Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A global enterprise is evaluating its data privacy practices. They need to ensure that personal data collected from customers is processed lawfully, fairly, and transparently, and that individuals have rights over their data. Which regulatory compliance standard is most directly concerned with these principles?
- AGeneral Data Protection Regulation (GDPR)
- BPayment Card Industry Data Security Standard (PCI DSS)
- CHealth Insurance Portability and Accountability Act (HIPAA)
- DSarbanes-Oxley Act (SOX)
Show answer & explanationAnswer & explanation
Correct answer: A. General Data Protection Regulation (GDPR)
GDPR is a comprehensive data protection law that focuses on the lawful, fair, and transparent processing of personal data and grants individuals significant rights over their information, particularly for residents of the European Union.
Why the other options are wrong
- B. PCI DSS focuses on securing credit card transactions, not general personal data rights.
- C. HIPAA specifically protects sensitive patient health information in the United States.
- D. SOX primarily deals with corporate financial reporting and disclosure requirements.
General Data Protection Regulation (GDPR)
A regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area.
- Mandates strict rules for processing personal data.
- Grants individuals rights over their data (e.g., right to access, erasure).
- Applies to any organization processing EU citizens' data, regardless of location.
Memory trick: EU citizens' data needs GDPR protection.