Compliance & governance standards
Two very different things developers still get asked about: the privacy regulations that constrain what you may do with personal data, and the notation used to specify business processes precisely. Interviewers raise them because both change the requirements before a line of code is written.
on this pageshowhide
guide
overview
~1 minCompliance comes up in engineering interviews because regulations and standards change the requirements before any design exists. A privacy law decides which personal data you may collect, how long you may keep it and what a user can make you do with it. A security framework decides which controls an auditor will ask you to prove. A process notation decides whether a workflow an analyst drew can be run by an engine at all. Interviewers rarely test article numbers. They want to see that you can turn a legal or audit requirement into concrete system behaviour (a deletion path, a consent record, a retention job, a control with evidence behind it) and that you know where the requirement stops. The hub groups four areas that share that effect and little else. [GDPR](/topics/proto-gdpr) is the EU regulation built on lawful bases, data subject rights, breach notification and transfer rules. [CCPA](/topics/proto-ccpa), together with the CPRA's amendments, is California's opt-out model with its own thresholds, rights and enforcement. [Infosec frameworks and certification](/topics/proto-infosec-standards) covers ISO 27001, SOC 2, NIST, PCI DSS, CIS and HIPAA: how a security programme is organised around risk, controls, evidence and audits. [BPMN](/topics/proto-bpmn) is the odd one out, a notation rather than a rule set, used to specify a business process precisely enough to automate it. Start with GDPR's definitions and lawful bases, since most privacy vocabulary originates there, then read CCPA as a comparison against it rather than as a second list to memorise. Take the infosec frameworks next if the role touches security, audits or regulated customers. BPMN stands on its own; pick it up when workflow engines or process automation are part of the job. Junior questions ask what a term means; senior ones hand you a scenario where two obligations collide.
primer
A few ideas run under all four sections. With them in place, most questions below become a matter of classifying the situation and applying the right rule. - **Compliance is an input to design, not a review at the end.** Where personal data lives, how it is keyed, and whether each record carries its purpose and collection date decide how cheap deletion, export and retention will be later. Retrofitting those onto a schema that never tracked them is the expensive version of every answer in this hub. - **Classify before you apply a rule.** Almost every question starts with a classification: is this personal data, is this company in scope, is this vendor a controller, processor, service provider or third party, is this remote access a transfer, is this incident a breach, is this a certification or an attestation. Get the category right and the obligation usually follows; get it wrong and a confident answer is confidently wrong. - **Personal data is wider than obvious identifiers.** Anything that can single out a person, directly or by combination, counts. Hashing, tokenising or pseudonymising reduces risk but leaves the data in scope; only data that can no longer be linked back to anyone leaves it. - **The two privacy models start from opposite defaults.** GDPR forbids processing until a lawful basis applies; CCPA permits collection with notice and gives consumers ways to object. That single difference shapes product defaults, consent screens and how a shared pipeline must branch. - **Rights become pipelines with deadlines.** Access, deletion, correction and opt-out requests each need intake, identity verification, fulfilment across every store and vendor, and a record that it happened. Exceptions such as legal retention duties make deletion selective rather than all or nothing. - **Security frameworks share one loop.** Assess risk, choose controls to treat it, operate them, collect evidence, get audited, improve. The frameworks differ in who evaluates you, what the result is called and how prescriptive the control list is, but the loop is the same. - **A model is not an execution.** In BPMN a diagram that communicates a process to people is not yet one an engine can run; execution needs exact conditions, data and implementations. The same gap between paper and practice reappears in the audit world as control design versus operating effectiveness.
- Personal data
- Any information relating to an identified or identifiable living person, including identifiers that work only in combination with other data. CCPA's equivalent term is personal information.
- Pseudonymisation
- Replacing direct identifiers so data cannot be tied to a person without separately held information. It lowers risk but the data remains personal data.
- Controller
- The party that decides why and how personal data is processed and carries primary GDPR accountability for that processing.
- Processor
- A party that handles personal data only on a controller's documented instructions, under a contract that limits what it may do with it.
- Lawful basis
- One of the grounds GDPR lists that must justify a processing activity before it starts; consent is one of them, not the default.
- Data subject request
- A request from an individual to exercise a privacy right such as access, deletion, correction or opt-out, answered within a statutory deadline.
- Selling and sharing
- CCPA terms for disclosing personal information to a third party for value, or for cross-context behavioural advertising; both trigger the consumer's opt-out right.
- Service provider
- Under CCPA, a vendor bound by contract to process personal information only for the business's purposes; disclosures to it are not sales.
- Opt-out preference signal
- A browser or device setting that tells every site a consumer does not want their data sold or shared, which covered businesses must honour.
- Adequacy decision
- A European Commission finding that a non-EU country protects personal data well enough for transfers to proceed without extra safeguards.
