Which scenario poses the greatest privacy risk: lacking hardware disposal policy or unencrypted internal emails?
Which of the following scenarios poses the GREATEST risk to an organization from a privacy perspective?
Community Votes
50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This item tests the data-lifecycle step of secure disposal and the candidate's ability to distinguish an insider-facing technical control (internal email encryption) from a physical exit pathway for PII.
In this CDPSE question, community votes are split 50/50 between a missing hardware disposal policy and inconsistent encryption of internal email. The strongest privacy-risk scenario is a lack of hardware disposal policy, because obsolete devices may leave the organization and expose personal data to unauthorized recovery.
Selecting B because encryption appears to be a strong technical privacy control overlooks the fact that the email is routed internally, where it remains inside the enterprise boundary; a hardware disposal gap, by contrast, lets physical media containing PII leave the organization without safeguards.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A is the greatest risk because a missing hardware disposal policy means no reliable control to ensure personal data on retired drives, laptops, and mobile devices is sanitized or destroyed. Privacy regulations, such as the GDPR's data minimization and security principles, require organizations to protect PII throughout its lifecycle, including disposal. Without the policy, devices are likely to be resold, recycled, or thrown away with recoverable data, potentially creating a large-scale breach and regulatory penalty. Thus, A is correct.
Why the Other Options Are Wrong
Option B focuses on unencrypted internal email, but these messages never leave the corporate network; encryption is most important for external transmissions. Option C says training is outsourced but does not state that training is inadequate or that personal data is exposed. Option D involves a governance lag but does not itself equate to exposure of personal information or a likely privacy incident. B, C, and D are all less immediate and lower-impact than losing track of physical hardware that may contain large volumes of PII.
Community Comment Notes
Commenters favoring A point out that although encryption 'sounds cool,' the greatest privacy risk to the organization comes from hardware disposal. Those citing B emphasize the danger of intercepted email containing sensitive personal information, but their reasoning assumes an external threat to an internal email channel. Comment 1 and comment 4 align with the correct option A, while the B rationale overlooks the boundary risk in hardware disposal.
Official Reference
Exam Strategy
When you see 'GREATEST risk' in privacy questions, rank options by probability and impact of a personal-data incident, not by name recognition of a security control. Choice B sounds compelling, but internal email remains inside the network; A causes a physical and legal exposure when data leaves the organization, so match the option that maps to the full data life cycle.
Related Analysis
Practice All CDPSE Questions
Access 229 questions with complete answers and detailed explanations.
View Full CDPSE Practice Test →