nerdexam
IAPP

CIPM · Question #128

Data retention and destruction policies should meet all of the following requirements EXCEPT?

The correct answer is C. Documentation related to audit controls (third-party or internal) should be saved in a non-. See the full explanation below for the reasoning.

Question

Data retention and destruction policies should meet all of the following requirements EXCEPT?

Options

  • AData destruction triggers and methods should be documented.
  • BPersonal information should be retained only for as long as necessary to perform its stated
  • CDocumentation related to audit controls (third-party or internal) should be saved in a non-
  • DThe organization should be documenting and reviewing policies of its other functions to ensure

How the community answered

(43 responses)
  • A
    12% (5)
  • B
    5% (2)
  • C
    77% (33)
  • D
    7% (3)

Community Discussion

No community discussion yet for this question.

Full CIPM Practice