Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium
A financial institution is implementing a new data retention policy to comply with GDPR regulations. The policy specifies that customer transaction data must be anonymized or deleted after seven years. Which core principle of data privacy is this policy primarily addressing?
- AIntegrity and Confidentiality
- BData Minimization
- CStorage Limitation
- DAccuracy
Show answer & explanationAnswer & explanation
Correct answer: C. Storage Limitation
The policy's requirement to anonymize or delete data after a specified period directly relates to the GDPR principle of Storage Limitation, which dictates that personal data should not be kept longer than necessary for the purposes for which it was processed.
Why the other options are wrong
- A. Integrity and Confidentiality concern protecting data from unauthorized access or alteration.
- B. Data Minimization is about collecting only necessary data, not how long it's kept.
- D. Accuracy refers to keeping data correct and up-to-date.
GDPR Storage Limitation
A principle under GDPR requiring personal data to be kept for no longer than is necessary for the purposes for which it is processed.
- Requires defining clear data retention periods.
- Mandates deletion or anonymization of data past its retention period.
- Reduces the risk of data breaches and non-compliance.
Memory trick: Lawfulness, Fairness, Transparency, Purpose, Minimization, Accuracy, Storage, Integrity, Accountability.