Soru

Zorluk: OrtaRegulatory Compliance and Legal Requirements Management

A telecommunications company based in the United States expands operations into the European Union and deploys a network analytics service that processes subscriber location data, personal contact details, and customer payment card numbers. Which of the following legal and regulatory compliance obligations apply to this service deployment? (Select TWO.)

  1. Processing personal contact details and subscriber location records of European Union residents mandates compliance with the General Data Protection Regulation (GDPR) regardless of where the servers are hosted.Cevap
  2. B
    Maintaining credit card numbers for billing automation permits the organization to substitute Sarbanes-Oxley Act (SOX) audits for annual Payment Card Industry Data Security Standard (PCI-DSS) assessments.
  3. Cardholder payment data stored and processed within the analytics platform must comply with Payment Card Industry Data Security Standard (PCI-DSS) encryption and access control requirements.Cevap
  4. D
    Deploying perimeter firewalls around the analytics database removes the legal requirement to notify supervisory authorities following a verified data breach under European privacy laws.

Cevap

The organization is subject to GDPR due to processing EU resident personal and location data, and must comply with PCI-DSS requirements for handling cardholder data.
Processing personal records of individuals in the European Union invokes GDPR due to its extraterritorial reach. Concurrently, handling credit card details subjects the infrastructure to PCI-DSS compliance for safeguarding cardholder data.

Adım Adım Çözüm

1
Analyze the data types and geographical context in the scenario.
Identified EU resident personal data/location records and payment card information.
Regulatory applicability depends on the specific classification of data processed and the geographic jurisdiction of the data subjects.
2
Evaluate applicable data privacy regulations.
Determined that processing EU residents' personal data falls under GDPR's extra-territorial reach.
GDPR applies globally to any entity offering goods/services to or monitoring the behavior of individuals in the EU.
3
Evaluate applicable payment security standards.
Determined that payment card processing mandates adherence to PCI-DSS technical and operational requirements.
PCI-DSS applies universally to organizations that handle branded credit or debit card data.

Anahtar Kavram

Regulatory Scope and Legal Compliance Governance
Bu soruyu puanla