Saltar para o conteúdo
← Compliance, ethics and future trends

Lição 2 de 4 · 8 min

Laws and industry rules: GDPR, HIPAA and PCI DSS

What three of the most cited data-protection rules cover, who they apply to, and what they mean in practice. An overview, not legal advice.

Por agora esta página está em inglês.

Security is not only a technical question. Laws and industry rules decide what organizations must protect, how quickly they must report a breach, and what happens when they fail. Three names come up constantly: the EU’s General Data Protection Regulation (GDPR), the US Health Insurance Portability and Accountability Act (HIPAA), and the Payment Card Industry Data Security Standard (PCI DSS). This lesson explains what each covers. It is general education, not legal advice: when a real decision depends on them, ask a qualified lawyer.

GDPR: personal data of people in the EU

The GDPR has applied since May 2018 to the processing of personal data, meaning any information about an identifiable person. Its reach is wide: under Article 3 it applies not only to organizations established in the EU, but also to organizations elsewhere that offer goods or services to people in the EU or monitor their behavior there. It rests on principles such as lawfulness, data minimization, purpose limitation and security, and it gives people rights: to access their data, correct it, have it erased, and object to some uses.

Two provisions matter most for security teams. Article 32 requires security “appropriate to the risk”, and names encryption and pseudonymization as examples. Article 33 requires notifying the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people. Article 83 sets fines of up to 20 million euros or 4 per cent of worldwide annual turnover, whichever is higher, for the most serious infringements.

HIPAA: health information in the United States

HIPAA protects individually identifiable health information in the US. It applies to “covered entities” (health plans, health-care clearinghouses and most health-care providers) and to their “business associates”, the companies that handle that information on their behalf, such as billing or cloud providers. Its Security Rule, in Part 164 of Title 45 of the US Code of Federal Regulations, requires administrative, physical and technical safeguards for electronic health information: risk analysis, access controls, audit logs, integrity controls and transmission security. A fitness app you download yourself is often outside HIPAA’s scope, which surprises many users: the law follows who holds the data, not just what kind of data it is.

PCI DSS: payment card data

PCI DSS is not a law. It is a security standard set by the PCI Security Standards Council, founded by the major card brands, and it applies to every organization that stores, processes or transmits cardholder data. Card brands and banks enforce it through their contracts. The current version, 4.0.1, covers requirements such as network security controls, protecting stored account data, encrypting card data sent over open networks, strong access control and multi-factor authentication, logging and monitoring, and regular testing. The simplest way for a small business to reduce its PCI burden is not to touch card numbers at all, by letting a payment provider handle them.

What they have in common

RuleProtectsApplies toEnforced by
GDPRPersonal data of people in the EUAnyone processing it, in or targeting the EUEU data protection authorities
HIPAAHealth information in the USCovered entities and their business associatesUS Department of Health and Human Services
PCI DSSPayment card dataAnyone storing, processing or transmitting itCard brands and banks, by contract

All three share the same core ideas: know what sensitive data you hold, collect and keep as little as possible, restrict who can reach it, encrypt it, log access, and have a plan for when something goes wrong. For an individual, they also explain your rights. Under GDPR, for example, you can ask a company what it holds about you, a useful first step against data brokers.

The GDPR also looks beyond the authority. When a breach is likely to result in a high risk to people, Article 34 requires informing the people affected without undue delay. And Article 25 asks for data protection by design and by default: privacy built into systems from the start, with only the data needed for each purpose processed by default.

A reter

  • GDPR protects personal data of people in the EU, even when processed from outside the EU.
  • GDPR breaches must usually be reported to the authority within 72 hours.
  • HIPAA covers US health information held by covered entities and their business associates.
  • PCI DSS is a card-industry standard, enforced by contract, for anyone handling card data.
  • This is education, not legal advice: consult a lawyer for real decisions.

Teste-se

  1. 1. A US company sells online to customers in France. Can the GDPR apply to it?

    • No, the GDPR only applies to EU companies
    • Yes: it applies to organizations offering goods or services to people in the EU — Certo.
    • Only if it has more than 250 employees
    • Only for health data

    Article 3 extends the GDPR to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior there.

  2. 2. What kind of rule is PCI DSS?

    • A European law
    • A security standard set by the card industry and enforced through contracts — Certo.
    • A US federal health law
    • An encryption algorithm

    PCI DSS comes from the PCI Security Standards Council, founded by the card brands; banks and card brands enforce it contractually.

  3. 3. Under the GDPR, how quickly must a notifiable personal data breach usually be reported to the supervisory authority?

    • Within 24 hours
    • Within 72 hours of becoming aware of it — Certo.
    • Within 30 days
    • Only at the end of the year

    Article 33 sets a 72-hour deadline, unless the breach is unlikely to result in a risk to people’s rights and freedoms.

Praticar com o FireAI

Ponha esta lição em prática no seu próprio Mac.

Fontes

Ponha em prática no seu Mac

Experimente todas as funcionalidades grátis durante 17 dias, sem cartão.

Transferir para Mac Docs