Data, Privacy & Compliance

Lesson 6 of 6

Lesson 6 — Frameworks, DPIAs and Surviving an Audit

ISO 27001, PCI DSS, HIPAA, SOC 2 — what they are for and how companies prove they comply.

🔴 Advanced 100 XP

Learn it

Different data types attract different rulebooks: payment cards → PCI DSS, US health data → HIPAA, general security management → ISO 27001, service provider assurance → SOC 2.

A DPIA (Data Protection Impact Assessment) is a written risk assessment required before high-risk processing such as large-scale profiling or monitoring.

An audit checks evidence: policies, logs, tickets, access reviews and training records — saying 'we're careful' is not evidence.

Key terms

DPIA
Documented risk assessment required before high-risk processing.
ISO 27001
International standard for an information security management system.
PCI DSS
Security standard for handling payment card data.
SOC 2
Independent auditor report on a service provider's controls.
Scope reduction
Designing systems so regulated data never enters them.
Access review
Periodic check that each account still needs its permissions.

Which rulebook applies?

One company, four systems.

  1. 1Online shop checkout: PCI DSS — reduce scope by using a hosted payment field so card numbers never hit your servers.
  2. 2Employee records: GDPR — lawful basis is legal obligation/contract, tight retention.
  3. 3US clinic integration: HIPAA — business associate agreement and audit trails required.
  4. 4Selling B2B SaaS: SOC 2 report requested by enterprise customers before signing.

A DPIA skeleton

markdown# DPIA: AI attendance camera in corridors
1. Processing: facial recognition of pupils, 08:00-16:00
2. Necessity: could a card tap achieve the same? YES -> less intrusive
3. Data: biometric (special category), 1,200 pupils, children
4. Risks: misidentification, chilling effect, breach of biometrics
5. Mitigations: none sufficient for biometrics of children
6. Decision: DO NOT PROCEED - use card taps
7. Signed off: DPO, 2026-02-04

A good DPIA can end with 'do not build this'. That is a successful outcome, not a failure.

Try it

Match each data type to the framework most associated with it.

Credit card numbers
US patient health records
Information security management
SaaS vendor assurance report
EU personal data rights

Challenge

Your company wants to introduce AI monitoring of employee laptops (screenshots every 5 minutes). Run a DPIA in writing: describe the processing, test necessity, list risks and mitigations, and give a reasoned decision.

Pick whichever way suits you — every mode earns the same bonus XP.

Write at least 40 more characters to submit.

Mark your own work

Guided walkthrough — 0/3 clues revealed

  1. Clue 1 locked — reveal it only if you get stuck.
  2. Clue 2 locked — reveal it only if you get stuck.
  3. Clue 3 locked — reveal it only if you get stuck.

Each clue costs 5 XP (never below 25 XP). You'd earn 50 XP right now.

Quiz time

Question 1 of 4Score 0

A DPIA is required when processing is…