Slayer CPA
SectionsBlogLog In
Information Systems and Controls/Blueprint/2.E

Privacy requirements

Area 2: Security, Confidentiality, and Privacy (35-45%)

Your Progress

0 of 95 questions attempted

Topics

  • Privacy regulations (GDPR, CCPA)
  • Privacy impact assessments
  • Data subject rights and consent

Lessons

  • Privacy Requirements and Data Protection

Study Frameworks

Privacy Regulation Applicability

Does the organization process personal data of EU/EEA residents?
Yes
GDPR applies — consent or legal basis required, data subject rights, 72-hour breach notification, DPO may be required
No
Does the organization collect personal information of California residents and meet revenue/data thresholds?
Yes
CCPA/CPRA applies — right to know, delete, opt-out of sale; no private right of action except for breaches
No
Does the organization handle protected health information (PHI) as a covered entity or business associate?
Yes
HIPAA applies — Privacy Rule, Security Rule, Breach Notification Rule; BAAs required with business associates
No
General data protection best practices apply — monitor for state-specific privacy laws and industry regulations

Privacy Regulation Comparison

FeatureGDPRCCPA/CPRAHIPAA
JurisdictionEU/EEA residentsCalifornia residentsUS healthcare (covered entities and BAs)
Data coveredAll personal dataPersonal information linked to consumer/householdProtected health information (PHI)
Legal basis requiredYes (consent, contract, legitimate interest, etc.)No (opt-out model)Treatment, payment, operations (no consent for TPO)
Right to deleteYes (right to erasure)YesLimited (amendment, not deletion)
Breach notification72 hours to supervisory authorityWithout unreasonable delay60 days to individuals, HHS, and media if >500
PenaltiesUp to 4% of global annual revenue or EUR 20M$2,500 per violation; $7,500 if intentional$100-$50,000 per violation; $1.5M annual cap per category
Practice These Topics(95 questions)