ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementHard

A multinational corporation is developing a new global privacy policy. The legal team discovers that the data protection laws in one of its operating regions explicitly prohibit the transfer of certain types of personal data outside national borders, even if the destination country has comparable data protection standards. This legal requirement is an example of which of the following?

  1. AJurisdictional restrictions
  2. BSafe Harbor principles
  3. CPrivacy by design
  4. DData minimization
Show answer & explanation

Correct answer: A. Jurisdictional restrictions

The scenario describes a specific legal prohibition on data transfer based on geographical boundaries (national borders), regardless of the destination's security posture. This is a clear example of jurisdictional restrictions, where laws dictate what can be done with data based on its location or the location of processing.

Why the other options are wrong

  • B. Safe Harbor (now Privacy Shield) was a framework for data transfer, not a prohibition.
  • C. Privacy by design is an approach to embed privacy into system design, not a specific legal restriction on data transfer.
  • D. Data minimization is a principle about collecting only necessary data, not geographic transfer restrictions.

Jurisdictional Restrictions

Legal or regulatory limitations that dictate how data can be collected, stored, processed, or transferred based on the geographic location of the data, the entity, or the individuals involved.

  • Crucial consideration for multinational organizations.
  • Can impact cloud adoption and data outsourcing decisions.
  • Examples include data residency requirements and cross-border data transfer prohibitions.

Memory trick: Privacy with borders, minimize data, design it in, and be safe.

More Security and Risk Management questions