Module 4 · Beginner · ⏱ 40 min · 🏆 +160 XP

Compliance & Regulations 101

Every industry has a rulebook. This module gives you the mental map of the major ones — what they protect, who enforces them, how they interconnect, and what happens when organizations ignore them.

GDPRHIPAA PCI-DSSSOX CCPACompliance Frameworks

Learning Objectives

  • Explain why compliance regulations exist and what three forces drive their creation.
  • Describe the scope, key requirements, and penalties of GDPR, HIPAA, PCI-DSS, and SOX.
  • Distinguish between prescriptive and principles-based regulations.
  • Map business activities to their corresponding compliance obligations.
  • Explain the difference between compliance and security.

Lecture

1 · Why Regulations Exist

Three forces create compliance regulations: (1) Market failures — companies won't voluntarily invest in privacy or safety if competitors don't. Regulation levels the playing field. (2) Information asymmetry — consumers cannot evaluate a company's security practices, so regulators require minimum standards. (3) Catastrophic harm — some harms (health data breach, financial fraud) are severe enough that society decides minimum floors are non-negotiable.

2 · Four Major Frameworks — Overview

RegulationProtectsWho Must ComplyMax Penalty
GDPREU personal dataAny org processing EU residents' data€20M or 4% global revenue
HIPAAUS health information (PHI)Healthcare providers, insurers, business associates$1.9M per violation category/year
PCI-DSSPayment card dataAny org storing, processing, or transmitting card data$5,000–$100,000/month; card acceptance revoked
SOXFinancial reporting integrityUS public companies$5M fine; 20 years prison for executives

3 · Compliance vs Security

A critical distinction: compliance is a minimum floor, not a ceiling. An organization can be 100% compliant and still be breached. The goal of compliance is to demonstrate minimum due care to regulators. The goal of security is to actually protect assets. The best programs pursue both — using compliance as the baseline and risk management to go further.

Common mistake: "We passed the audit, so we're secure." Compliance snapshots do not equal continuous security. Audits test what was true on the audit date — not what happens tomorrow.

Theory Deep Dive — Regulatory Landscape

🇪🇺 GDPR — General Data Protection Regulation (Deep Dive)

Enacted in 2018, GDPR is the most comprehensive data privacy law in the world. Its reach extends globally to any organization processing EU residents' personal data.

1
Seven Principles (Article 5)

Lawfulness, Fairness, Transparency — processing must have a legal basis; Purpose Limitation — data collected for one purpose cannot be reused for another; Data Minimisation — collect only what is necessary; Accuracy — keep data correct and up to date; Storage Limitation — do not retain longer than needed; Integrity & Confidentiality — protect data; Accountability — be able to demonstrate compliance.

2
Individual Rights

GDPR grants data subjects: Right of Access, Right to Rectification, Right to Erasure ("Right to be Forgotten"), Right to Data Portability, Right to Object, Rights related to Automated Decision-Making. GRC programs must build processes to honor these rights within statutory timeframes (30 days).

3
Legal Bases for Processing

Six lawful bases: Consent, Contract, Legal Obligation, Vital Interests, Public Task, Legitimate Interests. Marketing commonly uses Consent; payroll uses Contract; security monitoring may use Legitimate Interests. The basis must be documented before processing begins.

4
Breach Notification (Article 33 & 34)

Personal data breaches must be reported to the supervisory authority within 72 hours. Breaches posing high risk to individuals must also be communicated to those individuals without undue delay. GRC teams maintain breach notification procedures as part of incident response plans.

🏥 HIPAA — Health Insurance Portability and Accountability Act

HIPAA (1996, updated through HITECH 2009) protects Protected Health Information (PHI) — any individually identifiable health information. GRC professionals must understand its three rules:

Privacy Rule

Governs how PHI can be used and disclosed. Patients have rights to access their records, request corrections, and receive notice of privacy practices. Minimum Necessary principle — only access the PHI required for the task.

Security Rule

Applies to Electronic PHI (ePHI). Requires Administrative Safeguards (policies, training), Physical Safeguards (facility access controls), and Technical Safeguards (encryption, access controls, audit logs). Risk analysis is explicitly mandated.

Breach Notification Rule

Covered entities must notify affected individuals within 60 days of discovering a breach. Breaches affecting 500+ individuals must be reported to HHS and media. All breaches logged in the Breach Log.

