Organizations must navigate a complex web of laws, regulations, industry standards, and relationship-driven requirements that govern how they collect, store, and process data. Compliance obligations vary based on geographic location, industry, services offered, customer base, and the types of data handled.
Compliance Factors
One of the questions that a company needs to ask itself is what laws, regulations and standards it needs to comply with. Let's talk about what we have to comply with. What are the standards? What's setting the compelling reason that we have to implement a certain set of standards?
One of those reasons is because we're legally bound to it. Out of those, laws and regulations are a big one. So we've got laws and regulatory compliance that we have to comply with, that we have to follow, otherwise it could be really bad for the company. There is a difference between what a law is and what a regulation is, but it's not important for the purpose of this lesson, so we're just going to say it's laws and regulations.
Then we have the customers. The customers don't necessarily — well, they may demand something, but we don't necessarily have to follow it. But we might lose them as a customer. So they may make certain demands on us. One example of this is I was working on a state deal, helping the company land the state deal, and the state required us to implement all of these different security measures. They had this set of standards that we wanted to comply with, and they set it out there, and now we either choose not to do business with them, or we have to go and meet those standards.
Same thing with partners and vendors. Really, we could just categorize these two as relationships. Anytime we establish a relationship, there is a certain understanding that we are going to go through before we do business, as if we have to get on the same page before we do that. We're either going to lose them as a customer, partner or vendor, or we're going to comply with what their demands are.
Then if we say we're going to comply with that and then don't comply with that, now it becomes a legal issue and they can take us to court. So now we have a lawsuit or some sort of legal action, and we have to comply with those legal actions.
One other thing I'll throw in here is that sometimes it just comes internally, that we are mitigating risk, and so we want to comply with a certain set of standards because we chose to comply to that certain set of standards because it's best for the business, it mitigates risk. So there is some internal compliance that we might have, as well as external compliance.
Why we have to follow certain laws and regulations might depend on several different factors:
When it comes to geographical locations, there could be some that no matter where you're at in the world you have to comply with. Or perhaps it's if you're in a certain country you have to comply with it. Or maybe it is a grouping of countries, or perhaps it's a certain region, maybe a county, or perhaps it's a city, or perhaps it's a state.
Here are some of the list of the laws and regulations that are out there. We have the US Privacy Act of 1974, or GDPR, or there's the General Data Protection Law over in Brazil, or the Privacy Act of 1988 in Australia. So there are these different laws and regulations out there that we might have to comply to — not only one, but many of these.
Each one of those countries might have a lot of different laws and regulations. For instance, I mentioned the US has the US Privacy Act of 1974, but they have a lot of other federal laws in place that have to deal with privacy and other compliance that we would have to fall under. And within the United States we have 50 different states, and each one of them has their own set of laws, so now we have to comply with a lot of different state level laws.
And I hate to say this, but it's not just where we're doing business at. We have a business that's operating out of a certain country, but perhaps we have data that's being collected from users in another country, and the data is being stored in yet another country, and then we have service providers that we work with that have access to that data.
Let's give a little scenario here. Let's say our business is operating out of Australia over here, we're storing data in the cloud at a cloud provider that's over in the United States, we have clients that are in the European Union, and we also have a service provider that's in maybe Singapore that's offering some services and doing some data processing for us. So now we have to take into consideration all of these different locations and the rules that govern each of those locations. We may have to comply with several different locations based off of where our data is being stored, and our users and where they're from, and where our company is based out of, and that service provider that we're using.
Let's say we work for a company that's looking at opening up a new branch office, and that branch office we want to open up in Brazil. One of the considerations is what are the laws and regulations in Brazil, and are we going to be storing data over there? Is it going to be data from other countries, that maybe users from this will be stored over in this new location? We have to think about all of the pros and cons and all the laws and regulations of opening this branch office in this new location.
One example of laws and regulations that are driven by industry is the Gramm-Leach-Bliley Act. The Gramm-Leach-Bliley Act really is about financial institutes, so if you're selling financial products, like a bank or some other financial institution, then you have to comply with this Gramm-Leach-Bliley Act.
This also brings up the point of mergers and acquisitions. When we start merging together two different companies, that can be problematic, because now we have to take those security laws and regulations and standards and merge them together for that company. This can be especially difficult if we're talking about two different types of companies. For instance, GE was an energy company that started picking up more financial stuff and trying to merge that into the company, and now that causes some problems with these different laws and regulations, and how are you going to follow everything that you need to follow. So it's going to be a lot of extra work to make sure that you can merge those two together successfully from a compliance standpoint.
It could also be based off of those services. An example of this, that's actually not a law or regulation but is something that's set by the credit card industry, is the Payment Card Industry Data Security Standard, or PCI DSS. This one right here requires that if you're processing credit cards, then you're going to need to comply by a certain set of standards.
A good example of a law or regulation that you may have to follow if you're targeting a certain customer is COPPA, the Children's Online Privacy Protection Act. So if you have children that you're targeting as far as your services that you're offering, then you're going to need to comply with COPPA.
A good example of laws and regulations you have to comply with if you're collecting certain data would be HIPAA. HIPAA is the health information portability and accountability act, so if you're collecting health information, then what you're going to have to do is comply with HIPAA.
There are also different data types, so what we have to comply with may have to do with the type of data that we're collecting. Is it personal identifiable information? I already mentioned healthcare records. Or is it financial transactions, or is it educational records, or is it intellectual property? These are some data types that we may have to follow under certain standards and guidelines, based off of what data we're collecting or storing.
I'm going to do just a quick call-out here. Notice that a lot of what we're working with really has to do with data. A lot of our laws and regulations are about protecting consumer data and their rights. So really, when it comes to compliance, a lot of it will revolve around how we treat their data and manage their data. There's a big connection between this compliance and also data management. I'm going to get more deep into data management in a whole other module. I'm not going to get deep into it here — I just want to call that out so we understand the correlation.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →