Which GDPR principle emphasizes collecting only data that is necessary for a stated purpose?

Prepare for the Cybercrime Test with comprehensive coverage of real-world scenarios, various security domains, and expert techniques. Enhance your knowledge with flashcards and extensive question explanations. Ace your exam confidently!

Multiple Choice

Which GDPR principle emphasizes collecting only data that is necessary for a stated purpose?

Explanation:
Data minimization means collecting only what is necessary for the stated purpose. Under GDPR, data should be adequate, relevant, and limited to what is necessary in relation to how it will be processed. This keeps exposure and risk low and makes it easier to justify data collection to individuals and regulators. For example, if you’re processing for sending an invoice, you typically need just the name and contact details required to deliver it; collecting extra, unrelated information isn’t justified. The other options address different aspects of GDPR: data retention is about how long you keep data, data openness (transparency) is about informing individuals how their data will be used, and data replication isn’t a GDPR principle.

Data minimization means collecting only what is necessary for the stated purpose. Under GDPR, data should be adequate, relevant, and limited to what is necessary in relation to how it will be processed. This keeps exposure and risk low and makes it easier to justify data collection to individuals and regulators. For example, if you’re processing for sending an invoice, you typically need just the name and contact details required to deliver it; collecting extra, unrelated information isn’t justified. The other options address different aspects of GDPR: data retention is about how long you keep data, data openness (transparency) is about informing individuals how their data will be used, and data replication isn’t a GDPR principle.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy