A financial technology SaaS provider headquartered in Canada expands its operations to process real-time payment transactions and consumer credit metrics for financial institutions operating in both the European Union and the United States. During a legal compliance audit, the enterprise risk management team evaluates the organization's regulatory obligations regarding stored cardholder data, non-public personal information (NPI), and financial telemetry. Which of the following requirements MUST the organization implement to achieve compliance with PCI DSS and GDPR mandates? (Select TWO.)
- Encrypt stored primary account numbers (PAN) and maintain a logically segregated cardholder data environment (CDE).Answer
- Designate a statutory Data Protection Officer (DPO) and establish lawful cross-border data transfer mechanisms for EU personal data.Answer
- CDeploy an inline network intrusion prevention system (IPS) to satisfy mandatory technical controls under Sarbanes-Oxley Act (SOX) Section 404.
- DRelocate all physical data storage infrastructure to United States soil to satisfy Gramm-Leach-Bliley Act (GLBA) data residency directives.
Answer
The organization must encrypt stored primary account numbers (PAN) within a segregated cardholder data environment under PCI DSS, and designate a statutory Data Protection Officer (DPO) alongside lawful cross-border transfer mechanisms under GDPR.
Encrypting primary account numbers within a segregated cardholder data environment satisfies PCI DSS core security requirements. Appointing a Data Protection Officer and establishing lawful transfer mechanisms fulfills GDPR Articles 37 and 44 for processing EU personal data.
Step-by-Step Solution
Key Concept
Regulatory Compliance Scope and Framework Control Requirements