CDPSE · Domain 3
Data Life Cycle
About 23% of the exam
The personal data lifecycle
- Collect
- Store
- Use
- Share
- Retain
- Dispose
- Collect
- notice, purpose, lawful basis, minimum fields
- Store
- encrypt, access control, integrity, location
- Use
- purpose limitation, masked views, consent state
- Share
- agreement, transfer mechanism, riskiest stage
- Retain
- schedule, legal hold, restricted archive
- Dispose
- irreversible, verified, all copies
Classify at collection so every later stage inherits the right handling; the stages loop, they do not run once
Collection controls
- Notice at or before collection
- State the purpose before you collect
- Collect only what the purpose needs
- Optional fields marked and left unchecked
- Age bracket beats birthdate for age gating
- Record the lawful basis per flow
- Special categories need a clear necessity
- Metadata and logs are personal data too
Use and sharing
- New purpose: compatible or new basis
- Compatibility: link, context, nature, consequences, safeguards
- Minimize during use with role-based views
- Sharing agreement: purpose, security, retention, obligations
- Production data never lands in test
- Aggregate or pseudonymize for analytics
- Enforce current consent state at use
- Model training on personal data is a use
Retention and disposal
Retention schedule
- Period and trigger per data category
- Longest applicable legal duty wins
- Legal hold suspends the schedule
- Archive: restricted access, compliance only
- Automate enforcement, keep the evidence
- Review the schedule as laws change
Disposal
- Irreversible, method matched to media
- Crypto-shredding for cloud storage
- Certificates of destruction from vendors
- Backups, copies, exports included
- Anonymize instead when research value remains
- Erasure request vs legal duty: decline, explain
Kept because it might be useful is not a purpose; storage limitation ends identifiability when the purpose ends
States of personal data
- Identified
- direct identifiers present
- Pseudonymized
- key held apart, still personal data
- Anonymized
- irreversible by reasonably likely means
- Aggregated
- group statistics, watch small cells
- Synthetic
- fictitious records, test for memorization
- Masked
- obfuscated copy for lower environments
- Tokenized
- surrogate value, vault can reverse
- Derived
- combinations can raise sensitivity
Accuracy and quality
- Accuracy is a principle, not a nicety
- Wrong data harms the people it describes
- Quality indicators recorded in the inventory
- Corrections propagate to every downstream copy
- Freshness: update or dispose of stale data
- Version control on catalog entries
- Derived features tagged back to source
Data inventory versus ROPA
Data inventory
- Every personal data set the organization holds
- System, location, owner, classification
- Record counts to size the impact
- Storage and processing locations mandatory
- Retention period per entry
- Surfaces cross-border transfers automatically
Record of processing activities
- Organized around processing purposes
- Categories of subjects and data
- Recipients and third-country transfers
- Retention envisaged, security measures
- Processors keep their own record
- Joint controllers document the arrangement
The inventory answers where the data is; the ROPA answers why it is processed
Discovery and classification
- Pattern and regex scans on structured columns
- Content analysis for unstructured stores
- Rule-based labels applied automatically
- Human review for free-text fields
- Shadow data lives outside sanctioned systems
- Multi-cloud: different APIs, formats, access
- Labels drive access, encryption, retention
- Highest classification where laws differ
- Combination can elevate derived data
Keeping the inventory alive
- Automated scans plus change-triggered updates
- Reconcile entries against live discovery results
- Metric: entries reconciled within the period
- Connectors sync metadata from source systems
- Stewards validate the critical entries
- Different views for different audiences
- New databases enrolled into scope automatically
- Too coarse when unlike data shares a label
Lineage and mapping
- Lineage traces origin, movement, transformation
- Flow diagrams for each processing activity
- Shows downstream copies during a breach
- Finds every copy for a DSAR
- Consent scope documented on each flow
- Cross-border hops surfaced by location fields
- Feature stores inherit tags from source
Special situations
- Merger
- consent validity, purpose fit, harmonize retention
- Employee data
- longer retention, employment law, sensitivity
- AML versus storage limit
- legal duty retains, restrict processing
- Legal hold
- suspend deletion for those records only
- Trained model
- does it retain or reveal the person
- Debug logs
- collect less, purge sooner
- Research reuse
- anonymize or new basis
Lifecycle metrics
- Data subject request fulfillment time
- Records still held past retention
- Disposal verification rate
- Inventory reconciliation percentage
- Retention schedule adherence by system
- Shadow repositories found per scan
- Age of unresolved classification gaps
Know the order
- Classify at collection
- Store by label
- Use for the purpose
- Share under agreement
- Retain by schedule
- Dispose with proof
- Classification first, every control follows
- Legal hold overrides the schedule
- Legal duty overrides an erasure request
- Anonymize or delete, never keep just in case
Reference strip: stages, records, states, retention, discovery
Stages
- Collect: notice, purpose, minimum
- Store: encrypt, control, locate
- Use: purpose, masked views
- Share: agreement, riskiest stage
- Retain then dispose by schedule
Records
- Inventory: where the data is
- ROPA: purposes, categories, recipients
- Lineage: origin and transformations
- Flow diagrams per activity
Data states
- Pseudonymized is still personal
- Anonymized is irreversible
- Synthetic: check for memorization
- Tokenized: vault can reverse
Retention
- Longest legal duty wins
- Hold suspends deletion
- Archive restricted, compliance only
- Crypto-shred, certify, include backups
Discovery
- Scan structured and unstructured
- Shadow data outside sanctioned systems
- Labels drive downstream controls
- Reconcile scans with the inventory
Quick exam traps
- Trap: Pseudonymized data falls outside privacy law
- Trap: The ROPA and the data inventory are the same document
- Trap: An erasure request always overrides a legal retention period
- Trap: Keeping data for a possible future use satisfies minimization
- Trap: Hashing an email address anonymizes the record
- Trap: Production data in test is fine if access is restricted
- Trap: A completed inventory stays accurate without reconciliation
- Trap: Deleting the primary record completes disposal
cybercertprep.com · original revision sheet written from the public body of knowledge