Business Associate Agreements (BAAs)

Any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a Business Associate and must sign a BAA. This is third-party risk management in practice — HIPAA extends to your entire supply chain.

HIPAA does not specify exact controls — it requires organizations to conduct a risk analysis and implement reasonable and appropriate safeguards. This makes HIPAA a principles-based regulation, unlike PCI-DSS which is prescriptive.

💳 PCI-DSS — Payment Card Industry Data Security Standard

PCI-DSS v4.0 is a prescriptive, industry-driven standard developed by Visa, Mastercard, Amex, Discover, and JCB. It has 12 requirements organized into 6 goals:

GoalRequirementsFocus Area
Build & Maintain Secure Networks1–2Firewalls, no vendor defaults
Protect Cardholder Data3–4Encryption at rest and in transit
Vulnerability Management5–6Anti-malware, secure development
Strong Access Control7–9Least privilege, MFA, physical access
Monitor & Test Networks10–11Logging, intrusion detection, pen testing
Information Security Policy12Policies, training, vendor management

PCI-DSS v4.0 introduced "Customized Approach" — organizations can implement controls differently if they can demonstrate equivalent security outcomes, acknowledging that prescriptive rules may not fit all environments.

📊 SOX — Sarbanes-Oxley Act (2002)

SOX was enacted after the Enron and WorldCom collapses. It mandates internal controls over financial reporting (ICFR) and personal accountability for executives. Key GRC-relevant sections:

Section 302 — CEO/CFO Certification

CEOs and CFOs must personally certify the accuracy of financial reports. False certifications carry criminal penalties up to 20 years imprisonment. This creates a direct personal accountability chain from IT controls to the C-suite.

Section 404 — Internal Controls Assessment

Management must assess and report on the effectiveness of internal controls over financial reporting (ICFR). External auditors must attest to this assessment. Most GRC work in public companies ties back to Section 404 requirements.

Section 409 — Real-Time Disclosure

Material changes to financial condition must be disclosed promptly. A major cyber incident affecting financial systems may trigger Section 409 disclosure obligations.

IT General Controls (ITGCs)

SOX auditors focus heavily on ITGCs: change management, access controls, computer operations, and data backup/recovery. Weak ITGCs undermine the reliability of financial reporting controls built on them.

🌐 Prescriptive vs Principles-Based Regulation

Understanding this distinction shapes how you build compliance programs:

AttributePrescriptive (e.g., PCI-DSS)Principles-Based (e.g., HIPAA, GDPR)
SpecificityTells you exactly what to do ("Requirement 1.1: Install firewall at each Internet connection")Tells you the outcome required ("Implement reasonable safeguards")
FlexibilityLow — controls are specified; deviations require documented compensating controlsHigh — organizations choose how to achieve the required outcome
AuditabilityEasy to audit — requirement met or not metRequires judgment — is the approach "reasonable"?
Risk for orgsCompliance theater — tick boxes but miss the spiritJudgment risk — regulators may disagree on what is "reasonable"
Best approachImplement prescribed controls + document rationale for any alternativesConduct thorough risk assessment; document all decisions and reasoning

🗺️ Compliance Program Components — The Eight Pillars

An effective compliance program is not just a policy document. The US Department of Justice and Federal Sentencing Guidelines define an effective compliance program as having eight elements:

1. Standards & Procedures

Written policies that clearly communicate expected behavior and compliance requirements.

2. Program Oversight

A designated compliance officer or committee with adequate authority and resources.

3. Due Diligence in Delegation

Background screening and vetting for individuals given compliance-sensitive roles.

4. Training & Communication

All employees trained on relevant compliance obligations; training documented.

5. Monitoring & Auditing

Regular testing to verify the program works. Audit findings feed continuous improvement.

6. Enforcement & Discipline

Consistent consequences for violations. Without enforcement, policies are theater.

7. Response & Remediation

When violations occur, the organization responds appropriately, remediates, and prevents recurrence.

8. Risk Assessment

Ongoing assessment of compliance risks — identifying where the program is most likely to fail.

🧪 Lab — Match Controls to Compliance Frameworks

Check each item to confirm you understand which compliance framework it satisfies. This mirrors the daily work of a GRC analyst mapping controls to GDPR, HIPAA, PCI-DSS, and ISO 27001 simultaneously.

Scenario — The Hospital HIPAA Breach

Mission Quiz

Mission Complete

← Module 3 Next: Module 5 →