Courseiva

CISA Protection of Information Assets Practice Question

An organization processes personal data of EU residents and has implemented pseudonymisation as a privacy control. The IS auditor is reviewing the effectiveness of this control in meeting GDPR requirements. Which of the following is the MOST important limitation of pseudonymisation?

⚠ Common exam trap

CISA often tests the misconception that pseudonymisation equals anonymisation — candidates incorrectly assume pseudonymised data falls outside GDPR scope, when in fact it remains personal data subject to full regulatory obligations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pseudonymised data is still considered personal data under GDPR

Under GDPR Article 4(5), pseudonymisation is a technique where personal data can no longer be attributed to a specific data subject without additional information kept separately. However, because re-identification remains possible with that additional information, pseudonymised data is still legally considered personal data under GDPR, meaning data subject rights, breach notification, and other obligations continue to apply. This is the most important limitation an IS auditor must recognize when assessing the control's effectiveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pseudonymisation eliminates the need for data subject rights

    Why it's wrong here

    Pseudonymised data remains personal data under GDPR, so access, erasure, rectification and portability rights still apply; the controller must retain the mapping key to honour them. It tempts because anonymisation genuinely removes data from GDPR's scope, and that is the correct choice only when re-identification is truly impossible.

  • ✗

    Pseudonymisation is not recognized by GDPR

    Why it's wrong here

    GDPR Article 4(5) explicitly defines pseudonymisation and Article 32 names it as an appropriate safeguard, so the claim it is unrecognised is factually false. It tempts auditors who confuse pseudonymisation with anonymisation, which sits outside GDPR's scope; pseudonymisation is the correct control when data must remain linkable via a key.

  • ✗

    Pseudonymisation cannot be applied to structured data

    Why it's wrong here

    Pseudonymisation operates on structured records by replacing direct identifiers with tokens, so it applies readily to databases and tables. The claim inverts the technical position; it tempts because unstructured free-text is where tokenisation is hardest, and that scenario would justify different controls such as redaction or format-preserving encryption.

  • ✓

    Pseudonymised data is still considered personal data under GDPR

    Why this is correct

    Pseudonymisation replaces direct identifiers but retains a key enabling re-identification, so the data remains personal data under GDPR and its protections still apply. This limits the control: it reduces risk but does not remove the organisation's compliance obligations.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.