Question 1 of 30
GlobalTech Solutions, a multinational corporation with operations in the EU, US, and China, is implementing ISO 27701 to manage privacy information. A core challenge arises from the \"right to erasure\" (right to be forgotten) under GDPR, which conflicts with local data retention laws in certain jurisdictions. For instance, Chinese cybersecurity law mandates specific data retention periods for certain types of data, even if a data subject requests its erasure. GlobalTech\'s data processing includes marketing, customer service, and R&D. An internal auditor is tasked with assessing the effectiveness of GlobalTech\'s approach to handling data subject requests for erasure across these diverse legal landscapes, within the framework of ISO 27701. Which of the following approaches would best demonstrate compliance with ISO 27701 in this complex scenario?
Conduct a legal assessment of data retention requirements in each jurisdiction, develop a documented process for handling erasure requests that balances GDPR with local laws, communicate limitations to data subjects, implement technical measures for erasure/anonymization, and establish a governance structure for accountability.
Prioritize GDPR compliance above all else, erase all data upon request regardless of local laws, and accept potential legal penalties in non-EU jurisdictions as a cost of doing business.
Ignore GDPR requirements in non-EU jurisdictions, comply solely with local data retention laws, and only honor erasure requests from EU residents.
Implement a blanket data retention policy across all jurisdictions, retaining all data for the maximum period allowed under any applicable law to minimize legal risk, regardless of data subject requests.

Preparing for ISO 39001:2012 Internal Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free