Data Migration with Outdated Documentation: What Should Be Done Next?

A migration of personal data involving a data source with outdated documentation has been approved by senior management. Which of the following should be done NEXT?

  1. Review data flow post migration. Source Reference Answer
  2. Ensure appropriate data classification.
  3. Engage an external auditor to review the source data.
  4. Check the documentation version history for anomalies.

Community Votes

A
50%
B
50%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to sequence privacy operations: classification is a prerequisite that must occur before migration, while review after migration is too late.

When senior management approves a personal-data migration from a poorly documented source, the next step is to ensure appropriate data classification before moving forward. Community consensus favors classification first rather than a post-migration review.

Choosing A, 'Review data flow post migration' is the most common mistake because it sounds like a thorough follow-up, but it happens after the migration, not as the NEXT step.

Community Discussion (3 comments)

4dfe785 👍 1 Selected: B
The migration hasn't occurred yet. So, I think we should ensure appropriate data classification FIRST before we move forward with migration. Then and only then we can do A.
ARaghunanan 👍 1 Selected: A
Ensuring the data migration was successful is determined by a review post migration.
shiowbah 👍 2
B. Ensure appropriate data classification.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B, "Ensure appropriate data classification," is the correct next step. When a data source has outdated documentation, you do not reliably know what personal data it contains, its sensitivity, or its handling requirements. Before migrating personal data, you must classify it so that appropriate protections and controls can be applied during and after the migration. Senior approval does not remove the obligation to identify and classify personal data.

Why the Other Options Are Wrong

Option A, "Review data flow post migration," is a valid verification activity but it occurs after the migration, so it cannot be the NEXT step. Option C, engaging an external auditor, is not automatically necessary and would be premature before classification. Option D, checking version history, only helps understand documentation changes; it does not address the content, sensitivity, or classification of the personal data being migrated.

Community Comment Notes

Commenters favoring B correctly point out that the migration has not yet occurred, so classification should happen first. One comment states: "The migration hasn't occurred yet. So, I think we should ensure appropriate data classification FIRST before we move forward with migration. Then and only then we can do A." Another comment independently selects B, reinforcing the consensus. A single comment selecting A misses the timing context, which is the central trap in this question.

Official Reference

Exam Strategy

For any "what should be done NEXT" question, evaluate the timing of each answer option. Eliminate actions that can only logically occur after the event described, and choose the action that is a necessary prerequisite for safely handling personal data.

Related Analysis

Practice All CDPSE Questions

Access 229 questions with complete answers and detailed explanations.

View Full CDPSE Practice Test →

← Back to CDPSE Study Guide