- Standard contractual clauses
- Commission-approved contract terms that exporter and importer sign to provide safeguards for a transfer outside the EU when no adequacy decision exists.
- Security control
- A safeguard, technical, administrative or physical, chosen to reduce a specific risk, and the unit auditors test and ask evidence for.
- Residual risk
- The risk left after controls are applied, which a named owner must formally accept, treat further or avoid.
- Certification versus attestation
- Certification is an accredited body confirming conformity to a standard; attestation is an independent auditor's opinion on controls against criteria, delivered as a report.
- Statement of Applicability
- The ISO 27001 document listing which Annex A controls apply, whether each is implemented, and why any are excluded.
- Token
- The BPMN concept of a marker moving along sequence flows through one process instance; gateways and events are defined by what they do to tokens.
The four sections look unrelated, but three of them overlap heavily and the fourth supplies a way to describe the work the other three create. ### Two privacy laws, one data estate [GDPR](/topics/proto-gdpr) and [CCPA](/topics/proto-ccpa) regulate the same raw material, so a product with EU and US users usually runs one data inventory, one request pipeline and one vendor register, then branches where the laws differ: defaults, the rights offered, deadlines, verification and the classification of each vendor. The [comparison section](/topics/proto-ccpa-vs-gdpr-cpra) is where that branching is worked out, and the CPRA amendments are why the gap narrowed. Neither law tells you which encryption to use; both expect security appropriate to the risk, and both punish its absence, GDPR through fines and breach duties and CCPA through a private right of action after certain breaches. ### Frameworks supply the security the laws require That is where [infosec frameworks](/topics/proto-infosec-standards) connect. ISO 27001, SOC 2 and NIST give a programme structure and a way to prove it to customers and auditors. PCI DSS applies mainly through card-payment contracts rather than statute, and HIPAA is US law for health data; both are sector rules that sit on top of the general programme. [Risk management](/topics/proto-infosec-standards-risk-management) is the shared root: a risk assessment justifies which controls exist, and the same reasoning underpins GDPR's risk-based approach to breach notification and security measures. ### BPMN describes the processes the others demand Every obligation above becomes a process: handling a deletion request, escalating a breach within a deadline, approving a risk acceptance, collecting audit evidence. [BPMN](/topics/proto-bpmn) is the notation for specifying such a process unambiguously, and for automating it on a workflow engine. Its questions stand on their own, but its lessons about the gap between a drawing and an executable model mirror the audit distinction between a control that is designed and one that actually runs.
- Scope and Key Definitions →
Personal data, controller, processor and territorial reach decide whether any later rule applies; most privacy vocabulary in the hub starts here.
- Lawful Bases for Processing →
The justification every processing activity needs, and the reason consent is often the wrong choice rather than the safe one.
- Data Subject Rights →
Where the law turns into engineering: access and erasure requests, deadlines, and the exceptions that make deletion selective.
- GDPR Comparison & CPRA Changes →
Read CCPA as a set of differences from GDPR; this section names them and shows where a shared pipeline must branch.
- Security Risk Management →
Risk assessment and treatment are the common root of ISO 27001, SOC 2, NIST and HIPAA; learn it before any single framework.
- Flows and Connections →
Sequence flow, message flow and the token they carry are the grammar every other BPMN element is defined against.
Reaching for consent as the default GDPR basis; it is only right when the person has a genuine choice, and withdrawal then stops the processing.
Calling hashed or tokenised identifiers anonymous; if anyone can re-link them, the data is still personal and still in scope.
Saying a company has a SOC 2 certification; SOC 2 produces an auditor's attestation report, while ISO 27001 is the certifiable standard.
Treating an erasure request as delete everything, or as delete nothing because some records must be kept; the answer is a per-category split, plus notice to downstream recipients.
Assuming GDPR binds only EU-based companies, or that data hosted in the EU cannot be transferred; remote access from abroad can itself be a transfer.
Reading addressable HIPAA specifications as optional; each must be assessed, and not implementing one requires a documented reason and usually an alternative.
Quoting CCPA penalty amounts or thresholds as fixed figures; several are adjusted periodically, so name the year of the figure you cite.
Presenting implemented Annex A controls as ISO 27001 readiness while the management system clauses (scope, leadership, review, improvement) are missing.
Labelling a vendor processor or service provider because the contract says so; the role follows from who decides purposes and means, and under CCPA cross-context advertising disqualifies it.
In BPMN, drawing a sequence flow between pools or modelling an outside organisation as a lane; separate participants talk only through message flows.
