Lesson 6 of 6
Lesson 6 — Frameworks, DPIAs and Surviving an Audit
ISO 27001, PCI DSS, HIPAA, SOC 2 — what they are for and how companies prove they comply.
Learn it
Different data types attract different rulebooks: payment cards → PCI DSS, US health data → HIPAA, general security management → ISO 27001, service provider assurance → SOC 2.
A DPIA (Data Protection Impact Assessment) is a written risk assessment required before high-risk processing such as large-scale profiling or monitoring.
An audit checks evidence: policies, logs, tickets, access reviews and training records — saying 'we're careful' is not evidence.
Key terms
- DPIA
- Documented risk assessment required before high-risk processing.
- ISO 27001
- International standard for an information security management system.
- PCI DSS
- Security standard for handling payment card data.
- SOC 2
- Independent auditor report on a service provider's controls.
- Scope reduction
- Designing systems so regulated data never enters them.
- Access review
- Periodic check that each account still needs its permissions.
Which rulebook applies?
One company, four systems.
- 1Online shop checkout: PCI DSS — reduce scope by using a hosted payment field so card numbers never hit your servers.
- 2Employee records: GDPR — lawful basis is legal obligation/contract, tight retention.
- 3US clinic integration: HIPAA — business associate agreement and audit trails required.
- 4Selling B2B SaaS: SOC 2 report requested by enterprise customers before signing.
A DPIA skeleton
markdown# DPIA: AI attendance camera in corridors
1. Processing: facial recognition of pupils, 08:00-16:00
2. Necessity: could a card tap achieve the same? YES -> less intrusive
3. Data: biometric (special category), 1,200 pupils, children
4. Risks: misidentification, chilling effect, breach of biometrics
5. Mitigations: none sufficient for biometrics of children
6. Decision: DO NOT PROCEED - use card taps
7. Signed off: DPO, 2026-02-04A good DPIA can end with 'do not build this'. That is a successful outcome, not a failure.
Try it
Match each data type to the framework most associated with it.
Challenge
Your company wants to introduce AI monitoring of employee laptops (screenshots every 5 minutes). Run a DPIA in writing: describe the processing, test necessity, list risks and mitigations, and give a reasoned decision.
Pick whichever way suits you — every mode earns the same bonus XP.
Write at least 40 more characters to submit.
Mark your own work
Guided walkthrough — 0/3 clues revealed
- Clue 1 locked — reveal it only if you get stuck.
- Clue 2 locked — reveal it only if you get stuck.
- Clue 3 locked — reveal it only if you get stuck.
Each clue costs 5 XP (never below 25 XP). You'd earn 50 XP right now.