Question

Difficulty: MediumData Privacy and Compliance Regulations

An IT compliance auditor is updating the organization's data governance policy matrix. Match each data privacy framework or regulation on the left with its corresponding operational requirement or scope on the right.

  • PCI-DSSProhibits the persistent storage of card verification codes (CVV/CVC) after transaction authorization.
  • GDPRGrants individuals the right to request complete erasure of their personal data (Right to be Forgotten).
  • HIPAARequires technical and administrative safeguards for electronic Protected Health Information (ePHI).
  • FERPARestricts disclosure of student educational records and transcripts without explicit consent.

Answer

PCI-DSS matches with prohibiting post-authorization CVV storage; GDPR matches with the Right to be Forgotten data erasure requirement; HIPAA matches with safeguarding electronic Protected Health Information (ePHI); FERPA matches with restricting disclosure of student educational records.
Each regulatory framework is correctly paired with its defining mandate: PCI-DSS covers payment card transaction processing and restricts CVV storage; GDPR outlines EU data privacy rights including data erasure; HIPAA establishes safeguards for healthcare ePHI; and FERPA protects educational records.

Step-by-Step Solution

1
Identify the primary scope of PCI-DSS
PCI-DSS applies to payment card data and specifically restricts post-authorization storage of sensitive authentication data like CVV/CVC codes.
Security standards for payment card processors mandate strict handling of cardholder data.
2
Identify the primary mandate of GDPR
GDPR governs personal data privacy for EU individuals and mandates rights such as data portability and data erasure (Right to be Forgotten).
European privacy regulations emphasize individual sovereignty over personal data.
3
Identify the primary mandate of HIPAA
HIPAA applies to healthcare providers and business associates, establishing controls for electronic Protected Health Information (ePHI).
Healthcare compliance requires strict confidentiality and safeguarding of patient medical data.
4
Identify the primary mandate of FERPA
FERPA governs educational institutions and protects academic transcripts and student records.
Federal education regulations restrict the release of student records without authorization.

Key Concept

Data Privacy Regulations and Operational Scopes (GDPR, HIPAA, PCI-DSS, FERPA)
Rate this question