Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A multinational retailer operates under GDPR for its EU customers and must demonstrate accountability to supervisory authorities. The Chief Privacy Officer wants a mechanism that documents, on an ongoing basis, which processing activities occur, what data categories are involved, and how long each is retained. Which GDPR instrument should the privacy team maintain to satisfy this requirement?

⚠ Common exam trap

The trap here is assuming any accountability document satisfies GDPR Article 30, when only the Records of Processing Activities provides the required ongoing inventory of processing purposes, data categories, and retention periods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Records of Processing Activities (RoPA) under Article 30

The Records of Processing Activities is the Article 30 accountability instrument that captures processing purposes, data categories, recipients, retention, and safeguards in one maintained register. A DPIA analyses a single high-risk activity, while SCCs and BCRs are cross-border transfer mechanisms. Only the RoPA provides the persistent, organization-wide documentation the retailer needs to show supervisory authorities how EU personal data is handled and retained.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Standard Contractual Clauses (SCCs)

    Why it's wrong here

    SCCs are contractual transfer mechanisms used when personal data moves to a third country lacking an adequacy decision. They govern lawful cross-border transfers between the exporter and importer, not the internal documentation of processing purposes, data categories, and retention schedules. Adopting SCCs would not produce the ongoing register of processing activities the privacy team is being asked to maintain.

  • ✗

    Binding Corporate Rules (BCRs)

    Why it's wrong here

    BCRs are intra-group transfer policies approved by a supervisory authority that allow multinationals to move personal data between affiliates. They address lawful international transfers, not the operational documentation of each processing activity and its retention. Although BCRs demonstrate accountability, they do not substitute for the Article 30 register that records what is processed, why, and for how long.

  • ✗

    Data Protection Impact Assessment (DPIA)

    Why it's wrong here

    A DPIA is a targeted risk assessment required before high-risk processing such as large-scale profiling or sensitive-data handling. It analyses a specific initiative rather than serving as a comprehensive, continuously updated inventory of every processing activity, retention period, and data category. Using a DPIA alone would leave the retailer without the complete Article 30 register the supervisory authority expects during accountability reviews.

  • ✓

    Records of Processing Activities (RoPA) under Article 30

    Why this is correct

    The RoPA is the Article 30 accountability artifact that catalogues each processing activity, its purposes, data categories, recipients, retention periods, and security measures. It directly answers the regulator's need for a living register documenting what is processed and for how long. Because the retailer processes data at scale, maintaining this register is mandatory and serves as the documentary backbone for demonstrating GDPR accountability.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.