L21
Compliance: PII, GDPR, locality and PCI DSS
Cram this first — memory hook
Personally Identifiable Information = person; PCI = payment cards; locality = location; sovereignty = governing jurisdiction.
Exam trap
A privacy law, a data category and an industry security standard are not interchangeable labels. Power Usage Effectiveness is not the same abbreviation as .
The slide facts
The compliance section names , General Data Protection Regulation , data locality, data sovereignty and Payment Card Industry Data Security Standard . It does not define or Protected Health Information .
If you have time — extra
Personally Identifiable Information () can identify a person, directly or in combination with other information: a student number linked to a name is a useful classroom example. General Data Protection Regulation () is the European Union's personal-data protection framework; its applicability is a legal question, not something determined only by where one disk sits. Payment Card Industry Data Security Standard () is a payment-card security standard, not a general name for every privacy law. Data locality refers to where information is physically stored or processed; data sovereignty concerns the jurisdictional rules that may govern it. The slide uses helpful simplified examples, but real legal applicability can involve several factors and countries. For this exam, distinguish the category of data, the relevant standard/framework, and the storage/jurisdiction concept. Do not expand this study note into legal advice.
Walkthrough
Ask what kind of information is involved, what the question says about applicable obligations, where it is stored/processed, and which technical controls protect access and movement.