ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A retailer collected customers' addresses and payment details solely to process online orders. Months later, the analytics team proposes using the same dataset to build targeted advertising campaigns. According to fundamental privacy concepts, which action should the privacy officer take first?
Hash all customer names and email addresses before running the advertising analytics.
Retain the purchase records indefinitely to cover any potential future business or legal needs.
Move the data into a dedicated analytics environment protected by stricter access controls.
Verify that the advertising use aligns with the original collection purpose and seek additional customer consent if it does not.
Privacy principles such as purpose limitation and lawful processing require that personal information be used only for the purpose originally stated at the time of collection. Before any technical safeguards or extended retention are considered, the organization must determine whether the proposed advertising use is compatible with the original purpose. If it is not, the privacy officer must obtain fresh, informed customer consent or supply an updated notice before processing begins. Hashing names, relocating data, or extending retention may be useful safeguards but do not satisfy the primary obligation to ensure an appropriate legal basis for the new use.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is purpose limitation in privacy principles?
Open an interactive chat with Bash
How does informed consent apply to data usage changes?
Open an interactive chat with Bash
What are lawful processing requirements for personal data?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .