Courseiva
Asset SecuritymediumMultiple SelectObjective-mapped

CISSP Asset Security Practice Question

An organization is developing a new application that collects and processes European customers' personal data. To comply with the privacy by design principles under GDPR, which THREE measures should be implemented? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Retain the data only as long as necessary to fulfill the purpose (storage limitation)

Privacy by design principles include data minimization (collect only necessary data), purpose limitation (use data only for specified purpose), and storage limitation (retain data only as long as needed). Encryption is a security measure, not a privacy by design principle. Consent is important but not a design principle per se.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Retain the data only as long as necessary to fulfill the purpose (storage limitation)

    Why this is correct

    Storage limitation is a critical Privacy by Design principle requiring that personal data be retained only for the duration strictly necessary to fulfill the purpose for which it was collected. This principle prevents indefinite data retention, thereby reducing the long-term risk associated with holding sensitive information. Implementing robust data retention policies and automated deletion mechanisms directly into system architecture ensures compliance and mitigates future privacy liabilities.

  • Encrypt all personal data at rest and in transit

    Why it's wrong here

    While encryption is an indispensable security control for protecting personal data both at rest and in transit, it is not considered a core Privacy by Design principle itself. Encryption primarily addresses data confidentiality and integrity, acting as a technical safeguard against unauthorized access and breaches. Privacy by Design principles, conversely, focus on foundational design choices regarding data collection, use, and retention, aiming to prevent privacy harms proactively rather than merely securing data after collection.

  • Use the data only for the purpose for which it was collected (purpose limitation)

    Why this is correct

    Purpose limitation is a core Privacy by Design principle dictating that personal data, once collected, must only be used for the specific, explicit, and legitimate purpose for which it was originally obtained. This principle prevents scope creep and unauthorized secondary uses of data, ensuring transparency and maintaining user trust. By embedding this restriction into system design, organizations proactively prevent data misuse and uphold their commitment to privacy.

  • Obtain explicit consent from users before data collection

    Why it's wrong here

    Obtaining explicit consent from users before data collection is a legal basis for processing personal data, often mandated by regulations like GDPR, but it is not a Privacy by Design principle. Privacy by Design focuses on embedding privacy safeguards directly into the system's architecture and operational processes, irrespective of the specific legal justification for processing. While crucial for compliance, consent is an external legal requirement rather than an inherent design philosophy for data handling.

  • Collect only the personal data necessary for the specified purpose (data minimization)

    Why this is correct

    Data minimization is a foundational Privacy by Design principle that mandates collecting only the absolute minimum amount of personal data required to achieve a specified, legitimate purpose. This proactive approach significantly reduces the potential impact of a data breach by limiting the sensitive information an attacker could access. By embedding this principle into application design, organizations inherently lower their risk profile and enhance user privacy from the outset, making privacy the default.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.