Breakdown 1 — Compliance reporting
- Internal — to management/board/audit committee: status of controls, exceptions, KRIs.
- External — to regulators, customers, auditors: attestations (SOC 2), PCI reports, breach notifications within legal deadlines (GDPR: 72 hours).
Breakdown 2 — Consequences of non-compliance (class: know these)
| Consequence | Example |
|---|---|
| Fines | GDPR up to 4% of global revenue; HIPAA per-record penalties |
| Sanctions | Regulator restricts operations; individuals barred |
| Reputational damage | Customer loss after a public breach |
| Loss of license | Ability to operate revoked (banking, healthcare) |
| Contractual impacts | PCI: card brands raise fees or terminate processing; SLA penalties |
Breakdown 3 — Compliance monitoring
| Element | Meaning |
|---|---|
| Due diligence / due care | Diligence = investigate and verify before (class: "do your part before"); care = act responsibly ongoing |
| Attestation and acknowledgement | People sign that they read/follow policy (AUP acknowledgement); executives attest to controls (SOX) |
| Internal and external monitoring | Self-checks plus outside audits/assessments |
| Automation | Compliance dashboards, SCAP scans, continuous control monitoring instead of annual spreadsheets |
Breakdown 4 — Privacy (class keywords: GDPR)
| Concept | Meaning |
|---|---|
| Legal implications — local/regional, national, global | State laws (CCPA), federal (HIPAA/GLBA), global (GDPR) — apply the strictest that covers the data subject |
| Data subject | The person the data is about |
| Controller vs. processor | Controller decides purpose/means; processor acts on the controller's instructions (both have obligations under GDPR) |
| Ownership | Who owns/is accountable for the data (organizationally the data owner; legally the subject has rights over personal data) |
| Data inventory and retention | Know what personal data you hold, where, why, and for how long; delete when no longer needed |
| Right to be forgotten | Subject can request erasure (GDPR right to erasure) |
| Data sovereignty (class) | Data subject to the laws of where it's stored |
From class — regulations recap: SOX (financial reporting accuracy; separation of duties), HIPAA (health), GLBA (financial privacy), GDPR (EU personal data — sovereignty, right to be forgotten, controller/processor), PCI DSS (credit cards), FERPA (education — crossed out in class).
Exam tip: "Customer asks that all their data be deleted" → right to be forgotten. "Employees sign the AUP annually" → acknowledgement. "Company lost its ability to process cards" → contractual impact. "Which is the processor?" → the vendor doing the work for the controller.
Quick self-check
- Name three consequences of non-compliance.
- Due diligence vs. due care?
- Who is the data subject?
Sources: 20260917_173216.jpg, 20260917_173221.jpg, 20260917_182502.jpg