To provide evidence of GDPR compliance, a company performs an internal audit. As a result, it finds a data base, password-protected, listing all the social network followers of the client. Regarding the domain of the controller-processor relationships, how is this situation considered?
A. Compliant with the security principle, because the data base is password-protected
B. Non-compliant, because the storage of the data exceeds the tasks contractually authorized by the controller
C. Not applicable, because the data base is password protected, and therefore is not at risk of identifying any data subject
D. Compliant with the storage limitation principle, so long as the internal auditor permanently deletes the data base