A systems administrator is setting up storage and backup policies for a web application database that processes personal information of customers residing in the European Union. Which of the following technical controls and compliance procedures must be implemented to comply with the General Data Protection Regulation (GDPR)? (Select TWO.)
- Implement technical mechanisms to permanently delete an individual's personal data upon receiving a valid request.Cevap
- Apply strong cryptographic encryption to personal data both in transit and at rest.Cevap
- CRetain full card verification value (CVV) magnetic stripe data in plaintext to assist with annual compliance audits.
- DEnforce Business Associate Agreements (BAAs) with all international third-party cloud service providers.
Cevap
The correct controls to implement are providing technical mechanisms to permanently delete an individual's personal data upon request and applying strong cryptographic encryption to personal data in transit and at rest.
Under GDPR, organizations processing personal data of EU residents must implement robust technical protections, such as encrypting personal data in transit and at rest, while also adhering to individual data subject rights, specifically providing technical means to permanently delete personal data upon request (Right to Erasure).
Adım Adım Çözüm
Anahtar Kavram
GDPR Technical Safeguards and Data Subject Rights