Which GDPR principle emphasizes collecting only data that is necessary for a stated purpose?

Enhance your knowledge of cybercrime with essential study materials. Prepare with dynamic flashcards and multiple-choice questions, each offering insightful hints and explanations. Equip yourself to excel in the cybercrime exam!

Multiple Choice

Which GDPR principle emphasizes collecting only data that is necessary for a stated purpose?

Explanation:
Data minimization means collecting only what is necessary for the stated purpose. Under GDPR, data should be adequate, relevant, and limited to what is necessary in relation to how it will be processed. This keeps exposure and risk low and makes it easier to justify data collection to individuals and regulators. For example, if you’re processing for sending an invoice, you typically need just the name and contact details required to deliver it; collecting extra, unrelated information isn’t justified. The other options address different aspects of GDPR: data retention is about how long you keep data, data openness (transparency) is about informing individuals how their data will be used, and data replication isn’t a GDPR principle.

Data minimization means collecting only what is necessary for the stated purpose. Under GDPR, data should be adequate, relevant, and limited to what is necessary in relation to how it will be processed. This keeps exposure and risk low and makes it easier to justify data collection to individuals and regulators. For example, if you’re processing for sending an invoice, you typically need just the name and contact details required to deliver it; collecting extra, unrelated information isn’t justified. The other options address different aspects of GDPR: data retention is about how long you keep data, data openness (transparency) is about informing individuals how their data will be used, and data replication isn’t a GDPR principle.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy