A large online bookseller decides to contract with a vendor to manage Personal Information (PI). What is the least important factor for the company to consider when selecting the vendor?
Correct Answer: C
When selecting a vendor to manage personal information, the company should consider various criteria, such as the vendor's reputation, financial health, employee training program, privacy policies, security practices, compliance record, contractual terms, and service quality. However, the vendor's employee retention rates may not be as important as the other factors, as they do not directly affect the vendor's ability to protect and process the personal information entrusted to them. While high employee turnover may indicate some issues with the vendor's management or culture, it may not necessarily impact the vendor's performance or reliability, as long as the vendor has adequate measures to ensure continuity, accountability, and confidentiality of the personal information they handle. References:
* Vendor Selection Process: a Step-by-Step Guide, section "Step 2: Define the vendor selection criteria"
* [IAPP CIPP/US Study Guide], p. 81-82, section 3.4.1
* [IAPP CIPP/US Body of Knowledge], p. 18-19, section C.2.a