Courseiva
Data Governance →easyMultiple Choice

DA0-002 Data Governance Practice Question

A marketing team wants to use customer email addresses collected for newsletter subscriptions to send third-party promotional offers. The data governance policy states that data must be used only for the purpose for which it was collected. Which action should the data governance team take?

⚠ Common exam trap

The trap here is thinking that because the company already holds the data, it can use it for any purpose without additional consent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deny the use because it violates the purpose limitation principle unless new consent is obtained.

Purpose limitation is a core data governance principle: personal data should be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes. Using newsletter subscription emails for third-party promotions is a new purpose that requires a new lawful basis, typically explicit consent. The governance team should deny the request unless proper consent is obtained and the privacy notice is updated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deny the use because email addresses are considered sensitive personal data under all regulations.

    Why it's wrong here

    Email addresses are generally not classified as sensitive personal data, but they are still personal data subject to purpose limitation. The denial is correct, but the reasoning about sensitivity is inaccurate. The primary issue is the unauthorized new purpose, not the sensitivity classification.

  • ✗

    Allow the use if the third-party offers are related to the newsletter content.

    Why it's wrong here

    Even related offers constitute a new purpose not covered by the original consent. Purpose limitation is strict: the new use requires its own lawful basis. Relatedness does not override the need for consent or another legal ground. This would still be a policy violation.

  • ✓

    Deny the use because it violates the purpose limitation principle unless new consent is obtained.

    Why this is correct

    Purpose limitation requires that personal data be used only for the purposes specified at collection. Using email addresses for third-party promotions exceeds the original newsletter subscription purpose. The governance team should deny the request unless the individuals provide explicit consent for the new purpose, which may also require updating the privacy notice.

  • ✗

    Allow the use because the email addresses are already in the company's possession.

    Why it's wrong here

    Possession does not imply permission for new uses. Purpose limitation requires that data collected for newsletter subscriptions not be repurposed for third-party promotions without a lawful basis. Allowing this use would violate the governance policy and potentially data protection regulations.

About these practice questions

This DA0-002 question is part of Courseiva's 1,004-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.