Question 1 of 27
A financial services company is implementing a data retention policy to comply with regulatory requirements. They need to ensure that customer transaction data is retained for a minimum of 7 years, while also allowing for the deletion of data that is no longer necessary for business operations. The company has a mix of structured and unstructured data, and they are considering various retention strategies. Which approach best aligns with the principles of data retention policies while ensuring compliance and operational efficiency?
Implement a tiered data retention policy that categorizes data based on its importance and usage frequency, retaining critical transaction data for 7 years and archiving less critical data for a shorter duration.
Retain all customer transaction data indefinitely to avoid any risk of non-compliance with regulations.
Delete all customer transaction data after 3 years to minimize storage costs, regardless of regulatory requirements.
Retain customer transaction data for 5 years and then anonymize it, assuming this meets compliance requirements.