Under GDPR, what PHP session handling practice is required when a user withdraws consent?
-
A
Destroy the session and delete associated personal data
-
B
Archive the session for 30 days before deletion
-
C
Anonymize the session ID only
-
D
Transfer the session to a cold storage system