ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityEasy

A multinational corporation is implementing a new global data handling policy. The Chief Privacy Officer (CPO) is tasked with ensuring compliance across all jurisdictions. Which of the following principles is paramount when designing data retention schedules for personal data collected from EU citizens?

  1. AData should be retained indefinitely to support future business intelligence initiatives.
  2. BData should be retained for a minimum of 10 years to meet potential legal discovery requirements.
  3. CData retention periods should be standardized globally to simplify compliance.
  4. DData should be retained only for as long as necessary to fulfill the purpose for which it was collected.
Show answer & explanation

Correct answer: D. Data should be retained only for as long as necessary to fulfill the purpose for which it was collected.

The principle of 'storage limitation' under GDPR dictates that personal data should not be kept for longer than is necessary for the purposes for which it is processed. This directly addresses the need for specific, purpose-driven retention schedules.

Why the other options are wrong

  • A. Indefinite retention violates privacy principles and increases risk.
  • B. A blanket 10-year retention period is arbitrary and often violates 'storage limitation' unless specific legal requirements mandate it.
  • C. While desirable for simplicity, it often conflicts with varying jurisdictional requirements and privacy principles.

Storage Limitation (GDPR)

A principle under GDPR that requires personal data to be kept for no longer than is necessary for the purposes for which it is processed.

  • Prevents indefinite data retention.
  • Requires explicit retention periods.
  • Reduces risk of data breaches and misuse.

Memory trick: Lawful, Fair, Transparent, Purpose, Minimize, Accurate, Limit, Integrity, Accountability.

More Asset Security questions