nerdexam
Isaca

CRISC · Question #497

Which of the following scenarios presents the GREATEST risk of noncompliance with data privacy best practices?

The correct answer is D. Data being used for purposes the data subjects have not opted into. The greatest risk of noncompliance with data privacy best practices arises when personal data is used for purposes that the data subjects have not explicitly opted into.

Submitted by haruto_sh· Apr 18, 2026IT Risk Assessment

Question

Which of the following scenarios presents the GREATEST risk of noncompliance with data privacy best practices?

Options

  • AMaking data available to a larger audience of customers
  • BData not being disposed according to the retention policy
  • CPersonal data not being de-identified properly
  • DData being used for purposes the data subjects have not opted into

How the community answered

(27 responses)
  • A
    22% (6)
  • B
    15% (4)
  • C
    4% (1)
  • D
    59% (16)

Why each option

The greatest risk of noncompliance with data privacy best practices arises when personal data is used for purposes that the data subjects have not explicitly opted into.

AMaking data available to a larger audience of customers

Making data available to a larger audience of customers may introduce security or privacy risks depending on the data type and controls, but it is not inherently a non-compliance risk if proper consent and anonymization are in place.

BData not being disposed according to the retention policy

Data not being disposed of according to retention policy is a compliance risk, but often less fundamental than misusing data against a data subject's explicit wishes.

CPersonal data not being de-identified properly

Personal data not being de-identified properly is a significant privacy risk that can lead to re-identification, but it is a technical failure in data handling, whereas using data without consent is a violation of fundamental rights and principles.

DData being used for purposes the data subjects have not opted intoCorrect

Using personal data beyond the scope of its original collection purpose or without explicit consent (opt-in) directly violates fundamental data privacy principles like purpose limitation and consent requirements found in regulations such as GDPR, leading to severe noncompliance risks.

Concept tested: Data privacy compliance risks

Source: https://gdpr-info.eu/art-6-gdpr/

Topics

#Data Privacy#Compliance Risk#Consent Management#Purpose Limitation

Community Discussion

No community discussion yet for this question.

Full CRISC Practice