9.1.3 - Regulatory Compliance

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/9

flashcard set

Earn XP

Description and Tags

Flashcards covering key terms and definitions related to regulatory compliance, data protection legislation, and privacy laws.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

10 Terms

1
New cards

Regulatory Compliance

Externally determined requirements that organizations must follow, especially in certain industries or when processing specific types of data.

2
New cards

Personally Identifiable Information (PII)

Data that can identify, contact, locate, or describe an individual, such as SSN, name, birth date, etc.

3
New cards

General Data Protection Regulation (GDPR)

EU regulation that governs the collection and processing of personal data, requiring informed consent and giving data subjects rights regarding their data.

4
New cards

Informed Consent

The requirement that data must be collected and processed only for a clearly stated purpose, explained in plain language.

5
New cards

Data Sovereignty

Legal concept where processing and storage of data are restricted based on physical location, affecting rights and privacy.

6
New cards

Data Locality

Establishment of storage and processing boundaries based on national or state borders to comply with local privacy regulations.

7
New cards

Payment Card Industry Data Security Standard (PCI DSS)

Security standard for organizations that handle credit card information, requiring specific protections for cardholder data.

8
New cards

Cardholder Data Environment (CDE)

The part of a payment processing system that stores, processes, or transmits cardholder data and must comply with PCI DSS.

9
New cards

Data Breach Notification Procedures

The policies required to inform customers about data breaches involving their personal information.

10
New cards

Contractual Safeguards

Measures put in place to extend rights under GDPR when transferring data to jurisdictions with inadequate privacy regulations.