Урок 2 з 4 · 8 хв
Laws and industry rules: GDPR, HIPAA and PCI DSS
What three of the most cited data-protection rules cover, who they apply to, and what they mean in practice. An overview, not legal advice.
Поки що ця сторінка англійською.
Security is not only a technical question. Laws and industry rules decide what organizations must protect, how quickly they must report a breach, and what happens when they fail. Three names come up constantly: the EU’s General Data Protection Regulation (GDPR), the US Health Insurance Portability and Accountability Act (HIPAA), and the Payment Card Industry Data Security Standard (PCI DSS). This lesson explains what each covers. It is general education, not legal advice: when a real decision depends on them, ask a qualified lawyer.
GDPR: personal data of people in the EU
The GDPR has applied since May 2018 to the processing of personal data, meaning any information about an identifiable person. Its reach is wide: under Article 3 it applies not only to organizations established in the EU, but also to organizations elsewhere that offer goods or services to people in the EU or monitor their behavior there. It rests on principles such as lawfulness, data minimization, purpose limitation and security, and it gives people rights: to access their data, correct it, have it erased, and object to some uses.
Two provisions matter most for security teams. Article 32 requires security “appropriate to the risk”, and names encryption and pseudonymization as examples. Article 33 requires notifying the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people. Article 83 sets fines of up to 20 million euros or 4 per cent of worldwide annual turnover, whichever is higher, for the most serious infringements.
HIPAA: health information in the United States
HIPAA protects individually identifiable health information in the US. It applies to “covered entities” (health plans, health-care clearinghouses and most health-care providers) and to their “business associates”, the companies that handle that information on their behalf, such as billing or cloud providers. Its Security Rule, in Part 164 of Title 45 of the US Code of Federal Regulations, requires administrative, physical and technical safeguards for electronic health information: risk analysis, access controls, audit logs, integrity controls and transmission security. A fitness app you download yourself is often outside HIPAA’s scope, which surprises many users: the law follows who holds the data, not just what kind of data it is.
PCI DSS: payment card data
PCI DSS is not a law. It is a security standard set by the PCI Security Standards Council, founded by the major card brands, and it applies to every organization that stores, processes or transmits cardholder data. Card brands and banks enforce it through their contracts. The current version, 4.0.1, covers requirements such as network security controls, protecting stored account data, encrypting card data sent over open networks, strong access control and multi-factor authentication, logging and monitoring, and regular testing. The simplest way for a small business to reduce its PCI burden is not to touch card numbers at all, by letting a payment provider handle them.
What they have in common
| Rule | Protects | Applies to | Enforced by |
|---|---|---|---|
| GDPR | Personal data of people in the EU | Anyone processing it, in or targeting the EU | EU data protection authorities |
| HIPAA | Health information in the US | Covered entities and their business associates | US Department of Health and Human Services |
| PCI DSS | Payment card data | Anyone storing, processing or transmitting it | Card brands and banks, by contract |
All three share the same core ideas: know what sensitive data you hold, collect and keep as little as possible, restrict who can reach it, encrypt it, log access, and have a plan for when something goes wrong. For an individual, they also explain your rights. Under GDPR, for example, you can ask a company what it holds about you, a useful first step against data brokers.
The GDPR also looks beyond the authority. When a breach is likely to result in a high risk to people, Article 34 requires informing the people affected without undue delay. And Article 25 asks for data protection by design and by default: privacy built into systems from the start, with only the data needed for each purpose processed by default.
Головне
- GDPR protects personal data of people in the EU, even when processed from outside the EU.
- GDPR breaches must usually be reported to the authority within 72 hours.
- HIPAA covers US health information held by covered entities and their business associates.
- PCI DSS is a card-industry standard, enforced by contract, for anyone handling card data.
- This is education, not legal advice: consult a lawyer for real decisions.
Перевірте себе
1. A US company sells online to customers in France. Can the GDPR apply to it?
- No, the GDPR only applies to EU companies
- Yes: it applies to organizations offering goods or services to people in the EU — Правильно.
- Only if it has more than 250 employees
- Only for health data
Article 3 extends the GDPR to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior there.
2. What kind of rule is PCI DSS?
- A European law
- A security standard set by the card industry and enforced through contracts — Правильно.
- A US federal health law
- An encryption algorithm
PCI DSS comes from the PCI Security Standards Council, founded by the card brands; banks and card brands enforce it contractually.
3. Under the GDPR, how quickly must a notifiable personal data breach usually be reported to the supervisory authority?
- Within 24 hours
- Within 72 hours of becoming aware of it — Правильно.
- Within 30 days
- Only at the end of the year
Article 33 sets a 72-hour deadline, unless the breach is unlikely to result in a risk to people’s rights and freedoms.
Застосуйте на практиці з FireAI
Застосуйте цей урок на своєму Mac.
- Списки загроз (за бажанням) — Звіряйте свій трафік із публічними даними про загрози, нічого нікуди не надсилаючи.
- Режими безпеки: Дім, Кав’ярня, Параноїк, Під атакою — Підлаштуйте суворість FireAI під те, де насправді перебуває ваш Mac, одним дотиком.
- Who’s online: see every device on your network, and get told when one comes or goes — Know what’s on your Wi-Fi, from the TV to your kid’s phone, without any extra box.
- Дослідіть з’єднання — Вирішуйте, маючи факти перед собою, а не розпливчасте попередження.
Джерела
- GDPR Article 3: Territorial scope (gdpr-info.eu)
- GDPR Article 33: Notification of a personal data breach (gdpr-info.eu)
- GDPR Article 83: General conditions for imposing administrative fines (gdpr-info.eu)
- eCFR: 45 CFR Part 164, Subpart C (HIPAA Security Rule)
- PCI Security Standards Council: PCI DSS
Застосуйте це на своєму Mac
Усі функції безкоштовно на 17 днів, без банківської картки.