CCSP Legal, Risk, and Compliance Practice Question
A U.S. financial services firm uses a cloud provider with data centers in the EU. The firm must comply with both SEC regulations requiring books and records preservation and the GDPR. A data subject requests erasure of personal data that is also subject to a legal hold. What should the firm do?
⚠ Common exam trap
The trap here is assuming either that GDPR erasure always overrides legal holds or that legal holds always override erasure; the correct approach requires scoping and balancing both obligations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assess the scope of the legal hold, retain only the data subject to the hold under restricted processing, and erase or anonymize other personal data as required by the GDPR request.
When GDPR erasure requests conflict with legal holds, the firm must apply GDPR Article 17(3)(b), which permits retention when necessary to comply with a legal obligation. The correct approach is to scope the hold, retain only the data subject to it under restricted processing, and erase or anonymize the rest. This satisfies both the legal hold and the data subject's rights to the extent possible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately erase all personal data to comply with the GDPR erasure request, because data subject rights override legal retention obligations.
Why it's wrong here
GDPR Article 17(3)(b) allows processing to continue when necessary for compliance with a legal obligation. SEC books and records rules require retention, creating a legal obligation that can override erasure. Erasing data subject to a legal hold could constitute spoliation of evidence and violate SEC regulations. The firm must balance obligations and cannot simply prioritize erasure.
- ✓
Assess the scope of the legal hold, retain only the data subject to the hold under restricted processing, and erase or anonymize other personal data as required by the GDPR request.
Why this is correct
This approach respects both regimes. GDPR Article 17(3)(b) permits retention when necessary for legal obligations, but the firm should limit retention to data actually subject to the hold and restrict its processing. Data outside the hold should be erased or anonymized to satisfy the erasure request. This balanced, documented approach is the legally sound method for conflicting obligations.
- ✗
Transfer all personal data to a third country outside the EU to avoid GDPR jurisdiction, then erase it there.
Why it's wrong here
Transferring data to evade GDPR jurisdiction does not eliminate the obligation; GDPR applies to processing of EU data subjects' personal data regardless of location, and transfers must still comply with Chapter V. This action could also violate the legal hold and SEC rules, and may constitute an unlawful transfer. It does not resolve the conflict and introduces additional legal risk.
- ✗
Deny the erasure request entirely and retain all data indefinitely, because legal holds always supersede data subject rights.
Why it's wrong here
This is overly broad. GDPR erasure rights are not absolute, but they also are not entirely negated by a legal hold. The firm should erase data not subject to the hold and restrict processing of held data to the extent necessary. Denying the request entirely and retaining all data indefinitely would violate GDPR principles such as storage limitation and could lead to regulatory penalties.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.