Match each data privacy regulation or compliance framework on the left with its corresponding primary scope and regulated data type on the right.
- GDPRMandates data privacy rights and protection for personal data of European Union residents
- HIPAASafeguards Protected Health Information (PHI) handled by healthcare providers and business associates
- PCI-DSSEstablishes technical requirements for securing credit cardholder data and payment processing environments
- FERPAProtects the privacy of student educational records maintained by educational institutions
Answer
GDPR matches with protection of personal data for EU residents; HIPAA matches with safeguarding Protected Health Information (PHI); PCI-DSS matches with securing credit cardholder data; FERPA matches with privacy of student educational records.
Each framework addresses a specific data type and domain: GDPR covers EU personal privacy, HIPAA protects healthcare PHI, PCI-DSS secures cardholder payment data, and FERPA protects student educational records.
Step-by-Step Solution
Key Concept
Data Privacy and Compliance Regulations Scope