Question 1 of 30
In a multinational corporation, the data protection policy is being revised to comply with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). The policy must ensure that personal data is collected, processed, and stored in a manner that respects user privacy and complies with legal requirements. If the company decides to implement a data minimization principle, which of the following actions best aligns with this principle while also ensuring compliance with both regulations?
Collect only the personal data necessary for the specific purpose of processing and ensure that data is anonymized when no longer needed.
Gather extensive personal data to enhance customer profiling and marketing strategies, assuming users will opt-out if they wish.
Retain all collected personal data indefinitely to facilitate future analysis and business intelligence.
Implement a blanket consent policy that allows for the collection of all types of personal data without specifying the purpose.

Preparing for CISCO 500-651 Security Architecture for Systems Engineer (SASE)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free