DA0-002 Visualization and Reporting Practice Question
A data analyst is preparing a report on customer satisfaction scores. To comply with GDPR, which THREE actions must be taken? (Select THREE.)
⚠ Common exam trap
DA0-002 often tests the misconception that 'aggregated data is automatically anonymous' or that retaining data indefinitely is acceptable for analytics — both violate GDPR's storage limitation and anonymization standards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure aggregates do not identify individuals
Option B is correct because GDPR's data minimization and purpose-limitation principles require that aggregated statistics used for reporting must not allow re-identification of any individual, so ensuring aggregates do not identify individuals protects data subjects' privacy. Option D is correct because anonymizing personally identifiable information (PII) such as names, email addresses, and account numbers removes the personal data from scope of GDPR processing, satisfying the regulation's requirement to protect identifiable data. Option E is correct because GDPR Article 5(1)(e) mandates storage limitation, meaning the analyst must establish defined data retention periods for the report data rather than keeping it longer than necessary. Option A is incorrect because retaining data indefinitely violates the GDPR storage-limitation principle. Option C is incorrect because including customer names for context unnecessarily introduces identifiable personal data, contradicting data minimization and the anonymization requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Retain data indefinitely for analysis
Why it's wrong here
Indefinite retention breaches the GDPR storage-limitation principle, which requires personal data be kept no longer than necessary for its stated purpose. It is tempting because long retention supports historical trend analysis, and it would be acceptable only where a documented legal or regulatory obligation specifies that retention period.
- ✓
Ensure aggregates do not identify individuals
Why this is correct
Aggregation must not allow re-identification, so ensuring aggregates do not identify individuals upholds GDPR's anonymisation principle. It satisfies the compliance constraint by preventing small cell sizes or unique combinations from exposing a single data subject within the satisfaction report.
- ✗
Include customer names for context
Why it's wrong here
Including customer names exceeds the data-minimisation principle: satisfaction reporting needs only the scores, not directly identifying personal data. It is tempting because names give context and aid interpretation, and it would be justified only where identity is genuinely necessary and a lawful basis plus appropriate safeguards exist.
- ✓
Anonymize personally identifiable information
Why this is correct
Anonymising personally identifiable information removes the link between data subjects and their satisfaction scores, satisfying GDPR's data minimisation and purpose limitation requirements. This directly addresses the compliance constraint by ensuring the report contains no personal data requiring lawful basis.
- ✓
Establish data retention periods for the report data
Why this is correct
Establishing retention periods satisfies GDPR's storage limitation principle, which requires personal data be kept no longer than necessary for its stated purpose. For customer satisfaction scores, this means defining and enforcing a deletion schedule, ensuring the report data is not retained indefinitely beyond its lawful analytical use.
Go deeper
Related to this question
About these practice questions
One of 1,004 original DA0-002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.