QuestionQ293

Privacy Operational Lifecycle: Protect

Data retention and destruction policies should satisfy all of the following requirements EXCEPT?

  • A Data destruction triggers and methods should be documented.
  • B Personal information should be retained only for as long as necessary to perform its stated purpose.
  • C Documentation related to audit controls (third-party or internal) should be saved in a non-permanent format by default.
  • D The organization should be documenting and reviewing policies of its other functions to ensure alignment (e.g. HR, business development, finance, etc.).
Explanation

Audit-control documentation and audit records must be retained for a period consistent with the organization’s records-retention policy, supporting investigations and regulatory or organizational retention obligations. They should not default to a non-permanent format that could undermine their availability or retention.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!