EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewEasy

A global technology company is expanding its operations into the European Union. To ensure compliance with strict data protection regulations, the company must appoint a Data Protection Officer (DPO), conduct Data Protection Impact Assessments (DPIAs), and implement robust mechanisms for data subject rights, such as the 'right to be forgotten'. Which regulation is driving these specific requirements?

  1. ASOX
  2. BPCI DSS
  3. CGDPR
  4. DHIPAA
Show answer & explanation

Correct answer: C. GDPR

The General Data Protection Regulation (GDPR) is a comprehensive data privacy law in the European Union that mandates requirements such as appointing a DPO, conducting DPIAs, and safeguarding data subject rights like the right to be forgotten.

Why the other options are wrong

  • A. SOX (Sarbanes-Oxley Act) is a U.S. law for financial reporting and corporate governance, not data privacy.
  • B. PCI DSS (Payment Card Industry Data Security Standard) is for credit card handling, not general personal data protection.
  • D. HIPAA (Health Insurance Portability and Accountability Act) is a U.S. law for healthcare data, not general EU data protection.

GDPR (General Data Protection Regulation)

A comprehensive data privacy and security law enacted by the European Union (EU) that imposes strict rules on how personal data is collected, stored, and processed, granting individuals significant control over their data.

  • EU data privacy law.
  • Mandates DPO appointment in certain cases.
  • Requires Data Protection Impact Assessments (DPIAs).
  • Includes data subject rights (e.g., right to be forgotten).
  • Applies to organizations processing EU citizens' data globally.

Memory trick: HIPAA for Health, PCI for Cards, SOX for Books, GDPR for EU Data.

More Information Security and Ethical Hacking Overview questions