Question

Difficulty: EasyRegulatory Compliance and Legal Requirements Management

A Software-as-a-Service (SaaS) platform provider headquartered in the United States expands its human resources management platform to serve client organizations based in the European Union (EU). Which of the following regulatory compliance mandates must the organization implement to fulfill General Data Protection Regulation (GDPR) requirements? (Select TWO.)

  1. Establish a recognized legal basis, such as explicit consent or contractual necessity, prior to processing personal data.Answer
  2. Provide data subjects with the mechanism to request erasure of their personal records upon demand.Answer
  3. C
    Store all collected employee data exclusively in United States federal cloud facilities without cross-border transfer agreements.
  4. D
    Conduct mandatory PCI-DSS compliance attestations for non-financial employee personnel records.

Answer

The organization must establish a lawful basis for processing personal data and ensure EU data subjects are provided the right to request erasure of their personal data.
The correct requirements involve establishing a recognized legal basis (such as explicit consent) prior to processing personal data and honoring data subject rights, specifically the right to request data erasure ('right to be forgotten'). Both are core tenets of GDPR compliance for processing EU citizens' personal data.

Step-by-Step Solution

1
Identify the applicable regulatory framework.
Processing personal data of EU residents triggers compliance obligations under the European Union General Data Protection Regulation (GDPR).
GDPR applies extra-territorially to any enterprise offering goods or services to EU data subjects regardless of the company's physical headquarters.
2
Evaluate fundamental GDPR requirements for lawful processing and user rights.
GDPR mandates establishing a lawful basis (e.g., explicit consent, legitimate interest, or contract execution) and recognizing individual privacy rights such as the right to erasure.
Articles 6 and 17 of GDPR explicitly define lawful processing conditions and the right to be forgotten.
3
Differentiate non-applicable regulatory frameworks and improper control strategies.
Exclusively storing data in US federal facilities without transfer mechanisms violates cross-border transfer laws, while PCI-DSS applies exclusively to payment cardholder data.
Proper regulatory scope analysis prevents misapplying payment standards to general HR data or creating regulatory violations through unapproved data transfers.

Key Concept

GDPR Regulatory Compliance and Data Subject Rights
Estimated Time:50s
Rate this question