CPA · Question 77 · Area II: Security
An auditor is reviewing the 'Data Retention Policy'. The policy states that customer data is deleted after 7 years. However, the auditor finds backups containing 10-year-old data. This is a violation of which GDPR principle?
Answer options:
Accuracy
Storage Limitation
Integrity and Confidentiality
Lawfulness
82 questions · hints · full answers · grading