During a privacy audit, the IS auditor discovers that the organization does not have a complete data inventory. What is the PRIMARY risk associated with this finding?
This is a direct consequence of not knowing where PII resides.
Why this answer
Without knowing where PII is stored and processed, the organization cannot effectively protect it, respond to data subject requests, or ensure compliance with privacy regulations like GDPR.