Certified Information Privacy Technologist (CIPT) — Question 232

Which of the following is the best control to apply to personally identifiable data when the retention period ends?

Answer options

Correct answer: D

Explanation

The correct answer is D, Deletion, as it ensures that personally identifiable data is permanently removed and cannot be accessed or recovered. Options A and B, De-identification and Anonymization, reduce the risk of identification but do not eliminate the data. Option C, Archiving, retains the data, which is not appropriate once the retention period has ended.