A bank discovers that backups of decommissioned customer accounts are retained indefinitely on tape because no rule defines when they should be destroyed. A risk practitioner is advising on how to manage privacy risk at the disposal stage of the data lifecycle. Which control would most directly reduce the privacy risk created by this practice?
- AEncrypt every backup tape at rest so that any personal data on the retained media stays unreadable to anyone without the decryption key.
- BMove the backup tapes to an off-site vault with stricter physical access controls than the current on-premises tape library provides.
- CCatalogue each backup tape in an asset register so the bank always knows which decommissioned accounts are stored on which media.
- DDefine and enforce a retention schedule with secure disposal so personal data is destroyed once its lawful retention period ends. Correct
Why A is wrong: Encryption protects confidentiality of the tapes and feels like a strong fix, but it leaves the data in existence indefinitely, so it does not address the disposal failure driving the risk.
Why B is wrong: Tighter physical access reduces theft risk and sounds prudent, yet the underlying problem is that the data is never disposed of, which relocation does nothing to solve.
Why C is wrong: An accurate inventory improves visibility and is worth having, but knowing where data sits does not trigger its destruction, so the indefinite retention risk remains.
Why D is correct: A retention schedule with secure disposal sets when data must be destroyed and enforces it, removing the indefinitely held records that create the privacy exposure at end of life.