Bird
0
0

How should a company handle a data subject's request to erase their personal data under GDPR?

hard🧠 Conceptual Q9 of 15
Cybersecurity - Compliance and Governance
How should a company handle a data subject's request to erase their personal data under GDPR?
AIgnore the request if it is inconvenient
BErase data promptly unless there is a legal reason to retain it
CCharge a fee to process the erasure request
DDelete only data that is older than five years
Step-by-Step Solution
Solution:
  1. Step 1: Understand GDPR right to erasure

    GDPR grants individuals the right to have their personal data erased promptly unless exceptions apply.
  2. Step 2: Evaluate options

    Only Erase data promptly unless there is a legal reason to retain it aligns with GDPR's right to erasure, which must be fulfilled without undue delay unless legal grounds require retention. Ignoring requests, charging fees, or limiting by age violate GDPR.
  3. Final Answer:

    Erase data promptly unless there is a legal reason to retain it -> Option B
  4. Quick Check:

    GDPR erasure = Prompt unless legal reason [OK]
Quick Trick: Erase data promptly unless law says keep [OK]
Common Mistakes:
MISTAKES
  • Ignoring erasure requests
  • Charging fees for erasure
  • Deleting data based on age only

Want More Practice?

15+ quiz questions · All difficulty levels · Free

Free Signup - Practice All Questions
More Cybersecurity Quizzes