The same handful of choices recur across the sections, and naming the one you are making usually earns more credit than the rule you cite. - **One global programme versus per-jurisdiction handling.** Applying the strictest rule everywhere is simpler to build and audit but can switch off features that are lawful in a looser regime. Branching by jurisdiction keeps those features but multiplies the logic, the tests and the ways a user can be misclassified. - **Retention versus minimisation.** Analytics, fraud and legal teams want data kept; the privacy laws want it kept only as long as a stated purpose needs. The defensible answer sets a retention period per category, documents why, and enforces it with jobs rather than intentions. - **Verification strength versus request friction.** Weak identity checks leak data to impostors through access requests; heavy checks obstruct legitimate requests and can themselves breach the rules on how easy exercising a right must be. - **Readable model versus executable model.** A BPMN diagram tuned for business readers omits the conditions, data and implementations an engine needs; adding them makes it precise and harder for non-developers to review. - **Encrypt or accept exposure.** Strong encryption with separately held keys costs effort and key management, but it is often what turns a stolen device from a notifiable breach into a recorded incident.
Several question shapes recur across all four sections; recognising the shape tells you what the interviewer is checking. - **Classify, then apply.** Is it personal data, is the company a covered business, is the vendor a processor or a third party, is it a transfer, is it a breach, which BPMN element is this. The answer hinges on the classification step, so say it out loud. - **Two obligations collide.** Erasure against tax retention, deletion against an open dispute, opt-out against a vendor contract. The expected answer splits the data and states what each part is kept for, rather than letting one obligation win outright. - **Paper versus practice.** Annex A controls versus a working ISMS, control design versus operating effectiveness, an addressable specification versus an implemented one, a diagram versus an executable process. Interviewers check that you know a document alone is not compliance. - **The clock.** Breach notification windows, request response deadlines and extensions. Know when each clock starts, not only its length, since start points are where scenario questions set their traps. - **Same pipeline, branch points.** When GDPR and CCPA both apply, questions ask which parts of intake, verification and fulfilment can be shared and where the regimes force different behaviour.
explore
- GDPR36 questions
- Scope and Key Definitions6 questions
- Lawful Bases for Processing6 questions
- Data Subject Rights6 questions
- Consent Requirements6 questions
- Breach Notification and DPO6 questions
- Cross-Border Transfers and Penalties6 questions
- CCPA34 questions
- Scope and Thresholds6 questions
- Consumer Rights6 questions
- Sale & Sharing Opt-Outs6 questions
- Business Obligations6 questions
- Enforcement and Penalties5 questions
- GDPR Comparison & CPRA Changes5 questions
- BPMN30 questions
- Events5 questions
- Activities and Tasks5 questions
- Gateways5 questions
- Flows and Connections5 questions
- Pools and Swimlanes5 questions
- Executable Processes5 questions
- Infosec Frameworks & Certification42 questions
- Security Risk Management5 questions
- ISO 27001 & 270025 questions
- SOC 25 questions
- NIST CSF & 800-Series5 questions
- PCI DSS6 questions
- HIPAA Security Rule & HITRUST5 questions
- CIS Controls & Hardening Baselines5 questions
- Audit & Attestation Operations6 questions
questions
142 · 4 sectionsUnder the GDPR, what counts as a personal data breach, and does it only mean data being stolen?
basics
~20 sUnder GDPR Art. 4(12), a personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It covers confidentiality, integrity and availability failures, not just theft.
Under the GDPR, what four conditions make consent valid, and why does a pre-ticked box fail them?
basics
~20 sGDPR Art. 4(11) requires consent to be freely given, specific, informed and unambiguous, expressed by a statement or clear affirmative action. A pre-ticked box records the controller's choice, not the person's act, so Recital 32 excludes it.
Under the GDPR, what does a subscriber's right of access entitle them to receive, and by when must the controller respond?
basics
~20 sUnder GDPR Art. 15, the person gets confirmation that their data is processed, a copy of it, and context: purposes, categories, recipients, retention, source, rights and automated decisions. Art. 12(3) requires a reply within one month of receipt, extendable by two further months.
Under GDPR Art. 6(1), what are the six lawful bases for processing, and why is consent not the default?
basics
~20 sGDPR Art. 6(1) lists consent, contract, legal obligation, vital interests, public task and legitimate interests. None ranks above the others; consent fits only when the person has a real choice, because it can be withdrawn and processing must then stop.
Under the GDPR, is a table of SHA-256-hashed email addresses handed to an ad partner still personal data?
basics
~20 sYes. A hashed email is a stable identifier that anyone holding the address can recompute and match, so under the GDPR it is pseudonymised data, which Recital 26 treats as personal data. Only data rendered anonymous leave the Regulation's scope.
