Soru

Zorluk: KolayData Privacy and Compliance Regulations

An IT technician is configuring a workstation for a remote employee based in the European Union who collects customer profile details. Which of the following technical and operational practices directly align with the mandatory requirements of the General Data Protection Regulation (GDPR)? (Select TWO.)

  1. Implementing technical workflows to honor user requests for complete data erasureCevap
  2. Obtaining explicit consent from data subjects before collecting and processing their personal dataCevap
  3. C
    Applying strict physical access logging for systems storing Protected Health Information (PHI)
  4. D
    Prohibiting local storage of card verification value (CVV) codes post-authorization

Cevap

Implementing technical workflows to honor user requests for complete data erasure, and obtaining explicit consent from data subjects before collecting and processing their personal data.
The General Data Protection Regulation (GDPR) grants individuals in the European Union specific data privacy rights. Key operational requirements include obtaining explicit user consent before processing personal data and maintaining mechanisms to fulfill the 'right to be forgotten' (erasure of personal data upon request).

Adım Adım Çözüm

1
Identify the relevant privacy regulation based on the scenario context.
The scenario specifies an employee in the European Union handling personal data, which makes GDPR the governing regulation.
GDPR protects the privacy and personal data rights of individuals residing within the European Union.
2
Evaluate the options against GDPR compliance requirements.
Obtaining explicit consent prior to data processing and supporting the right to erasure ('right to be forgotten') are core GDPR mandates.
These controls grant EU data subjects transparency and control over their personal identifying information.
3
Distinguish non-GDPR compliance rules.
PHI requirements belong to HIPAA, and payment card security guidelines belong to PCI-DSS.
Different compliance standards target different data types (healthcare vs. payment card industry).

Anahtar Kavram

General Data Protection Regulation (GDPR) Requirements
Bu soruyu puanla