A is not satisfying the privacy requirements, as in security and shielding the company from damage if a data breach occurs, even if a good move in general. C is unfulfillable due to the volume of data, number of customers and many years. It would slow business, which is opposite to our roles intentions. D is not addressing the topic of PII being processed. As controller, I can sign a contract with the processor, but it will not shield me from privacy requirements and possible damage. The only valid option is B to mitigate the risk of the data being exposed.