About this interactive
Seven scenarios, seven compliance regimes, one pairing each. The recall half is straightforward once you know what each acronym covers. The half worth carrying out of the activity is why any of them applied in the first place, because nothing about compliance is chosen — it is triggered, and the trigger is different every time. Four of these seven are laws. HIPAA reaches the hospital because of the industry it is in and the kind of data it holds: protected health information, guarded by a Security Rule that names administrative, physical and technical safeguards and attaches a breach-notification duty to failure. GLBA reaches the bank the same way, through its industry, and asks two separate things of it — an honest explanation to customers of how their private financial information is shared and protected, and a safeguards program that actually protects it. GDPR reaches the company selling European customer data even though the company sits outside Europe, and that is precisely the point of it: scope follows the data subject, not the head office. COPPA reaches the children's game through the age of its users, drawing a hard line at thirteen and requiring verifiable parental consent before any personal information is collected. CMMC is the odd one among the mandatory four, because it arrives through a contract rather than a statute — a Department of Defense supplier holding controlled unclassified information has to pass a third-party assessment at the required maturity tier before an award, which makes the customer, in this case, a government. PCI DSS is not a law at all. No legislature passed it; the card brands wrote it and enforce it as a condition of being allowed to process payments, which in practice makes it every bit as binding as one for a retailer who wants to stay in business. Its requirement to encrypt stored cardholder data is the one the plain-text order database breaks. And SOC 2 is not mandatory in any sense — the cloud vendor engages a CPA firm and pays for an attestation because a prospective enterprise customer asked for evidence that its controls work. A Type 1 report says the controls are in place; a Type 2 says they were actually followed over a period. Sorted by what compels them, the set reads: four regulations imposed by law, one imposed by contract, one imposed by an industry body, one requested by a customer. That is the shape of a real compliance landscape, and it is why an organization's obligations have to be worked out from its own facts — its location, its industry, its data, its customers — rather than looked up on a list.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →