nerdexam
Cisco

200-201 · Question #565

A compliance analyst has received a complaint from a customer regarding personal data being held by the company unlawfully, despite the customer's request for it to be deleted. The company, based in…

Given the company's adherence to GDPR and the customer's request for data deletion, the compliance analyst must immediately delete the email address, as it constitutes personal data held unlawfully.

Submitted by viktor_hu· Mar 6, 2026Security Policies and Procedures

Question

A compliance analyst has received a complaint from a customer regarding personal data being held by the company unlawfully, despite the customer’s request for it to be deleted. The company, based in Europe, must adhere to the strict GDPR guidelines. The only data collected by the company in this case is the email address “[email protected]”. How should the compliance analyst act on the case?

Options

  • ADo not delete the data - this email is not considered PII.
  • BDelete the data regardless of where customer is from.
  • CDelete the data if the customer is from the EU.
  • DNotify legal team about data compliance breach.

Why each option

Given the company's adherence to GDPR and the customer's request for data deletion, the compliance analyst must immediately delete the email address, as it constitutes personal data held unlawfully.

ADo not delete the data - this email is not considered PII.

An email address is considered Personal Identifiable Information (PII) under GDPR because it can directly or indirectly identify an individual, making data deletion mandatory upon a valid request.

BDelete the data regardless of where customer is from.
CDelete the data if the customer is from the EU.

GDPR's territorial scope (Article 3) applies if a company in the EU processes personal data, meaning the data subject's location (EU or non-EU) does not negate their rights if GDPR applies to the processing.

DNotify legal team about data compliance breach.

While notifying the legal team about a compliance breach is an important subsequent step given the data was held unlawfully, the immediate and primary action to rectify the situation is to fulfill the customer's request by deleting the data.

Concept tested: GDPR Right to Erasure (Article 17)

Source: https://gdpr-info.eu/art-17-gdpr/

Topics

#GDPR#PII#data privacy#compliance

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice