Question

Difficulty: HardRegulatory Compliance and Legal Requirements Management

An enterprise risk manager is conducting a gap analysis across global business units to establish baseline legal and contractual compliance controls. Match each regulatory or industry framework to its primary operational scope and data protection mandate.

  • General Data Protection Regulation (GDPR)Extraterritorial law governing data subject consent, lawful processing, and cross-border transfers of personal data for EU residents.
  • Health Insurance Portability and Accountability Act (HIPAA)Enforces technical, administrative, and physical safeguards for Protected Health Information (PHI) managed by covered entities.
  • Payment Card Industry Data Security Standard (PCI-DSS)Contractual security baseline requiring encryption and tokenization for entities processing Primary Account Numbers (PAN).
  • Sarbanes-Oxley Act (SOX)Mandates internal financial reporting controls and audit logging integrity for US publicly traded corporations.

Answer

General Data Protection Regulation (GDPR) matches the extraterritorial law governing personal data for EU residents; Health Insurance Portability and Accountability Act (HIPAA) matches the protection of Protected Health Information (PHI) for covered entities; Payment Card Industry Data Security Standard (PCI-DSS) matches the contractual baseline for processing Primary Account Numbers (PAN); Sarbanes-Oxley Act (SOX) matches internal financial reporting and auditing controls for US public companies.
Each framework targets a distinct compliance domain: GDPR covers EU personal data privacy regardless of processor location; HIPAA mandates PHI protection for healthcare entities; PCI-DSS sets contractual requirements for credit card data (PAN); and SOX governs corporate financial record integrity and reporting.

Step-by-Step Solution

1
Analyze data classifications and jurisdictional boundaries for each framework.
Identified PHI, PAN/CHD, corporate financial telemetry, and EU resident personal data.
Regulatory compliance requirements are categorized primarily by data type and legal jurisdiction.
2
Map legal mandates versus industry contractual standards.
PCI-DSS is identified as an industry contractual baseline, while GDPR, HIPAA, and SOX are statutory legislative mandates.
Differentiating statutory requirements from contractual obligations prevents misapplication of penalty frameworks during audit assessments.
3
Align each mandate with its exact functional definition.
GDPR correlates to EU personal data, HIPAA to PHI, PCI-DSS to cardholder data, and SOX to internal financial controls.
Demonstrates comprehensive knowledge of regulatory scope and compliance governance.

Key Concept

Regulatory Scope and Legal Data Classifications
Rate this question