Regulatory and Legal Compliance Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory and Legal Compliance flashcards as text
Under GDPR, what is the maximum timeframe within which a data breach must be reported to the supervisory authority after the controller becomes aware of it?
Answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
The Children's Online Privacy Protection Act (COPPA) applies to websites and online services directed to children under what age?
Answer: 13
COPPA protects the online privacy of children under 13 by requiring verifiable parental consent before collecting their personal information.
An organization wants to transfer personal data from the EU to a country without an adequacy decision. Which mechanism provides an appropriate safeguard under GDPR?
Answer: Standard Contractual Clauses (SCCs)
Standard Contractual Clauses (SCCs) are pre-approved contractual mechanisms that provide adequate safeguards for transferring personal data outside the EU.
Which provision of the Gramm-Leach-Bliley Act (GLBA) requires financial institutions to develop a written information security program?
Answer: Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to implement a comprehensive written information security program to protect customer financial information.
In a compliance program, a 'whistleblower hotline' is primarily designed to satisfy which element of an effective compliance program?
Answer: Reporting mechanisms
Whistleblower hotlines serve as anonymous reporting mechanisms that allow employees to report potential violations without fear of retaliation.
A U.S. company's foreign subsidiary pays bribes to a government official to win a contract. Which U.S. law has most likely been violated?
Answer: Foreign Corrupt Practices Act (FCPA)
The FCPA prohibits U.S. companies and their subsidiaries from bribing foreign government officials to obtain or retain business.
Which concept in regulatory compliance refers to the practice of treating similar regulatory requirements across different jurisdictions as a single, unified standard?
Answer: Harmonization
Harmonization is the process of aligning different regulatory requirements across jurisdictions into a common standard to reduce compliance complexity.