Which of the following addresses individual rights such as the right to be informed, the right of access, and the right to be forgotten?
Choose an answer
Tap an option to check your answer.
Correct answer: GDPR.
Why this is the answer
GDPR (General Data Protection Regulation) is a comprehensive data privacy and security law that grants individuals extensive rights over their personal data, including the right to be informed about data collection, the right to access their data, and the right to have their data erased (the "right to be forgotten"). PCI DSS (Payment Card Industry Data Security Standard) focuses on securing credit card transactions, not individual data rights. NIST (National Institute of Standards and Technology) provides cybersecurity frameworks and guidelines, but it's not a regulatory law like GDPR. ISO (International Organization for Standardization) develops international standards, including some related to information security (e.g., ISO 27001), but it doesn't specifically define individual data rights in the same way GDPR does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed