How should a debt collection agency decide data is adequate, relevant, and limited?
A debt collection agency is attempting to locate a debtor and collects information on several people with similar names. During the inquiry, some of these people are discounted. How should the agency decide what data is adequate, relevant, and limited?
Community Votes
50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests whether you understand that data minimisation does not automatically mean deleting all data in every case; organisations may retain a minimal record to show reasonable processing and handle complaints.
For CDPSE, the correct answer is to keep only the minimum data needed to form a basic record of people discounted from a debtor search, matching ICO data minimisation guidance. Community comments highlight the ICO's explicit example of this scenario.
Choosing B, 'delete all personal data collected after the debtor is found', is the most common mistake because it overstates the requirement. The ICO example specifically says the agency 'should delete most of their personal data', not all, while keeping enough for a basic record and accountability.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A is correct because it aligns with the ICO's data minimisation example, cited in comment [2], which says the agency should keep only enough personal data to form a basic record of excluded individuals. This allows the agency to demonstrate it acted reasonably and to comply with its complaints procedure. The phrase 'minimum data needed' directly reflects the principle that personal data must be 'limited to what is necessary' under GDPR Article 5(1)(c). Comments [1] and [3] also support A, reinforcing that the correct approach is retaining a minimal record rather than nothing at all.
Why the Other Options Are Wrong
Option B is too absolute because deleting all personal data after the debtor is found would leave the agency unable to show why certain people were investigated and discounted, which may be needed for complaints or legal defence. Option C, anonymising the data, changes its nature and may not serve the legitimate need to have a basic record that can be linked to the specific individuals excluded. Option D, keeping the full data with an indication, is excessive and violates data minimisation because full records are not necessary once a person is discounted. Each wrong option either over-retains data or under-retains accountability evidence.
Community Comment Notes
Comment [2] is the most useful because it quotes the ICO's direct example for this exact scenario, indicating that 'most' information should be deleted, not 'all'. Comments [1] and [3] agree with A but provide less reasoning. Together they show consensus that while minimisation requires deleting most personal data, a minimal 'basic record' is acceptable and even necessary for governance and complaint handling. This nuanced point is essential for CDPSE exam takers to understand.
Official Reference
Exam Strategy
Watch for absolutes like 'delete all' or 'keep all'; data minimisation questions often require a balanced 'delete most, keep minimum' answer. If an option mentions retaining just enough to show reasonable processing or support complaints, that is usually the correct expression of the principle.
Related Analysis
Practice All CDPSE Questions
Access 229 questions with complete answers and detailed explanations.
View Full CDPSE Practice Test →