CRISC Certified in Risk and Information Systems Control – Question841

A new international data privacy regulation requires personal data to be disposed after the specified retention period, which is different from the local regulatory requirement. Which of the following is the risk practitioner's BEST recommendation to resolve the disparity?

A.
Adopt the international standard.
B. Adopt the standard determined by legal counsel.
C. Adopt the local standard.
D. Adopt the least stringent standard determined by the risk committee.

Correct Answer: B