QuestionQ293
Privacy Operational Lifecycle: ProtectData retention and destruction policies should satisfy all of the following requirements EXCEPT?
- A Data destruction triggers and methods should be documented.
- B Personal information should be retained only for as long as necessary to perform its stated purpose.
- C Documentation related to audit controls (third-party or internal) should be saved in a non-permanent format by default.
- D The organization should be documenting and reviewing policies of its other functions to ensure alignment (e.g. HR, business development, finance, etc.).
Community Discussion