Question 1 of 30
GlobalTech Solutions, a multinational corporation with operations in the EU and the US, is implementing ISO 27701:2019 to enhance its privacy information management system (PIMS). As part of the implementation, the company is addressing the management of data subject rights, specifically the \"right to erasure\" (right to be forgotten) under GDPR. GlobalTech processes personal data of EU citizens and needs to ensure a compliant and efficient process for handling erasure requests. The legal department has flagged concerns about potential legal holds on certain data. Considering the requirements of ISO 27701:2019 and GDPR, which approach would be the MOST effective for GlobalTech to manage data subject requests for erasure while maintaining compliance and addressing legal hold requirements?
Implement a centralized system for receiving and validating erasure requests, including a verification process to confirm the requestor's identity. Automate the deletion process where possible, but incorporate a mechanism to identify and preserve data subject to legal holds. Document all erasure requests, validations, and actions taken for audit purposes.
Implement an automated data deletion process that automatically removes all data associated with a data subject upon receiving an erasure request, without considering potential legal holds or identity verification.
Delegate the responsibility of handling erasure requests to individual departments, allowing each department to manage requests independently based on their internal procedures.
Rely on a manual process where erasure requests are handled by the IT department without specific guidelines or documentation, relying on the IT staff's discretion to determine which data to delete.

Preparing for ISO 14044:2006 Internal Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free