nerdexam
Isaca

CDPSE · Question #135

Which of the following needs to be identified FIRST to define the privacy requirements to use when assessing the selection of IT systems?

The correct answer is B. Applicable privacy legislation. Privacy legislation defines the mandatory, legally enforceable minimum requirements an organization must meet when processing personal data. Identifying applicable laws and regulations (e.g., GDPR, HIPAA, CCPA) must come first because they establish the non-negotiable baseline…

Privacy Governance

Question

Which of the following needs to be identified FIRST to define the privacy requirements to use when assessing the selection of IT systems?

Options

  • AType of data being processed
  • BApplicable privacy legislation
  • CApplicable control frameworks
  • DAvailable technology platforms

How the community answered

(56 responses)
  • A
    4% (2)
  • B
    88% (49)
  • C
    7% (4)
  • D
    2% (1)

Explanation

Privacy legislation defines the mandatory, legally enforceable minimum requirements an organization must meet when processing personal data. Identifying applicable laws and regulations (e.g., GDPR, HIPAA, CCPA) must come first because they establish the non-negotiable baseline obligations-lawful basis for processing, data subject rights, retention limits, breach notification, etc.-that all subsequent decisions must satisfy. The type of data being processed (A) informs which regulations apply but cannot be used meaningfully until the legal context is known. Control frameworks (C) and technology platforms (D) are chosen and configured after legal requirements are understood, since they are the means to achieve compliance, not the driver of it.

Topics

#Legal compliance#Privacy requirements#IT system selection#Privacy program development

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice