Soru

Zorluk: OrtaRegulatory Compliance and Legal Requirements Management

A multinational e-commerce company headquartered in the United States is expanding its online retail services to consumers residing within the European Union. During payment checkout, the platform processes customer credit card numbers, primary account numbers (PAN), full legal names, billing addresses, and IP addresses. Which of the following regulatory compliance frameworks or mandates directly govern the protection and handling of this customer data? (Select TWO.)

  1. Payment Card Industry Data Security Standard (PCI-DSS)Cevap
  2. General Data Protection Regulation (GDPR)Cevap
  3. C
    Health Insurance Portability and Accountability Act (HIPAA)
  4. D
    Federal Information Security Modernization Act (FISMA)

Cevap

Payment Card Industry Data Security Standard (PCI-DSS) and General Data Protection Regulation (GDPR)
The scenario describes processing credit card numbers alongside personal data belonging to residents of the European Union. Payment Card Industry Data Security Standard (PCI-DSS) explicitly dictates security controls for storing, processing, and transmitting cardholder data (CHD). Concurrently, General Data Protection Regulation (GDPR) enforces strict privacy controls and data subject rights for processing personal data (such as names, addresses, and IP addresses) of individuals located in the EU, regardless of the enterprise's geographic headquarters.

Adım Adım Çözüm

1
Analyze the data types processed by the retail platform
Identified Cardholder Data (credit card primary account numbers) and EU Personally Identifiable Information (full names, billing addresses, IP addresses).
Determining the data classification and geographical subject scope is necessary to map legal and regulatory mandates.
2
Map Cardholder Data to the appropriate security standard
Cardholder data processing mandates compliance with the Payment Card Industry Data Security Standard (PCI-DSS).
PCI-DSS is the technical operational baseline required by card brands for processing payment credit cards.
3
Map European Union consumer personal data to applicable privacy law
Processing personal data of EU residents requires compliance with the General Data Protection Regulation (GDPR).
GDPR has extraterritorial reach governing any business offering goods or services to EU data subjects.

Anahtar Kavram

Regulatory Scope and Data Protection Mandates
Bu soruyu puanla