Implement a data retention policy to manage personal information - This is correct. A data retention policy ensures businesses handle personal information responsibly by defining how long data is retained, when it is deleted, and how it is protected. This is a standard requirement in compliance with privacy regulations like GDPR, HIPAA, and CCPA.
Discard all personal information after initial use - Discarding personal information immediately after use is often impractical, as businesses may need the data for ongoing operations, compliance, or future references, as permitted by law.
Limit access to data only during working hours - While access controls are crucial, limiting access based solely on working hours is not a common requirement and does not address broader security and compliance needs.
Store personal information on public servers for easy access - Storing personal information on public servers poses significant security and privacy risks and violates most data protection regulations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are privacy regulations like GDPR, HIPAA, and CCPA?
Open an interactive chat with Bash
What should be included in a data retention policy?
Open an interactive chat with Bash
What are the risks of storing personal information on public servers?