CIPM Data Retention and Deletion 1 — Questions and Answers
Question 1: What is the primary principle behind data retention schedules in a privacy program?
- Retaining data as long as technically possible to support future needs
- Keeping data only as long as necessary for its specified purpose (Correct answer)
- Storing all data indefinitely to comply with potential legal holds
- Retaining data based solely on business unit preferences
Correct answer: Keeping data only as long as necessary for its specified purpose
The data minimization and storage limitation principles require that personal data be kept only as long as necessary for the purpose for which it was collected.
Question 2: Which of the following best describes a data retention schedule?
- A log of all employees who accessed personal data
- A document mapping data categories to their required retention periods and disposal methods (Correct answer)
- A backup policy for archiving data to offsite storage
- A list of data subjects who have opted out of data collection
Correct answer: A document mapping data categories to their required retention periods and disposal methods
A data retention schedule maps each category of data to its mandated or appropriate retention period and the method of secure disposal at end of life.
Question 3: When establishing retention periods, which factor should take highest priority?
- Internal storage cost reduction targets
- Legal and regulatory requirements (Correct answer)
- Vendor contract terms
- Employee convenience and workflow preferences
Correct answer: Legal and regulatory requirements
Legal and regulatory requirements set the minimum baseline for retention periods, and failure to comply can result in penalties and liability.
Question 4: What is a 'legal hold' in the context of data retention?
- A regulatory prohibition on collecting certain categories of data
- A suspension of normal deletion schedules due to anticipated or ongoing litigation (Correct answer)
- A contractual obligation to share data with a third party
- A data subject's request to restrict processing
Correct answer: A suspension of normal deletion schedules due to anticipated or ongoing litigation
A legal hold (or litigation hold) suspends routine data disposal obligations when litigation, investigation, or audit is reasonably anticipated.
Question 5: Which method is most appropriate for securely disposing of personal data stored on solid-state drives (SSDs)?
- Overwriting with zeros using a single-pass wipe
- Physical degaussing with a strong magnetic field
- Cryptographic erasure (destroying the encryption keys) (Correct answer)
- Standard file deletion through the operating system
Correct answer: Cryptographic erasure (destroying the encryption keys)
SSDs use wear-leveling that makes overwriting unreliable; cryptographic erasure renders data unrecoverable by destroying the keys used to encrypt it.
Question 6: Under the GDPR's storage limitation principle, personal data should be:
- Retained for at least five years to ensure business continuity
- Kept in a form that permits identification no longer than necessary (Correct answer)
- Stored in encrypted form indefinitely as encryption satisfies the requirement
- Deleted only upon a data subject's explicit request
Correct answer: Kept in a form that permits identification no longer than necessary
GDPR Article 5(1)(e) requires that personal data be kept in a form permitting identification of data subjects for no longer than necessary for the stated purpose.
Question 7: What is 'data minimization' as it relates to retention?
- Compressing data files to reduce storage costs
- Collecting and retaining only the data that is adequate, relevant, and limited to what is necessary (Correct answer)
- Anonymizing data before long-term archiving
- Reducing the number of systems that store personal data
Correct answer: Collecting and retaining only the data that is adequate, relevant, and limited to what is necessary
Data minimization requires that only data that is necessary for the specified purpose be collected and retained, limiting both scope and duration.
What is the primary principle behind data retention schedules in a privacy program?