Question 1 of 30
Global Dynamics, a multinational corporation, is undergoing an internal audit of its Privacy Information Management System (PIMS) based on ISO 27701:2019. The audit reveals inconsistencies in how different departments handle data subject requests, specifically concerning the right to erasure (Article 17 of GDPR). The marketing department retains anonymized data derived from user profiles even after a deletion request, arguing it\'s no longer personally identifiable and is used for aggregate trend analysis. The legal department insists on complete deletion of all data, regardless of anonymization. The HR department retains employee data, even after a request for erasure, citing local labor laws.\n\nConsidering these inconsistencies and the requirements of ISO 27701:2019, which of the following actions should the internal auditor prioritize to ensure compliance with GDPR and effective implementation of the PIMS?
Conduct a comprehensive review of the legal basis for each department's data processing activities, balancing the right to erasure with legitimate interests and legal obligations, ensuring a consistent and documented policy based on legal review, Privacy Impact Assessments, and transparency with data subjects.
Mandate the legal department's interpretation of complete data deletion across all departments, overriding any claims of legitimate interest or legal obligation to ensure strict adherence to the right to erasure, simplifying the PIMS implementation and reducing potential legal risks.
Allow each department to maintain its current practices, as long as they can demonstrate a reasonable effort to comply with GDPR, fostering departmental autonomy and avoiding unnecessary disruption to established workflows, while documenting the variations in a central repository.
Implement a blanket policy of retaining all data for a fixed period, regardless of deletion requests or legal obligations, to minimize the risk of accidental data loss and ensure business continuity, while providing a generic privacy notice to data subjects explaining the data retention policy.

Preparing for ISO 14044:2006 Internal Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free