Soru

Zorluk: OrtaRegulatory Compliance and Legal Requirements Management

An international e-commerce organization headquartered in the United States discovers an unauthorized database export containing names, email addresses, and behavioral tracking logs of customers residing in the European Union. Which regulatory framework explicitly mandates that the data controller notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the personal data breach?

  1. General Data Protection Regulation (GDPR)Cevap
  2. B
    Payment Card Industry Data Security Standard (PCI-DSS)
  3. C
    Health Insurance Portability and Accountability Act (HIPAA)
  4. D
    Sarbanes-Oxley Act (SOX)

Cevap

The General Data Protection Regulation (GDPR) mandates notification to the supervisory authority within 72 hours of becoming aware of a personal data breach involving EU residents.
The General Data Protection Regulation (GDPR) applies extraterritorially to any entity processing the personal data of data subjects located within the European Union. Under GDPR Article 33, when a breach occurs that poses a risk to individuals' rights and freedoms, the organization acting as the data controller must report the breach to its supervisory authority within 72 hours of discovery.

Adım Adım Çözüm

1
Identify the data classification and geographical jurisdiction of the affected individuals in the scenario.
The exposed data comprises customer names, emails, and behavioral tracking data (personally identifiable information) belonging to residents of the European Union.
Regulatory jurisdiction for privacy legislation is governed by the location and residency of the affected data subjects, establishing European privacy law applicability regardless of company headquarters location.
2
Evaluate the regulatory mandate requiring a 72-hour breach notification window to supervisory authorities.
Article 33 of the General Data Protection Regulation (GDPR) specifies a strict 72-hour notification timeframe to the relevant lead supervisory authority following breach awareness.
This timeline ensures prompt regulatory oversight and assessment of risks to individuals' rights and freedoms.

Anahtar Kavram

GDPR Data Breach Notification Obligations
Tahmini Süre:1m 15s
Bu soruyu puanla