How should a debt collection agency decide data is adequate, relevant, and limited?

A debt collection agency is attempting to locate a debtor and collects information on several people with similar names. During the inquiry, some of these people are discounted. How should the agency decide what data is adequate, relevant, and limited?

  1. The agency should keep only the minimum data needed to form a basic record of people removed from the search. Source Reference Answer
  2. The agency should delete all personal data collected after the debtor is found.
  3. The agency should keep the data collected but store in an anonymized format.
  4. The agency should keep the data collected and mark an indication on the people removed from the search.

Community Votes

A
50%
B
50%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests whether you understand that data minimisation does not automatically mean deleting all data in every case; organisations may retain a minimal record to show reasonable processing and handle complaints.

For CDPSE, the correct answer is to keep only the minimum data needed to form a basic record of people discounted from a debtor search, matching ICO data minimisation guidance. Community comments highlight the ICO's explicit example of this scenario.

Choosing B, 'delete all personal data collected after the debtor is found', is the most common mistake because it overstates the requirement. The ICO example specifically says the agency 'should delete most of their personal data', not all, while keeping enough for a basic record and accountability.

Community Discussion (3 comments)

gctejwani 👍 1 Selected: B
The ICO explicitly provides an example that directly addresses this scenario: "A debt collection agency is engaged to find a particular debtor. It collects information on several people with a similar name to the debtor. During the enquiry some of these people are discounted. The agency should delete most of their personal data"
Craigp990i 👍 1 Selected: A
A. The agency should keep only the minimum data needed to form a basic record of people removed from the search.
shiowbah 👍 2
A. The agency should keep only the minimum data needed to form a basic record of people removed from the search.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A is correct because it aligns with the ICO's data minimisation example, cited in comment [2], which says the agency should keep only enough personal data to form a basic record of excluded individuals. This allows the agency to demonstrate it acted reasonably and to comply with its complaints procedure. The phrase 'minimum data needed' directly reflects the principle that personal data must be 'limited to what is necessary' under GDPR Article 5(1)(c). Comments [1] and [3] also support A, reinforcing that the correct approach is retaining a minimal record rather than nothing at all.

Why the Other Options Are Wrong

Option B is too absolute because deleting all personal data after the debtor is found would leave the agency unable to show why certain people were investigated and discounted, which may be needed for complaints or legal defence. Option C, anonymising the data, changes its nature and may not serve the legitimate need to have a basic record that can be linked to the specific individuals excluded. Option D, keeping the full data with an indication, is excessive and violates data minimisation because full records are not necessary once a person is discounted. Each wrong option either over-retains data or under-retains accountability evidence.

Community Comment Notes

Comment [2] is the most useful because it quotes the ICO's direct example for this exact scenario, indicating that 'most' information should be deleted, not 'all'. Comments [1] and [3] agree with A but provide less reasoning. Together they show consensus that while minimisation requires deleting most personal data, a minimal 'basic record' is acceptable and even necessary for governance and complaint handling. This nuanced point is essential for CDPSE exam takers to understand.

Official Reference

Exam Strategy

Watch for absolutes like 'delete all' or 'keep all'; data minimisation questions often require a balanced 'delete most, keep minimum' answer. If an option mentions retaining just enough to show reasonable processing or support complaints, that is usually the correct expression of the principle.

Related Analysis

Practice All CDPSE Questions

Access 229 questions with complete answers and detailed explanations.

View Full CDPSE Practice Test →

← Back to CDPSE Study Guide