QuestionQ28

Compliance with European Data Protection Law and Regulation

Under Article 30 of the GDPR, controllers must retain records of all the following EXCEPT?

Choose two
  • A Incidents of personal data breaches, whether disclosed or not.
  • B Data inventory or data mapping exercises that have been conducted.
  • C Categories of recipients to whom the personal data have been disclosed.
  • D Retention periods for erasure and deletion of categories of personal data.
Explanation

Article 30(1) requires records of processing activities to include categories of recipients and, where possible, the envisaged time limits for erasure of the different categories of personal data. It does not mandate records of data-inventory or data-mapping exercises. Documentation of personal-data breaches is required separately by Article 33(5), not by Article 30.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!