A telecommunications company based in the United States expands operations into the European Union and deploys a network analytics service that processes subscriber location data, personal contact details, and customer payment card numbers. Which of the following legal and regulatory compliance obligations apply to this service deployment? (Select TWO.)
- Processing personal contact details and subscriber location records of European Union residents mandates compliance with the General Data Protection Regulation (GDPR) regardless of where the servers are hosted.Answer
- BMaintaining credit card numbers for billing automation permits the organization to substitute Sarbanes-Oxley Act (SOX) audits for annual Payment Card Industry Data Security Standard (PCI-DSS) assessments.
- Cardholder payment data stored and processed within the analytics platform must comply with Payment Card Industry Data Security Standard (PCI-DSS) encryption and access control requirements.Answer
- DDeploying perimeter firewalls around the analytics database removes the legal requirement to notify supervisory authorities following a verified data breach under European privacy laws.
Answer
The organization is subject to GDPR due to processing EU resident personal and location data, and must comply with PCI-DSS requirements for handling cardholder data.
Processing personal records of individuals in the European Union invokes GDPR due to its extraterritorial reach. Concurrently, handling credit card details subjects the infrastructure to PCI-DSS compliance for safeguarding cardholder data.
Step-by-Step Solution
Key Concept
Regulatory Scope and Legal Compliance Governance