IGP Records Management & Data Privacy 2 — Questions and Answers
Question 1: Under GDPR, which principle requires that personal data be kept in a form that permits identification of data subjects for no longer than necessary?
- Data minimization
- Storage limitation (Correct answer)
- Purpose limitation
- Integrity and confidentiality
Correct answer: Storage limitation
The storage limitation principle under GDPR requires that personal data be kept in identifiable form only as long as necessary for the stated purpose.
Question 2: A company receives a litigation hold notice after existing records have already been scheduled for destruction. What is the correct action?
- Proceed with destruction since it was already scheduled
- Suspend the destruction and preserve all potentially relevant records (Correct answer)
- Destroy only records not mentioned in the notice
- Transfer the records to outside counsel immediately
Correct answer: Suspend the destruction and preserve all potentially relevant records
A litigation hold supersedes any existing retention schedules and requires immediate suspension of destruction for all potentially relevant records.
Question 3: Which ISO standard specifically addresses records management systems and their requirements?
- ISO 27001
- ISO 15489 (Correct answer)
- ISO 9001
- ISO 31000
Correct answer: ISO 15489
ISO 15489 is the international standard specifically dedicated to records management, covering principles and implementation guidelines.
Question 4: A data subject requests deletion of their personal data under CCPA. Under which circumstance may the business lawfully refuse?
- The data is more than two years old
- The data is necessary to complete a transaction the consumer requested (Correct answer)
- The consumer did not provide opt-in consent originally
- The business employs fewer than 50 people
Correct answer: The data is necessary to complete a transaction the consumer requested
CCPA allows businesses to deny deletion requests when the data is necessary to complete a transaction the consumer requested or reasonably anticipated.
Question 5: What is the primary purpose of a records inventory in an information governance program?
- To assign monetary value to each record type
- To identify what records exist, where they are located, and how they are managed (Correct answer)
- To determine which employees have access to records
- To calculate storage costs for budget planning
Correct answer: To identify what records exist, where they are located, and how they are managed
A records inventory establishes a baseline understanding of what records exist, their location, format, and management practices before any governance decisions are made.
Question 6: Which data privacy concept gives individuals the right to receive their personal data in a structured, commonly used, machine-readable format?
- Right to erasure
- Right to data portability (Correct answer)
- Right to restriction of processing
- Right to object
Correct answer: Right to data portability
The right to data portability, established under GDPR Article 20, allows individuals to receive and transfer their personal data in a reusable format.
Question 7: In records management, what distinguishes a 'record' from a 'non-record'?
- Records are digital; non-records are physical
- Records document organizational activities and have ongoing value; non-records are transitory (Correct answer)
- Records are stored on-premises; non-records are in the cloud
- Records require encryption; non-records do not
Correct answer: Records document organizational activities and have ongoing value; non-records are transitory
Records are documents that provide evidence of organizational activities and have ongoing business, legal, or historical value, distinguishing them from transitory non-records like draft copies.
Under GDPR, which principle requires that personal data be kept in a form that permits identification of data subjects for no longer than necessary?