Match each data privacy framework or regulatory standard on the left with its corresponding technical requirement or operational enforcement constraint on the right.
- GDPR Right to Erasure ('Right to be Forgotten')Requires purging personal records upon individual request, provided statutory tax or financial retention mandates do not legally supersede the request.
- PCI-DSS Account Data HandlingMandates isolating the Cardholder Data Environment (CDE) and strictly forbids persisting Sensitive Authentication Data (SAD) like CVV codes after transaction authorization.
- HIPAA Security Rule Technical SafeguardsEnforces technical mechanisms including unique user identification, automatic session logoff, audit logging, and encryption for electronic Protected Health Information (ePHI).
- FERPA Educational Privacy RegulationsRestricts non-consensual disclosure of student academic records and requires providing formal annual notices regarding directory information opt-out rights.
Answer
The regulations match their operational requirements as follows: GDPR Right to Erasure matches requiring record purging upon request unless statutory financial retention laws supersede; PCI-DSS matches isolating the CDE and prohibiting CVV persistence post-authorization; HIPAA Security Rule matches technical safeguards such as unique IDs, auto-logoff, and audit controls for ePHI; FERPA matches restricting disclosure of student academic records and managing directory information opt-out rights.
Each data privacy framework maps directly to its specific legal scope and technical enforcement requirements: GDPR regulates EU personal data erasure subject to statutory retention exceptions; PCI-DSS mandates CDE network isolation and bans CVV storage post-authorization; HIPAA mandates access, audit, and encryption controls for ePHI; and FERPA governs student educational records disclosure.
Step-by-Step Solution
Key Concept
Data Privacy Frameworks and IT Compliance Technical Controls
Estimated Time:2m 30s