Question

Difficulty: EasyData Governance, Classification, and Privacy Controls

An enterprise security team is defining fundamental data governance and privacy requirements for a new corporate application. Match each data governance concept on the left with its corresponding operational description on the right.

  • Data SovereigntySubjecting stored data to the privacy laws and regulatory jurisdiction of the geographic location where it resides.
  • Data MinimizationCollecting and processing only the personal information strictly necessary to fulfill a specific, authorized purpose.
  • Data AnonymizationIrreversibly removing all personally identifiable attributes so that the individual data subject cannot be re-identified.
  • Data Retention PolicyEstablishing operational timelines for storing records to comply with legal mandates and securely destroying them when expired.

Answer

Data Sovereignty pairs with subjecting data to local laws where stored; Data Minimization pairs with collecting only strictly necessary data; Data Anonymization pairs with irreversibly removing identifiable attributes; Data Retention Policy pairs with establishing storage timelines and disposal schedules.
Each concept directly aligns with its fundamental security requirement: Data Sovereignty relates to legal jurisdiction based on physical storage location; Data Minimization enforces collecting only what is strictly necessary; Data Anonymization irreversibly removes PII; and Data Retention Policies specify holding periods and secure destruction.

Step-by-Step Solution

1
Identify the core objective of Data Sovereignty
Recognize that legal jurisdiction over data depends on geographic physical location.
Sovereignty relates directly to national boundaries and regional data privacy compliance laws.
2
Identify the core objective of Data Minimization
Recognize the constraint to restrict collection to minimal required fields.
Minimization reduces risk exposure by preventing superfluous collection of sensitive user information.
3
Identify the core objective of Data Anonymization
Recognize irreversible destruction of identity markers.
Unlike pseudonymization, true anonymization cannot be reversed to expose personal identities.
4
Identify the core objective of a Data Retention Policy
Recognize lifecycle rules governing how long data stays in storage and when it must be purged.
Retention policies balance compliance obligations with risk reduction through timely data destruction.

Key Concept

Data Governance, Classification, and Privacy Controls

Practice More

Review how data pseudonymization differs from data anonymization under GDPR and modern privacy standards.
Estimated Time:1m 0s
Rate this question