Data Subject Rights

Access, correction, portability and erasure across systems that never planned for them.

4Questions
6Flashcards
4Terms
Regulatory & Data Protection Architecture

Neighbouring topics

Regulatory & Data Protection Architecture

General material on designing under legal and regulatory obligation.

3 quiz 9 cards 2 terms

Privacy by Design

Data minimisation, default protection and purpose binding as structural decisions.

6 quiz 10 cards 1 terms

Lawful Basis & Purpose Limitation

Why you may hold the data, and why that forbids the second use somebody proposed.

3 quiz 8 cards 4 terms

Consent Architecture

Capturing, versioning and propagating consent to every system that acts on the data.

5 quiz 9 cards 3 terms

Data Residency

Keeping data within a jurisdiction, including backups, logs and support access.

7 quiz 11 cards 2 terms

Digital Sovereignty

Control over data, operations and the operator, beyond where the bytes physically sit.

4 quiz 9 cards 3 terms

Cross-Border Transfer

The legal mechanism that permits data to leave, and the architecture that respects it.

4 quiz 6 cards 4 terms

PCI-DSS Scoping

Segmentation and tokenisation to shrink what is in scope, because scope is the cost.

6 quiz 8 cards 4 terms

Healthcare Data Protection

PHI handling, minimum necessary access, and audit expectations in clinical systems.

4 quiz 10 cards 3 terms

Financial Services Regulation

Operational resilience, payment rules and supervisory expectations as design inputs.

4 quiz 11 cards 3 terms

Records Retention & Legal Hold

Keeping what must be kept, deleting what must go, and freezing both on demand.

5 quiz 9 cards 4 terms

Erasure vs Immutability

Deletion obligations against event logs, backups and ledgers designed never to forget.

4 quiz 12 cards 2 terms

Pseudonymisation

Separating identity from record, and the re-identification risk that remains.

4 quiz 9 cards 4 terms

Privacy-Enhancing Technologies

Differential privacy, secure enclaves and federated computation, and what each buys.

4 quiz 8 cards 5 terms

Regulatory Reporting Pipelines

Submissions with fixed deadlines, fixed formats, and a regulator who audits the lineage.

4 quiz 6 cards 4 terms

Sector Cloud Rules

Regulator expectations for cloud use, exit plans and material outsourcing notification.

4 quiz 7 cards 4 terms

Exit & Concentration Risk

Being able to leave a provider, and what the regulator asks when you cannot.

6 quiz 9 cards 2 terms

Third-Party Risk

Assessing, contracting and monitoring the vendors your architecture now depends on.

5 quiz 7 cards 4 terms

Geo-Restriction & Sanctions

Blocking access by jurisdiction, and the accuracy and evasion problems that come with it.

4 quiz 10 cards 3 terms