A developer accidentally commits an AWS access key to a public GitHub repository. Under which framework's breach response procedures should the company notify affected parties if customer data was accessed?
-
A
PCI DSS only, if payment data is involved
-
B
No notification is required for key exposure
-
C
GDPR if EU personal data was exposed, and applicable US state breach laws
-
D
Only HIPAA applies to all data breaches