IAPP
CIPM · Question #128
Data retention and destruction policies should meet all of the following requirements EXCEPT?
The correct answer is C. Documentation related to audit controls (third-party or internal) should be saved in a non-. See the full explanation below for the reasoning.
Question
Data retention and destruction policies should meet all of the following requirements EXCEPT?
Options
- AData destruction triggers and methods should be documented.
- BPersonal information should be retained only for as long as necessary to perform its stated
- CDocumentation related to audit controls (third-party or internal) should be saved in a non-
- DThe organization should be documenting and reviewing policies of its other functions to ensure
How the community answered
(43 responses)- A12% (5)
- B5% (2)
- C77% (33)
- D7% (3)
Community Discussion
No community discussion yet for this question.