CIPM Data Retention and Deletion 2 — Questions and Answers
Question 1: Which of the following is a key element of an effective data destruction certification?
- Signature of the data subject whose data was destroyed
- Documentation of the date, method, and identity of personnel who performed destruction (Correct answer)
- Approval from the Chief Marketing Officer
- A copy of the data that was destroyed for audit purposes
Correct answer: Documentation of the date, method, and identity of personnel who performed destruction
Destruction certificates serve as evidence of compliance and should capture when, how, and by whom data was destroyed, creating an auditable record.
Question 2: How should an organization handle personal data in backup systems when the primary data has reached its retention limit?
- Backups are exempt from retention requirements and can be kept indefinitely
- The organization should establish processes to purge expired data from backups on a scheduled basis (Correct answer)
- Only encrypt the backup data rather than deleting it
- Transfer backup data to a third-party for long-term archiving
Correct answer: The organization should establish processes to purge expired data from backups on a scheduled basis
Retention obligations apply to all copies of data, including backups; organizations must establish processes to purge expired data from backup systems.
Question 3: What role does a Records Retention Policy play in a privacy program?
- It defines the technical architecture for storing records
- It establishes organization-wide rules for how long records are kept and how they are disposed of (Correct answer)
- It authorizes data subjects to access their personal data
- It determines which employees can view sensitive records
Correct answer: It establishes organization-wide rules for how long records are kept and how they are disposed of
A Records Retention Policy provides the governance framework specifying retention periods by record type and the approved methods for secure disposal.
Question 4: Which of the following scenarios requires a reassessment of existing retention periods?
- A new software version is deployed to manage records
- New legislation changes the minimum retention requirement for a data category (Correct answer)
- An employee is promoted to a records management role
- The organization changes its email provider
Correct answer: New legislation changes the minimum retention requirement for a data category
Changes in law or regulation that affect minimum or maximum retention periods require a review and update of existing retention schedules to ensure ongoing compliance.
Question 5: What is 'pseudonymization' and how does it relate to retention?
- Permanently removing all identifiers from data so it can be kept indefinitely without restriction
- Replacing direct identifiers with a key, allowing re-identification, but reducing risk during longer retention periods (Correct answer)
- Encrypting data to prevent unauthorized access during the retention period
- Converting data to an anonymous format immediately upon collection
Correct answer: Replacing direct identifiers with a key, allowing re-identification, but reducing risk during longer retention periods
Pseudonymization replaces identifiers with a key while retaining re-identification capability; it reduces risk during retention but the data remains personal and subject to retention rules.
Question 6: Under the California Consumer Privacy Act (CCPA), businesses must inform consumers about:
- The specific employees responsible for managing their data
- The length of time each category of personal information will be retained, or the criteria used to determine it (Correct answer)
- The exact server locations where data is stored
- The profit generated from selling their personal information
Correct answer: The length of time each category of personal information will be retained, or the criteria used to determine it
CCPA requires businesses to disclose in their privacy notice either the specific retention period or the criteria used to determine how long each category of personal information is kept.
Question 7: What is the purpose of a data inventory or data map in managing retention?
- To monitor employee access to personal data in real time
- To identify all data categories, their locations, and owners so retention schedules can be applied consistently (Correct answer)
- To automatically delete data when it reaches its retention limit
- To encrypt data at rest across all organizational systems
Correct answer: To identify all data categories, their locations, and owners so retention schedules can be applied consistently
A data inventory provides visibility into what data exists, where it lives, and who owns it, enabling accurate application of retention rules across the organization.
Which of the following is a key element of an effective data destruction certification?