โ† All CDPSE Flashcard Decks

Data Lifecycle Management Flashcards

6 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Data Lifecycle Management flashcards as text
  1. An organization collects customer email addresses for order confirmations but later uses them for marketing newsletters. This violates which data lifecycle principle?

    Answer: Purpose limitation

    Purpose limitation requires that personal data collected for a specific purpose must not be used for incompatible secondary purposes without a new legal basis.

  2. Which technique renders personal data permanently unusable by removing all direct and indirect identifiers?

    Answer: Anonymization

    Anonymization irreversibly removes all identifying information so that re-identification is not reasonably possible, taking the data outside the scope of most privacy regulations.

  3. A company stores personal data on decommissioned server hard drives in a locked warehouse. What is the MAIN privacy risk?

    Answer: Unauthorized physical access leading to data recovery

    Retaining unwiped storage media creates a risk that data could be physically accessed and recovered using forensic tools.

  4. Under the CDPSE framework, who bears primary accountability for defining data retention policies?

    Answer: Data owner or business unit responsible for the data

    The data owner is accountable for determining how long data must be retained to meet business and regulatory requirements.

  5. What is the privacy risk of keeping personal data in test and development environments?

    Answer: Exposure of live personal data in less-controlled environments

    Dev and test environments typically have weaker security controls than production, so using real personal data risks unauthorized exposure.

  6. Which activity BEST supports the principle of data minimization during system design?

    Answer: Collecting only the data elements strictly required for the defined purpose

    Data minimization means not collecting personal data beyond what is necessary, reducing the privacy risk surface from the outset.