1. Geo-Restriction & Sanctions advanced

    A trading platform must restrict access by jurisdiction and screen against sanctions lists. What must the architecture handle?

    2 min answer coindcxsanctionsgeoscreening
  2. Geo-Restriction & Sanctions advanced

    Sanctions lists change weekly. What does your architecture need so that is not a compliance risk?

    2 min answer sanctionsscreeningrescreeningevidence
  3. Healthcare Data Protection advanced

    A clinical system holds patient records used for care, research and operational analytics. How should access be architected?

    1 min answer healthcareaccess-controlde-identificationaudit
  4. Healthcare Data Protection advanced

    Why does health data access emphasise auditing over prevention, and what does that require architecturally?

    2 min answer healthcarebreak-glassauditconsent
  5. Lawful Basis & Purpose Limitation advanced

    A recommendation model was trained on browsing histories collected under consent. Several thousand users withdraw that consent. What happens to the model that has already learned from their data, and what makes your answer defensible?

    3 min answer consent-withdrawaltraining-dataprovenanceretraining
  6. Lawful Basis & Purpose Limitation advanced

    Data was collected to fulfil bookings. A team wants to use it to train a recommendation model. What determines whether that is permitted, and how is it enforced?

    2 min answer purpose-limitationlawful-basisconsentenforcement
  7. PCI-DSS Scoping advanced

    A commerce platform wants to reduce the systems in scope for payment card compliance. What architecture achieves that?

    2 min answer pcitokenisationscope-reductionsegmentation
  8. PCI-DSS Scoping advanced

    A merchant keeps card entry inside a provider-hosted iframe and believes its scope is minimal. Customer support uses a screen-sharing tool that can see and record the customer's browser during checkout, calls are recorded, and a session-replay script runs on every page for analytics. Review the arrangement.

    3 min answer pci-dssscopesession-replayscreen-sharing
  9. PCI-DSS Scoping advanced

    A payments platform wants to reduce the systems subject to card-data compliance. What actually reduces scope, and what does not?

    2 min answer razorpaypciscopetokenisation
  10. PCI-DSS Scoping advanced

    An e-commerce platform stores card numbers to support repeat purchases. How do you reduce PCI scope?

    2 min answer pcitokenisationscopepayments
  11. PCI-DSS Scoping advanced

    Your first PCI assessment finds the whole estate in scope. How did that happen and how do you reduce it?

    2 min answer pcisegmentationcompliance
  12. Privacy by Design advanced

    A privacy review finds that a customer's date of birth and partial bank details are visible in session-replay recordings for a subset of users, although the analytics vendor's configuration masks those fields. It affects roughly 3% of sessions, all on one flow. Where do you look, and what does the pattern tell you?

    3 min answer session-replaymaskingthird-party-scriptsdata-minimisation