Master the IT-English vocabulary of data retention: retention periods, purging, legal hold, minimisation and the right to erasure.
0 / 14 completed
1 / 14
A 'retention period' of 24 months is set for logs. What does it specify?
A retention period defines how long data may be stored before deletion or anonymisation.
2 / 14
What does 'data minimisation' mean?
Data minimisation limits collection and retention to what is necessary for the purpose.
3 / 14
A 'legal hold' is placed on certain records. What does that mean?
A legal hold suspends normal deletion so relevant records are preserved for legal matters.
4 / 14
A user invokes the 'right to erasure'. What must the company do?
The right to erasure (right to be forgotten) obliges deletion of personal data absent a lawful basis to retain.
5 / 14
Which sentence correctly uses 'purge'?
To purge is to permanently delete data, typically once it exceeds the retention period.
6 / 14
Reviewer: 'I'm concerned about the length of this log file. We're retaining all application events for five years – that seems excessive, especially given we only need audit trails for regulatory compliance. Can you explain your rationale?'
Which response best addresses the reviewer's concern while adhering to data retention principles?
The reviewer raises a legitimate point about data volume and cost. The correct response acknowledges the five-year retention period isn't inherently wrong, but frames it within the context of industry standards and legal obligations – specifically, regulatory compliance which often dictates longer retention periods for audit trails. Simply deleting logs or minimizing storage costs without considering these factors would be a poor justification and misses the core issue raised by the reviewer. The key is to explain *why* a longer period is necessary.
7 / 14
Reviewer: 'I'm concerned about the length of this log file. We're retaining all application events for five years – that seems excessive, especially given we only need audit trails for regulatory compliance. Can you explain your rationale?'
Which response best addresses the reviewer's concern while adhering to data retention principles?
The reviewer raises a legitimate point about data volume and cost. The correct response acknowledges the five-year retention period isn't inherently wrong, but frames it within the context of industry standards and legal obligations – specifically, regulatory compliance which often dictates longer retention periods for audit trails. Simply deleting logs or minimizing storage costs without considering these factors would be a poor justification and misses the core issue raised by the reviewer. The key is to explain *why* a longer period is necessary.
8 / 14
Reviewer: 'I'm concerned about the length of this log file. We're retaining all application events for five years – that seems excessive, especially given we only need audit trails for regulatory compliance. Can you explain your rationale?'
Which response best addresses the reviewer's concern while adhering to data retention principles?
The reviewer raises a legitimate point about data volume and cost. The correct response acknowledges the five-year retention period isn't inherently wrong, but frames it within the context of industry standards and legal obligations – specifically, regulatory compliance which often dictates longer retention periods for audit trails. Simply deleting logs or minimizing storage costs without considering these factors would be a poor justification and misses the core issue raised by the reviewer. The key is to explain *why* a longer period is necessary.
9 / 14
Reviewer: 'I'm concerned about the length of this log file. We're retaining all application events for five years – that seems excessive, especially given we only need audit trails for regulatory compliance. Can you explain your rationale?'
Which response best addresses the reviewer's concern while adhering to data retention principles?
The reviewer raises a legitimate point about data volume and cost. The correct response acknowledges the five-year retention period isn't inherently wrong, but frames it within the context of industry standards and legal obligations – specifically, regulatory compliance which often dictates longer retention periods for audit trails. Simply deleting logs or minimizing storage costs without considering these factors would be a poor justification and misses the core issue raised by the reviewer. The key is to explain *why* a longer period is necessary.
10 / 14
Reviewer: 'The API response shows we're logging every user interaction, including failed login attempts, and the retention policy is set to 10 years. This feels like a significant risk considering GDPR requirements – are we truly justified in holding this data for so long?'. What's the primary concern being raised here regarding the data retention policy?
The reviewer is primarily concerned about GDPR (General Data Protection Regulation) compliance. Retaining all user interactions, particularly failed logins, for 10 years likely exceeds the necessary timeframe mandated by regulations and raises concerns about data minimization – holding more data than strictly required increases the risk of fines and legal challenges. Option A is incorrect as storage capacity isn't directly addressed; options C & D are irrelevant to the core issue.
11 / 14
During a standup meeting, Sarah says: 'We've implemented a data retention policy that automatically deletes all application logs older than 30 days. We're aiming for a rolling window to reduce storage costs and improve performance.' What does 'rolling window' refer to in this context?
'Rolling window' refers to a dynamic retention schedule. Instead of a fixed period (like 30 days), it means the deletion criteria continuously adjusts based on the amount of data being generated – as new data comes in, the 'window' shifts forward. Option A is incorrect because it describes a static timeframe; options C & D are not part of the defined strategy.
12 / 14
A PR description reads: 'Implemented a purge command to remove all log entries from the last six months. This addresses concerns about excessive storage usage and improves query performance.' What is the purpose of the 'purge' command in this scenario?
The 'purge' command is used to systematically delete data – in this case, log entries – that have exceeded the defined retention period (six months). This directly addresses concerns about storage usage and performance. Option A describes log rotation; options C & D represent different actions entirely.
13 / 14
You're reviewing a Slack message from a colleague: 'Just ran the data retention script. It's now purging all audit logs older than 7 years according to our policy.' What does this script likely do?
The script is designed to automatically delete log entries based on their age. The phrase 'purging' indicates this action – removing data beyond the defined retention period (7 years). Options A, C & D represent different functionalities that aren't related to automated deletion.
14 / 14
A system administrator is explaining the data retention policy to a new developer. They say: 'We're implementing a strategy of 'data minimization', which means we only keep the *minimum* amount of data necessary for our legal and operational needs.' What does 'data minimization' primarily aim to achieve?
'Data minimization' focuses on reducing the volume of data stored. While compliance is a factor, the primary goal is to minimize storage costs and improve system performance by only retaining essential data – this directly addresses operational efficiency concerns. Option A misrepresents the balance between compliance and cost; options C & D are secondary benefits.
What does the "Data Retention Policies" exercise practise?
Master the IT-English vocabulary of data retention: retention periods, purging, legal hold, minimisation and the right to erasure.
How many questions are in this exercise?
This exercise has 14 questions, each multiple-choice with a full explanation shown after you answer.
What English level is this exercise for?
This exercise is tagged Intermediate. If the vocabulary feels difficult, browse the Data Privacy category page for an easier module to start with.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free with no account, sign-up, or paywall.
Do I get feedback if I answer incorrectly?
Yes — whichever option you choose, right or wrong, you'll immediately see an explanation clarifying the correct term and why the other options don't fit.
Can I retry this exercise?
Yes — once you finish all the questions, a "Try again" button on the results screen resets the exercise so you can practise as many times as you like.
Do I need an account to track my progress?
No account is required. Your progress bar and score for this session are tracked in the browser as you go, but nothing is saved once you leave the page.
Is "Data Retention Policies" part of a larger series?
Yes — it's one exercise in the Data Privacy category on CoderSlingo. See the category page for the full list of related exercises on similar terminology.
Can I link directly to this exercise?
Yes — this exercise has its own permanent URL, so you can bookmark it or share the link directly with a colleague or study partner.
Where can I find more exercises like this one?
See the Data Privacy category page for related exercises, or browse the main Exercises hub for other IT English topics.