🔥 3-day streak
ISACA CDPSE — Certified Data Privacy Solutions Engineer75 / 147
Question 75 of 147

A privacy officer at a healthcare technology company has just completed a compliance gap assessment against a newly applicable data protection regulation. The assessment identified 47 gaps across multiple processing activities, ranging from missing retention schedules to inadequate legal bases for certain data flows. The remediation budget and staff are limited, and the regulation takes effect in six months. What should the privacy officer do FIRST to determine the sequence of remediation efforts?

Reviewed for accuracy · Report an issueNext question