the GDPR principle of 'Integrity and confidentiality' (Article 5(1)(f)), which requires personal data to be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures. Storing data in a country without adequate data protection and without safeguards directly compromises the security and confidentiality of that data.

Why the other options are wrong

  • A. Purpose limitation means data should only be collected for specified, explicit, and legitimate purposes, not violated by insecure storage location.
  • B. Lawfulness, fairness, and transparency relate to the legal basis and clear communication of data processing, not directly to cross-border storage security.
  • D. Storage limitation dictates that data should not be kept longer than necessary, not related to the security of its storage location.

GDPR Principle: Integrity and Confidentiality

One of the seven core principles of GDPR, requiring personal data to be processed in a manner that ensures appropriate security against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.

  • Also known as 'Security' principle.
  • Requires 'appropriate technical or organisational measures'.
  • Covers protection against unauthorized access, disclosure, alteration, or destruction.
  • Directly impacted by data residency and transfer mechanisms.

Memory trick: GDPR's principles are like rules for handling data: keep it legal, limited, accurate, secure, and accountable.

More Security Concepts questions