ExamGecko
Home Home / IAPP / CIPM
Question list
Search
Search

List of questions

Search

Related questions











Question 126 - CIPM discussion

Report
Export

Data retention and destruction policies should meet all of the following requirements EXCEPT?

A.

Data destruction triggers and methods should be documented.

Answers
A.

Data destruction triggers and methods should be documented.

B.

Personal information should be retained only for as long as necessary to perform its stated purpose.

Answers
B.

Personal information should be retained only for as long as necessary to perform its stated purpose.

C.

Documentation related to audit controls (third-party or internal) should be saved in a non-permanent format by default.

Answers
C.

Documentation related to audit controls (third-party or internal) should be saved in a non-permanent format by default.

D.

The organization should be documenting and reviewing policies of its other functions to ensure alignment (e.g. HR, business development, finance, etc.).

Answers
D.

The organization should be documenting and reviewing policies of its other functions to ensure alignment (e.g. HR, business development, finance, etc.).

Suggested answer: C

Explanation:

Documentation related to audit controls (third-party or internal) should be saved in apermanentformat by default, not a non-permanent one. This is to ensure that the organization can demonstrate its compliance with the applicable laws and regulations, as well as its own policies and procedures, in case of an audit or a legal challenge. The other options are valid requirements for data retention and destruction policies, as they help to minimize the risks and costs associated with storing personal information beyond its intended purpose.Reference:CIPM Body of Knowledge, Domain III: Privacy Program Management Activities, Task 3: Manage data retention and disposal.

asked 22/11/2024
Helania Stevenson
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first