Which scenario poses the greatest privacy risk: lacking hardware disposal policy or unencrypted internal emails?

Which of the following scenarios poses the GREATEST risk to an organization from a privacy perspective?

  1. The organization lacks a hardware disposal policy.
  2. Emails are not consistently encrypted when sent internally. Source Reference Answer
  3. Privacy training is carried out by a service provider.
  4. The organization’s privacy policy has not been reviewed in over a year.

Community Votes

B
50%
A
50%

50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This item tests the data-lifecycle step of secure disposal and the candidate's ability to distinguish an insider-facing technical control (internal email encryption) from a physical exit pathway for PII.

In this CDPSE question, community votes are split 50/50 between a missing hardware disposal policy and inconsistent encryption of internal email. The strongest privacy-risk scenario is a lack of hardware disposal policy, because obsolete devices may leave the organization and expose personal data to unauthorized recovery.

Selecting B because encryption appears to be a strong technical privacy control overlooks the fact that the email is routed internally, where it remains inside the enterprise boundary; a hardware disposal gap, by contrast, lets physical media containing PII leave the organization without safeguards.

Community Discussion (4 comments)

821bbab 👍 1
A seems cool but I am going with B (Always wear the privacy hat in CDPSE). Failing to consistently encrypt emails, even when sent internally, poses a significant privacy risk. Sensitive personal information could be exposed if the emails are intercepted, either by internal actors or through unintended breaches in the organization's network. Without encryption, data in transit is vulnerable to unauthorized access, potentially leading to a serious breach of privacy and non-compliance with data protection regulations. Example, employees salaries excel sheet sent by mistake either internally or externally is severe privacy breach.
4dfe785 👍 2 Selected: A
Going with A on this one. B sounds cool... but the GREATEST risk to the organization should be "A"
Craigp990i 👍 2 Selected: B
B. Emails are not consistently encrypted when sent internally.
mmus 👍 1
A. The organization lacks a hardware disposal policy.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A is the greatest risk because a missing hardware disposal policy means no reliable control to ensure personal data on retired drives, laptops, and mobile devices is sanitized or destroyed. Privacy regulations, such as the GDPR's data minimization and security principles, require organizations to protect PII throughout its lifecycle, including disposal. Without the policy, devices are likely to be resold, recycled, or thrown away with recoverable data, potentially creating a large-scale breach and regulatory penalty. Thus, A is correct.

Why the Other Options Are Wrong

Option B focuses on unencrypted internal email, but these messages never leave the corporate network; encryption is most important for external transmissions. Option C says training is outsourced but does not state that training is inadequate or that personal data is exposed. Option D involves a governance lag but does not itself equate to exposure of personal information or a likely privacy incident. B, C, and D are all less immediate and lower-impact than losing track of physical hardware that may contain large volumes of PII.

Community Comment Notes

Commenters favoring A point out that although encryption 'sounds cool,' the greatest privacy risk to the organization comes from hardware disposal. Those citing B emphasize the danger of intercepted email containing sensitive personal information, but their reasoning assumes an external threat to an internal email channel. Comment 1 and comment 4 align with the correct option A, while the B rationale overlooks the boundary risk in hardware disposal.

Official Reference

Exam Strategy

When you see 'GREATEST risk' in privacy questions, rank options by probability and impact of a personal-data incident, not by name recognition of a security control. Choice B sounds compelling, but internal email remains inside the network; A causes a physical and legal exposure when data leaves the organization, so match the option that maps to the full data life cycle.

Related Analysis

Practice All CDPSE Questions

Access 229 questions with complete answers and detailed explanations.

View Full CDPSE Practice Test →

← Back to CDPSE Study Guide