An international aerospace technology firm headquartered in Munich, Germany, with active defense and commercial operations in the United States, discovers an unencrypted database snapshot exposed on a public cloud bucket. Investigation reveals that the exposed data contains both European Union customer Personal Identifiable Information (PII) and restricted US defense technical specifications subject to International Traffic in Arms Regulations (ITAR). Which action correctly fulfills the enterprise's concurrent statutory compliance and regulatory reporting duties?
- Report the personal data exposure to the relevant EU supervisory authority within 72 hours under GDPR while executing export control risk assessment and disclosure procedures with the US Department of State Directorate of Defense Trade Controls (DDTC).Answer
- BClassify the exposure solely as an internal operational incident requiring corrective administrative controls, thereby avoiding mandatory external breach notifications since no malicious exfiltration was confirmed by SIEM logs.
- CTransfer total legal liability and breach notification responsibility to the cloud service provider's technical data custodian who provisioned the storage bucket.
- DApply immediate network perimeter firewall blocks to the cloud bucket and retroactively rotate database keys to legally nullify statutory breach notification mandates.
Answer
The enterprise must report the PII exposure to the designated EU supervisory authority within 72 hours under GDPR and follow statutory disclosure protocols with the US Directorate of Defense Trade Controls (DDTC) regarding ITAR technical data exposure.
The correct response recognizes that multinational operations dealing with dual-use or multi-jurisdictional data must satisfy independent statutory requirements simultaneously. Under GDPR, personal data breaches must be reported to the supervisory authority within 72 hours. Concurrently, public exposure of ITAR-controlled defense technical data constitutes an unauthorized export under US law, mandating formal disclosure procedures with the Directorate of Defense Trade Controls (DDTC).
Step-by-Step Solution
Key Concept
Multi-Jurisdictional Regulatory Compliance & Breach Notification Mandates