A multinational e-commerce company headquartered in the United States is expanding its online retail services to consumers residing within the European Union. During payment checkout, the platform processes customer credit card numbers, primary account numbers (PAN), full legal names, billing addresses, and IP addresses. Which of the following regulatory compliance frameworks or mandates directly govern the protection and handling of this customer data? (Select TWO.)
- Payment Card Industry Data Security Standard (PCI-DSS)Cevap
- General Data Protection Regulation (GDPR)Cevap
- CHealth Insurance Portability and Accountability Act (HIPAA)
- DFederal Information Security Modernization Act (FISMA)
Cevap
Payment Card Industry Data Security Standard (PCI-DSS) and General Data Protection Regulation (GDPR)
The scenario describes processing credit card numbers alongside personal data belonging to residents of the European Union. Payment Card Industry Data Security Standard (PCI-DSS) explicitly dictates security controls for storing, processing, and transmitting cardholder data (CHD). Concurrently, General Data Protection Regulation (GDPR) enforces strict privacy controls and data subject rights for processing personal data (such as names, addresses, and IP addresses) of individuals located in the EU, regardless of the enterprise's geographic headquarters.
Adım Adım Çözüm
Anahtar Kavram
Regulatory Scope and Data Protection Mandates