SDI Regulatory Compliance & Legal Framework 3 — Questions and Answers
Question 1: A service desk team in the US handles calls for EU residents. Which regulation most directly governs how personal data about those EU callers must be handled?
- CCPA
- GDPR (Correct answer)
- PIPEDA
- GLBA
Correct answer: GDPR
GDPR has extraterritorial reach and applies to processing of personal data of EU residents regardless of where the processing organization is located.
Question 2: Under software asset management (SAM) best practices, what is the primary legal risk of deploying more software licenses than purchased?
- Vendor audit findings leading to back-payments and penalties (Correct answer)
- Loss of right to future software upgrades
- Mandatory migration to open-source alternatives
- Automatic SLA breach notifications to regulators
Correct answer: Vendor audit findings leading to back-payments and penalties
Under-licensing exposes organizations to vendor audits that can result in significant back-payments for unpaid licenses plus contractual penalties.
Question 3: Which framework provides a set of controls specifically designed to protect information security and is frequently referenced in compliance audits alongside ISO 20000?
- COBIT
- ISO/IEC 27001 (Correct answer)
- ITIL 4
- NIST SP 800-53
Correct answer: ISO/IEC 27001
ISO/IEC 27001 defines requirements for an information security management system (ISMS) and is commonly audited in parallel with ISO 20000 for IT service management compliance.
Question 4: FERPA primarily restricts the disclosure of educational records and applies directly to service desks operating in which sector?
- Financial services
- Healthcare
- Higher education institutions (Correct answer)
- Federal government agencies
Correct answer: Higher education institutions
FERPA (Family Educational Rights and Privacy Act) protects student educational records and applies to schools, colleges, and universities that receive federal funding.
Question 5: A service desk outsources ticket processing to a third-party vendor in another country. Under GDPR, this vendor is classified as a:
- Data controller
- Data processor (Correct answer)
- Data subject
- Supervisory authority
Correct answer: Data processor
A third party that processes personal data on behalf of and under instruction from another organization is a data processor under GDPR.
Question 6: Which principle of the UK Data Protection Act / GDPR states that personal data should only be kept for as long as necessary?
- Data minimization
- Purpose limitation
- Storage limitation (Correct answer)
- Accuracy
Correct answer: Storage limitation
The storage limitation principle requires that personal data not be kept in a form that identifies individuals for longer than necessary for the stated purpose.
Question 7: In the context of service desk operations, a 'right to erasure' request (also called 'right to be forgotten') obliges the service desk to:
- Archive the individual's records in a secure cold-storage system
- Delete personal data without undue delay when there is no overriding legitimate ground to retain it (Correct answer)
- Anonymize the data and retain it for statistical reporting
- Notify all downstream vendors before any deletion occurs
Correct answer: Delete personal data without undue delay when there is no overriding legitimate ground to retain it
GDPR Article 17 grants individuals the right to have their personal data erased without undue delay when certain conditions are met and no overriding legal basis to retain it exists.
A service desk team in the US handles calls for EU residents.
Which regulation most directly governs how personal data about those EU callers must be handled?