Under the CCPA, what must a mobile banking app's notice at collection tell users at sign-up, and where must it appear?
basics
~20 sUnder the CCPA, the notice at collection lists the personal and sensitive personal information categories, their purposes, whether each is sold or shared and how long each is kept, shown at or before collection (Civil Code 1798.100(a); 11 CCR 7012).
Under the CCPA, what can a consumer learn through the right to know, and how do 'categories' differ from 'specific pieces' of personal information?
basics
~20 sUnder Civil Code 1798.110 and 1798.115, a consumer can learn the categories of personal information collected, its sources, purposes and recipients by category, what was sold, shared or disclosed, and the specific pieces: the actual data values held.
Under the CCPA as amended by the CPRA, what is the difference between 'selling' and 'sharing' personal information?
basics
~20 sUnder Civil Code 1798.140, selling is making personal information available to a third party for monetary or other valuable consideration; sharing is making it available to a third party for cross-context behavioural advertising, whether or not anything is paid.
Under the CCPA as amended by the CPRA, what makes an organisation a 'business' that the law applies to?
basics
~20 sUnder Civil Code 1798.140(d), a CCPA business is a for-profit entity that collects consumers' personal information, determines its purposes and means, does business in California and meets any one of three thresholds: revenue, data volume or data revenue.
How does the CCPA's opt-out model differ from the GDPR's lawful-basis model, and what does that mean for product defaults?
basics
~20 sUnder the GDPR, processing is unlawful until one of six Art. 6(1) bases applies, so consent-based features start off; under the CCPA, collection with notice is allowed and consumers opt out of sale, sharing and some sensitive-data uses.
In BPMN 2.0, how do the user, manual, service, script, business-rule, send and receive task types differ?
basics
~20 sIn BPMN 2.0 the task type says who performs the work: a user task is human work the engine tracks, a manual task is human work it does not, service, script and business-rule tasks are automated, and send and receive tasks exchange messages.
In BPMN 2.0, how do start, intermediate and end events differ, and what makes an event catching rather than throwing?
basics
~20 sIn BPMN 2.0 a start event (thin circle) only catches the trigger that creates a process instance, an end event (thick circle) only throws a result as it consumes a token, and an intermediate event (double circle) may catch or throw.
In BPMN 2.0, how do sequence flow, message flow and association differ in notation and in meaning?
basics
~20 sIn BPMN 2.0 a sequence flow (solid line, solid arrowhead) orders flow nodes inside one process and carries the token; a message flow (dashed, open circle to open arrowhead) passes a message between pools; an association (dotted) only attaches information.
In BPMN 2.0, how do exclusive, inclusive and parallel gateways behave when they split the flow and when they join it?
basics
~20 sIn BPMN 2.0 an exclusive gateway takes exactly one branch and merges without waiting; an inclusive gateway takes every branch whose condition is true and joins those still expected; a parallel gateway takes all branches and waits for all.
In BPMN 2.0, what is the difference between a pool and a lane in a hiring process diagram?
basics
~20 sIn BPMN 2.0 a pool is the graphical form of a participant, such as the employer or the candidate, and contains at most one process; a lane is a sub-partition inside that process, such as Recruiting or Hiring manager.
In security compliance, how do certification (ISO/IEC 27001), attestation (SOC 2) and self-assessment differ in who evaluates and what results?
basics
~20 sCertification means an independent body audits you against a standard and issues a certificate, as with ISO/IEC 27001. Attestation means a CPA practitioner gives an opinion against criteria, as in SOC 2. Self-assessment means you evaluate yourself and an official affirms it.
What are the CIS Critical Security Controls v8.1, and how are their 18 Controls and 153 Safeguards meant to be used?
basics
~20 sThe CIS Controls v8.1 are a prescriptive, prioritized set of 18 security Controls broken into 153 Safeguards. They tell an organization what to do first, starting with asset and software inventory, rather than serving as a certification standard.
Under the HIPAA Security Rule, what are the administrative, physical and technical safeguards, and why is the 164.308(a)(1) risk analysis the starting point?
basics
~20 sThe HIPAA Security Rule protects electronic PHI through administrative (164.308), physical (164.310) and technical (164.312) safeguards. The required risk analysis in 164.308(a)(1) comes first because every choice of reasonable and appropriate measures rests on it.
What is the difference between ISO/IEC 27001 and ISO/IEC 27002, and which one can an organization be certified against?
basics
~20 sISO/IEC 27001 states the requirements for an information security management system, including the Annex A control list, and is the standard organizations are certified against. ISO/IEC 27002 is guidance on implementing each of those controls and cannot be certified.
What are the six Functions of the NIST Cybersecurity Framework 2.0, and what does the new Govern Function add?
basics
~20 sNIST CSF 2.0 organizes outcomes under six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern, new in 2.0, covers risk strategy, roles, policy, oversight and supply chain risk, and informs how the other five are implemented.