SY0-701 Question 462
Single answerA U.S.-based e-commerce company sells directly to customers in Germany, Brazil, and California. It uses a third-party cloud CRM to store customer profiles, order history, marketing preferences, and support tickets. A customer in Germany submits a request to have all personal data deleted. During the review, the security analyst finds that customer data also exists in the CRM, billing platform, marketing system, archived backups, and several old spreadsheets kept by sales staff. The company must meet legal obligations without deleting records it is required to retain for tax and fraud investigations. Which action should the company take FIRST to respond appropriately to this request?
- A
Immediately purge all records related to the customer from every system, including tax records and backup archives, to comply with the right to be forgotten
- B
Identify where the customer's personal data resides, determine which systems the company controls directly versus those handled by processors, and apply retention requirements before deleting eligible data
- C
Deny the request because the company is headquartered in the United States and is not subject to privacy requirements from other regions
- D
Ask the cloud CRM provider to handle the request independently because processors own the customer data once it is uploaded to their platform
Show answer and explanation
Correct answer: B
Explanation
The best first step is to establish a complete picture of the customer's personal data across the environment and map legal responsibility before taking action. This is a practical Security+ privacy scenario because successful handling depends on data inventory, retention, ownership and accountability, and understanding controller versus processor roles. Under the EU GDPR, a customer is a data subject, and the organization that determines the purposes and means of processing is the controller. Service providers that process data on behalf of the controller are processors. The right to be forgotten, more accurately the right to erasure under GDPR Article 17, is subject to exceptions, including compliance with legal obligations and establishment, exercise, or defense of legal claims. GDPR Article 5 also supports data minimization and storage limitation, which is why maintaining a current data inventory and retention schedule is essential. Similar obligations exist in other jurisdictions, though terminology and rights vary, such as Brazil's LGPD and California privacy laws. From a best-practice perspective, organizations should maintain records of processing activities, define retention periods, classify where regulated data resides, and ensure contracts with processors require support for data subject requests. In this scenario, the company should identify all repositories, validate which records must be retained, delete eligible data, and coordinate with processors to complete the request appropriately.
- A. Incorrect.
This is incorrect because privacy laws such as the GDPR do provide a right to erasure in many cases, but that right is not absolute. Organizations may need to retain some records for legal obligations such as taxation, accounting, litigation hold, or fraud prevention. Immediately deleting everything, especially from all backups and regulated records, can violate retention requirements and operational best practices.
- B. Correct.
This is correct because the company should first perform or consult a data inventory to identify all locations containing the data, determine roles and responsibilities between the controller and processors, and evaluate applicable retention obligations before deleting data that is eligible for erasure. In this scenario, the company decides the purposes and means of processing customer data, so it acts as the controller, while the cloud CRM is generally a processor acting on the company's behalf. This approach aligns with privacy compliance and sound incident-handling discipline.
- C. Incorrect.
This is incorrect because privacy obligations can apply based on where the data subjects are located and where goods or services are offered, not only where the company is headquartered. For example, the GDPR can apply to organizations outside the EU if they offer goods or services to individuals in the EU. Similar regional and national privacy requirements may also apply in Brazil and California.
- D. Incorrect.
This is incorrect because processors do not become the owners or primary decision-makers for the personal data simply by storing it. In most business arrangements, the company collecting customer data remains the controller and is responsible for responding to data subject requests, while instructing processors to assist as required by contract and law.