ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium
A large e-commerce company stores vast amounts of customer data, including names, addresses, credit card numbers, and purchase history. The company has a privacy policy stating that customer data will only be used for order fulfillment and personalized marketing, and will not be shared with third parties without explicit consent. This policy is an example of what core aspect of protecting privacy?
- ATransparency
- BAccuracy
- CData minimization
- DPurpose limitation
Show answer & explanationAnswer & explanation
Correct answer: D. Purpose limitation
The policy stating that data will 'only be used for order fulfillment and personalized marketing' and 'not be shared with third parties without explicit consent' directly aligns with the principle of purpose limitation. This principle dictates that personal data should be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
Why the other options are wrong
- A. Transparency is about informing individuals about data practices, but the policy itself defines the 'purpose' rather than just being transparent about it.
- B. Accuracy refers to ensuring data is correct and up-to-date, which is not the focus of this policy statement.
- C. Data minimization is about collecting only the necessary data, not how it's used after collection.
Purpose Limitation
A privacy principle that states personal data should be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Defines the scope of data use.
- Prevents repurposing data without consent.
- A core principle in privacy regulations like GDPR.
Memory trick: Fair, Purpose, Minimize, Accurate, Limit, Secure, Accountable, Transparent.