DA0-002 · Question #10
A data analyst is following up on a recent, company-wide data audit of customer invoice data. Which of the following is the best option for the analyst to use?
The correct answer is B. GDPR. When auditing company-wide customer invoice data, GDPR is the most relevant regulation to use, as it governs the processing of personal data for individuals within the EU, which commonly includes details found in customer invoices.
Question
A data analyst is following up on a recent, company-wide data audit of customer invoice data. Which of the following is the best option for the analyst to use?
Options
- APCI DSS
- BGDPR
- CISO
- DPII
How the community answered
(42 responses)- A5% (2)
- B71% (30)
- C10% (4)
- D14% (6)
Why each option
When auditing company-wide customer invoice data, GDPR is the most relevant regulation to use, as it governs the processing of personal data for individuals within the EU, which commonly includes details found in customer invoices.
PCI DSS (Payment Card Industry Data Security Standard) is a standard for organizations that handle branded credit cards, focusing specifically on cardholder data security, not broader personal data privacy like GDPR.
GDPR (General Data Protection Regulation) is a comprehensive data protection and privacy law that applies to all companies processing the personal data of individuals residing in the European Union, regardless of the company's location. Customer invoice data frequently contains personal information that falls under GDPR's scope, making it critical for a data audit.
ISO (International Organization for Standardization) refers to a body that develops various international standards (e.g., ISO 27001 for information security), not a specific data privacy regulation that directly governs customer invoice data in the context of an audit.
PII (Personally Identifiable Information) is a type of data (information that can identify an individual), not a regulation or standard to 'use' for an audit; the audit would be concerned with data classified as PII under regulations like GDPR.
Concept tested: Data privacy regulations, GDPR
Source: https://gdpr-info.eu/
Topics
Community Discussion
No community discussion yet for this question.