An auditor is scoping an engagement over a customer relationship system that stores personal data. To frame the data privacy risk correctly for planning, which statement best captures the core data privacy concept the auditor should apply?
- APersonal data should be collected and processed only for specified, legitimate purposes and limited to what those purposes require. Correct
- BPersonal data should be encrypted at rest and in transit so that a network intruder who intercepts it cannot read the contents.
- CPersonal data should be retained indefinitely so that the organisation can always respond to any future regulator or customer request.
- DPersonal data should be made available across all internal departments to maximise the business value the organisation extracts from it.
Why A is correct: Correct because purpose limitation and data minimisation are foundational privacy principles, so the auditor frames the risk around whether collection and use stay within the stated legitimate purpose.
Why B is wrong: Tempting because encryption protects data, but it is a security safeguard supporting confidentiality rather than the privacy principle governing why and how much personal data may be collected and used.
Why C is wrong: Tempting because retention supports responsiveness, but indefinite retention conflicts with storage limitation and increases privacy exposure, so it misstates the underlying privacy concept.
Why D is wrong: Tempting because data sharing can create value, but broad internal availability conflicts with access restriction and purpose limitation, increasing rather than controlling privacy risk.