โ† All GCP Flashcard Decks

Regulatory Compliance & Legal Framework Flashcards

7 cards from real GCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Legal Framework flashcards as text
  1. Under HIPAA, which entity is directly responsible for safeguarding protected health information (PHI) when using a cloud service provider?

    Answer: The covered entity and its business associates

    Both covered entities and their business associates share responsibility for PHI protection under HIPAA, requiring a signed Business Associate Agreement (BAA) with cloud providers.

  2. Which U.S. federal law governs the privacy and security of student education records stored in cloud systems?

    Answer: FERPA

    The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records and restricts their disclosure without consent.

  3. A company stores credit card data in Google Cloud Storage. Which compliance standard primarily governs how this data must be secured?

    Answer: PCI DSS

    The Payment Card Industry Data Security Standard (PCI DSS) specifically governs the storage, processing, and transmission of cardholder data.

  4. Under GDPR, what is the maximum timeframe within which a data breach must be reported to the supervisory authority?

    Answer: 72 hours

    GDPR Article 33 requires that personal data breaches be reported to the supervisory authority within 72 hours of becoming aware of the breach.

  5. Which GCP feature helps organizations demonstrate compliance by providing audit logs of all API calls and administrative actions?

    Answer: Cloud Audit Logs

    Cloud Audit Logs records administrative activity and data access events, providing an immutable trail needed for compliance audits.

  6. The Children's Online Privacy Protection Act (COPPA) applies to websites and online services directed at children under what age?

    Answer: Under 13

    COPPA applies to operators of websites and online services directed to children under 13 years of age, requiring parental consent before collecting their data.

  7. Which legal concept requires that data collected for one specified purpose cannot be used for an unrelated purpose without additional consent under GDPR?

    Answer: Purpose limitation

    GDPR's purpose limitation principle (Article 5(1)(b)) mandates that personal data be collected for specified, explicit, and legitimate purposes and not further processed incompatibly.