🔥 3-day streak
ISACA CDPSE — Certified Data Privacy Solutions Engineer2 / 147
Question 2 of 147
A healthcare analytics platform stores patient records used by multiple internal teams: clinical staff need full records for treatment, while a marketing team wants access to demographic fields for outreach campaigns. The privacy engineer is designing an access model that enforces purpose limitation at the data layer so that even authorized users can only retrieve fields consistent with their stated processing purpose. Which access control approach BEST enforces this requirement technically?
Reviewed for accuracy · Report an issueNext question