DA0-002 Data Governance Practice Question
A marketing team wants to use customer email addresses collected for newsletter subscriptions to send third-party promotional offers. The data governance policy states that data must be used only for the purpose for which it was collected. Which action should the data governance team take?
⚠ Common exam trap
The trap here is thinking that because the company already holds the data, it can use it for any purpose without additional consent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deny the use because it violates the purpose limitation principle unless new consent is obtained.
Purpose limitation is a core data governance principle: personal data should be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes. Using newsletter subscription emails for third-party promotions is a new purpose that requires a new lawful basis, typically explicit consent. The governance team should deny the request unless proper consent is obtained and the privacy notice is updated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deny the use because email addresses are considered sensitive personal data under all regulations.
Why it's wrong here
Email addresses are generally not classified as sensitive personal data, but they are still personal data subject to purpose limitation. The denial is correct, but the reasoning about sensitivity is inaccurate. The primary issue is the unauthorized new purpose, not the sensitivity classification.
- ✗
Allow the use if the third-party offers are related to the newsletter content.
Why it's wrong here
Even related offers constitute a new purpose not covered by the original consent. Purpose limitation is strict: the new use requires its own lawful basis. Relatedness does not override the need for consent or another legal ground. This would still be a policy violation.
- ✓
Deny the use because it violates the purpose limitation principle unless new consent is obtained.
Why this is correct
Purpose limitation requires that personal data be used only for the purposes specified at collection. Using email addresses for third-party promotions exceeds the original newsletter subscription purpose. The governance team should deny the request unless the individuals provide explicit consent for the new purpose, which may also require updating the privacy notice.
- ✗
Allow the use because the email addresses are already in the company's possession.
Why it's wrong here
Possession does not imply permission for new uses. Purpose limitation requires that data collected for newsletter subscriptions not be repurposed for third-party promotions without a lawful basis. Allowing this use would violate the governance policy and potentially data protection regulations.
Go deeper
Related to this question
About these practice questions
This DA0-002 question is part of Courseiva's 1,004-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.