Personnel files containing disciplinary notes are stored on a shared drive with no role-based access limits and no retention schedule. Which remediation best addresses the core GDPR risks?
Select an answer to reveal the explanation.
Short Explanation
Disciplinary notes are not hallway gossip for the whole company drive. Lock them to people who actually need them, and set a clock for how long they stay. Open-forever shared folders fail confidentiality and storage limitation.
Full Explanation
Employee personnel records often include sensitive employment history and must be protected under integrity and confidentiality principles. Unrestricted shared-drive access conflicts with need-to-know and security obligations, while indefinite retention without purpose-linked schedules conflicts with storage limitation. Controllers should combine access restriction, auditability, and documented retention/deletion rules consistent with employment and legal requirements.