FIDO Regulatory Compliance & Legal Framework 2 — Questions and Answers
Question 1: Under GDPR, how must FIDO authenticators handle biometric data collected during registration?
- Store it indefinitely for audit purposes
- Treat it as special category data requiring explicit consent (Correct answer)
- Share it with relying parties for identity verification
- Encrypt it using FIDO-proprietary algorithms only
Correct answer: Treat it as special category data requiring explicit consent
GDPR Article 9 classifies biometric data as special category data requiring explicit consent and heightened protection.
Question 2: Which US federal law most directly governs the use of electronic signatures and FIDO-based authentication in federal agency transactions?
- COPPA
- ESIGN Act (Correct answer)
- HIPAA
- SOX
Correct answer: ESIGN Act
The Electronic Signatures in Global and National Commerce (ESIGN) Act establishes legal recognition of electronic signatures and authentication methods in US federal transactions.
Question 3: A FIDO2 deployment at a healthcare provider must comply with HIPAA. Which FIDO characteristic directly supports the HIPAA requirement for unique user identification?
- Platform authenticator attestation
- Per-user, per-RP credential binding (Correct answer)
- Client-to-Authenticator Protocol (CTAP)
- Authenticator Certification Level 1
Correct answer: Per-user, per-RP credential binding
FIDO2's per-user, per-relying-party credential binding ensures each user has a cryptographically unique identity, satisfying HIPAA's unique user identification requirement.
Question 4: NIST SP 800-63B classifies FIDO2 hardware security keys as which Authenticator Assurance Level?
- AAL1
- AAL2
- AAL3 (Correct answer)
- AAL0
Correct answer: AAL3
NIST SP 800-63B places hardware FIDO2 keys with verifier impersonation resistance at AAL3, the highest assurance level.
Question 5: The EU's eIDAS regulation defines 'qualified electronic signatures.' How do most FIDO authenticators relate to this framework?
- All FIDO authenticators automatically qualify as qualified electronic signature devices
- FIDO authenticators typically meet advanced but not qualified electronic signature requirements (Correct answer)
- FIDO is exempt from eIDAS requirements by EU directive
- FIDO only supports simple electronic signatures under eIDAS
Correct answer: FIDO authenticators typically meet advanced but not qualified electronic signature requirements
FIDO authenticators generally satisfy advanced electronic signature (AdES) requirements but qualified electronic signatures (QES) require additional certification under eIDAS.
Question 6: Under PCI DSS v4.0, multi-factor authentication is required for which access scenario involving FIDO?
- All employee internet browsing
- Administrative access to the cardholder data environment (Correct answer)
- Guest Wi-Fi network access
- Internal HR system access only
Correct answer: Administrative access to the cardholder data environment
PCI DSS v4.0 requires MFA for all administrative access into the cardholder data environment (CDE), which FIDO-based authentication can satisfy.
Question 7: Which principle of the California Consumer Privacy Act (CCPA) is most relevant when a FIDO service provider stores authenticator metadata linked to California residents?
- Right to bear arms
- Right to know what personal information is collected (Correct answer)
- Right to vote in digital elections
- Right to free authentication services
Correct answer: Right to know what personal information is collected
CCPA grants California residents the right to know what personal information businesses collect, which applies to authenticator metadata stored by FIDO service providers.
Under GDPR, how must FIDO authenticators handle biometric data collected during registration?