easyMultiple SelectObjective-mapped
CISSP Practice Question: Which TWO of the following are principles of the…
Which TWO of the following are principles of the data minimization concept under privacy regulations such as GDPR?
⚠ Common exam trap
ISC2 often tests the distinction between the seven GDPR principles (lawfulness, fairness, transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability) and the data subject rights (access, rectification, erasure, etc.), so candidates mistakenly select a right like access as a minimization principle.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Collect only the personal data that is directly relevant and necessary for the specified purpose
Data minimization under GDPR (Article 5(1)(c)) requires that personal data collected be 'adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.' This principle directly mandates collecting only the data that is directly relevant and necessary for the specified purpose, preventing over-collection and reducing privacy risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure personal data is accurate and kept up to date
Why it's wrong here
This statement describes the "Accuracy" principle, which mandates that personal data must be accurate and, where necessary, kept up to date throughout its lifecycle. While crucial for maintaining data integrity, ensuring fairness to data subjects, and supporting reliable decision-making, it is distinct from data minimization, which focuses on limiting the volume and scope of data collected and processed in the first place, rather than its quality after collection.
- ✓
Collect only the personal data that is directly relevant and necessary for the specified purpose
Why this is correct
This option directly reflects a core aspect of data minimization, which dictates that organizations should only collect personal data that is absolutely essential and directly pertinent to achieving a clearly defined, legitimate purpose. By restricting initial data acquisition to the minimum required, it prevents unnecessary accumulation, reduces the potential attack surface, and mitigates privacy risks associated with holding excessive or irrelevant data.
- ✗
Store personal data for as long as possible for future analysis
Why it's wrong here
Storing personal data "as long as possible" directly contradicts both the principle of data minimization and the related principle of storage limitation. Data minimization requires that data retention periods be strictly limited to what is necessary for the original specified purpose, or for legal/regulatory obligations, thereby preventing indefinite storage and reducing long-term risk exposure. Indefinite retention for speculative future analysis is a clear violation of these principles.
- ✓
Limit the processing of personal data to only what is necessary for the intended purpose
Why this is correct
This statement accurately describes another critical facet of data minimization, emphasizing that even after collection, the subsequent processing activities involving personal data must be strictly limited to what is genuinely necessary to fulfill the explicitly stated and legitimate purpose. This includes restricting access, operations, and sharing of data, ensuring that data is not used or exposed beyond its intended scope, thereby minimizing privacy impact and potential misuse.
- ✗
Provide individuals with access to their data upon request
Why it's wrong here
Providing individuals with access to their data upon request is a fundamental aspect of data subject rights, specifically the "Right of Access," which empowers individuals to review their personal information held by an organization. While vital for transparency, accountability, and enabling other rights like rectification, this principle is separate from data minimization, which focuses on reducing the volume and scope of data collected and processed from the outset, rather than managing access to existing data.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Privacy
Privacy in IT is the control over how personal data is collected, stored, used, and shared by systems and organizations.
Key term
GDPR
The General Data Protection Regulation (GDPR) is a European Union law that sets strict rules for how organizations collect, store, process, and protect the personal data of individuals within the EU.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.