Under the GDPR purpose-limitation principle, which practice best helps an organization remain compliant when it designs an online form to collect personal data from customers?
Request every piece of information that could be useful in future projects, provided the data is stored securely.
Rely on the corporate privacy policy alone and omit purpose statements on the form to avoid confusing customers.
Use a blanket consent statement that allows the organization to repurpose the data for any future processing.
Document and disclose, before collection, exactly which personal data will be collected and the legitimate purposes for each field.
Documenting and disclosing, in advance, the exact personal data fields and the specific lawful purposes for each satisfies the GDPR's requirement that data be collected only for "specified, explicit and legitimate purposes." This transparency lets data subjects understand how their information will be used and allows auditors to verify compliance. The other choices either encourage collecting data 'just in case,' rely on blanket consent for undefined future uses, or omit purpose statements altogether-all of which breach the purpose-limitation and transparency obligations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the GDPR purpose-limitation principle?
Open an interactive chat with Bash
Why is documenting and disclosing data collection purposes important?
Open an interactive chat with Bash
What happens if an organization uses blanket consent forms?
Open an interactive chat with Bash
ISC2 CISSP
Asset Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .