A tourism board confuses “European data protection legislation principles” with ISO 27001 controls. Which response keeps the answer in the correct CIPP/E legal-principle space?
Select an answer to reveal the explanation.
Short Explanation
ISO 27001 is a security management gym membership; GDPR principles are the legal traffic laws. Fairness, purpose limitation, and friends live in the statute. A shiny ISO certificate helps prove security practice, but it does not rewrite or replace European data-protection legislation principles on the CIPP/E exam.
Full Explanation
CIPP/E assesses understanding of principles embedded in European data-protection legislation (for example fairness, lawfulness, transparency, purpose limitation, and related GDPR principles). ISO/IEC 27001 provides an information-security management system framework and control catalogue; it is complementary operational guidance, not the legislative principle set itself. NIST catalogues and ISO certification do not create a legal exemption from GDPR principles.