ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 91 - 312-40 discussion

Report
Export

The organization TechWorld Ltd. used cloud for its business. It operates from an EU country (Poland and Greece). Currently, the organization gathers and processes the data of only EU users. Once, the organization experienced a severe security breach, resulting in loss of critical user data. In such a case, along with its cloud service provider, the organization should be held responsible for non-compliance or breaches. Under which cloud compliance framework will the company and cloud provider be penalized?

A.
GDPR
Answers
A.
GDPR
B.
NIST
Answers
B.
NIST
C.
ITAR
Answers
C.
ITAR
D.
HIPAA
Answers
D.
HIPAA
Suggested answer: A

Explanation:

1.GDPR: The General Data Protection Regulation (GDPR) is the primary law regulating how companies protect EU citizens' personal data1.

1.Applicability: GDPR applies to all organizations operating within the EU, as well as organizations outside of the EU that offer goods or services to customers or businesses in the EU1.

1.Data Breaches: In the event of a data breach, organizations are required to notify the appropriate data protection authority within 72 hours, if feasible, after becoming aware of the breach2.

1.Penalties: Organizations that do not comply with GDPR can face hefty fines. For serious infringements, GDPR states that companies can be fined up to 4% of their annual global turnover or 20 million (whichever is greater)1.

1.Responsibility: Both the data controller and the processor will be held responsible for not adhering to the GDPR rules, which includes security breaches resulting in the loss of user data1.

GDPR Info on fines and penalties1.

EDPB Guidelines on personal data breach notification under GDPR2.

asked 18/09/2024
Péter Szittya
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first