Courseiva

CCSP Legal, Risk, and Compliance Practice Question

A U.S. financial services firm uses a cloud provider with data centers in the EU. The firm must comply with both SEC regulations requiring books and records preservation and the GDPR. A data subject requests erasure of personal data that is also subject to a legal hold. What should the firm do?

⚠ Common exam trap

The trap here is assuming either that GDPR erasure always overrides legal holds or that legal holds always override erasure; the correct approach requires scoping and balancing both obligations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assess the scope of the legal hold, retain only the data subject to the hold under restricted processing, and erase or anonymize other personal data as required by the GDPR request.

When GDPR erasure requests conflict with legal holds, the firm must apply GDPR Article 17(3)(b), which permits retention when necessary to comply with a legal obligation. The correct approach is to scope the hold, retain only the data subject to it under restricted processing, and erase or anonymize the rest. This satisfies both the legal hold and the data subject's rights to the extent possible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately erase all personal data to comply with the GDPR erasure request, because data subject rights override legal retention obligations.

    Why it's wrong here

    GDPR Article 17(3)(b) allows processing to continue when necessary for compliance with a legal obligation. SEC books and records rules require retention, creating a legal obligation that can override erasure. Erasing data subject to a legal hold could constitute spoliation of evidence and violate SEC regulations. The firm must balance obligations and cannot simply prioritize erasure.

  • ✓

    Assess the scope of the legal hold, retain only the data subject to the hold under restricted processing, and erase or anonymize other personal data as required by the GDPR request.

    Why this is correct

    This approach respects both regimes. GDPR Article 17(3)(b) permits retention when necessary for legal obligations, but the firm should limit retention to data actually subject to the hold and restrict its processing. Data outside the hold should be erased or anonymized to satisfy the erasure request. This balanced, documented approach is the legally sound method for conflicting obligations.

  • ✗

    Transfer all personal data to a third country outside the EU to avoid GDPR jurisdiction, then erase it there.

    Why it's wrong here

    Transferring data to evade GDPR jurisdiction does not eliminate the obligation; GDPR applies to processing of EU data subjects' personal data regardless of location, and transfers must still comply with Chapter V. This action could also violate the legal hold and SEC rules, and may constitute an unlawful transfer. It does not resolve the conflict and introduces additional legal risk.

  • ✗

    Deny the erasure request entirely and retain all data indefinitely, because legal holds always supersede data subject rights.

    Why it's wrong here

    This is overly broad. GDPR erasure rights are not absolute, but they also are not entirely negated by a legal hold. The firm should erase data not subject to the hold and restrict processing of held data to the extent necessary. Denying the request entirely and retaining all data indefinitely would violate GDPR principles such as storage limitation and could lead to regulatory penalties.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.