ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityEasy

A multinational corporation operates in several countries, each with distinct data privacy regulations regarding the collection, processing, and storage of customer data. The company is developing a global data handling policy. Which principle, often found in privacy regulations like GDPR, dictates that personal data should only be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes?

  1. AData Minimization
  2. BPurpose Limitation
  3. CStorage Limitation
  4. DAccountability
Show answer & explanation

Correct answer: B. Purpose Limitation

Purpose Limitation dictates that data should be collected for specific, explicit, and legitimate purposes and not be processed incompatibly with those purposes. This is a core principle of many privacy regulations like GDPR.

Why the other options are wrong

  • A. Data Minimization focuses on collecting only the necessary amount of data, not the purpose for its collection.
  • C. Storage Limitation dictates that data should not be kept longer than necessary, not the initial purpose of collection.
  • D. Accountability refers to the obligation of organizations to demonstrate compliance with data protection principles, not the specific principle of data use.

Purpose Limitation (GDPR)

A GDPR principle stating that personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.

  • Data collected for stated reasons
  • No incompatible secondary use
  • Core privacy principle

Memory trick: LIMIT your Purpose, Minimize your Data, Store for a short Time, Ensure Accuracy and Integrity, Maintain Lawfulness, and be Accountable.

More Asset Security questions