Module 4 | Government Regulatory Frameworks & Data Protection •
MODULE 4
Government Regulatory Frameworks
Data Protection Laws, Security Standards,
Retention Policies, Compliance & International Standards
SECTION 1: Government Regulatory Frameworks
1.1 Definition and Purpose
Government regulatory frameworks are structured sets of laws, guidelines, rules, and standards
enacted by governing authorities to regulate how organisations collect, store, process, share, and
dispose of personal data. They establish legal obligations for organisations, enforceable rights for
individuals, and mechanisms to investigate and penalise non-compliance.
A regulatory framework for data protection serves multiple purposes:
• Protect individuals' fundamental rights to privacy and data control
• Prevent exploitation, discrimination, and misuse of personal data
• Establish legal certainty for businesses operating across jurisdictions
• Enable safe cross-border data flows in the global digital economy
• Provide remedies and redress mechanisms for data-related harms
• Deter cybercrime, data breaches, and irresponsible data handling
1.2 How Regulatory Frameworks Regulate Data Handling
Regulatory frameworks cover the full data lifecycle:
Stage What Regulations Govern Example Requirement
Collection What data can be collected, purpose, GDPR requires lawful basis before
consent collecting personal data
Storage Where data is stored, security ISO 27001 mandates encrypted storage
standards, access control with access logs
Processing Who can process, purpose limitation, GDPR: data must not be processed
data minimisation beyond its original purpose
Sharing / Transfer Third-party agreements, cross- GDPR restricts transfer of EU data to non-
border rules adequate countries
Retention How long data can be kept, deletion 7-year financial record rule; GDPR
timelines storage limitation principle
Page 1 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Stage What Regulations Govern Example Requirement
Disposal / Erasure Secure deletion, Right to be GDPR Article 17: erasure on request or
Forgotten when no longer needed
1.3 Key Enforcement Mechanisms
Regulatory Fines and Financial Sanctions
GDPR provides for heavy financial penalties for non-compliance.
Two-tier penalty system:
Up to €10 million or 2% of global annual turnover (whichever is higher)
→ For procedural violations (e.g., record-keeping failures)
Up to €20 million or 4% of global annual turnover (whichever is higher)
→ For serious violations (e.g., unlawful processing, violation of data subject rights)
Purpose:
Ensure accountability
Act as a deterrent
Encourage organisations to implement strong compliance systems
These penalties apply to both data controllers and data processors.
Supervisory Authority Powers (DPA Powers)
Each EU country has a Data Protection Authority (DPA) to enforce GDPR.
Example:
Data Protection Commission
DPAs have power to:
Conduct investigations
Carry out data protection audits
Access organisational records
Issue warnings and reprimands
Make binding legal decisions
These authorities ensure organisations follow lawful processing principles.
Compliance Orders
Regulatory authorities can issue corrective orders requiring organisations to:
Stop unlawful processing
Rectify incorrect data practices
Implement stronger security measures
Suspend international data transfers
Page 2 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Delete unlawfully processed data
This ensures immediate correction of violations.
Criminal Prosecution
Certain data protection violations may lead to criminal liability, especially when:
There is intentional unlawful access
Data is misused fraudulently
Systems are hacked illegally
Example:
Computer Misuse Act 1990
Under such laws, offenders may face:
Criminal fines
Imprisonment
Prosecution in criminal courts
Criminal liability is usually separate from regulatory fines.
Civil Litigation (Article 82 GDPR)
Under Article 82, data subjects have the right to:
Claim compensation for material damage (financial loss)
Claim compensation for non-material damage (emotional distress)
Individuals can sue organisations in civil courts if their rights are violated.
This strengthens individual data protection rights.
Mandatory Breach Notification (72-Hour Rule)
Under GDPR:
Organisations must report personal data breaches to the supervisory authority within 72
hours of becoming aware of the breach.
If not reported within 72 hours, justification must be provided.
In high-risk cases, affected individuals must also be informed.
Failure to report breaches can result in additional fines and penalties.
1.4 Role in Organisational Accountability
Regulatory frameworks shift accountability from individuals to organisations. They require:
• Appointment of responsible officers (e.g., Data Protection Officers under GDPR)
• Documented evidence of compliance (Records of Processing Activities)
• Regular risk assessments and audits
• Privacy-by-design and privacy-by-default practices
• Contractual obligations on third-party processors
Page 3 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
🌍 Real-World Example: IT Act 2000 in India's E-Governance
India's Information Technology Act 2000 (amended in 2008) governs electronic records, digital
signatures, and cyber offences.
Section 43A: Organisations handling sensitive personal data must implement 'reasonable security
practices' or face compensation liability.
Section 72A: Disclosure of personal information without consent by an intermediary is a punishable
offence (up to 3 years imprisonment).
In e-governance: Aadhaar data stored by UIDAI is governed by the Aadhaar Act 2016, imposing
strict restrictions on storage and disclosure.
The Digital Personal Data Protection Act 2023 (DPDPA) is India's comprehensive new framework,
aligned closely with GDPR principles.
Page 4 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
SECTION 2: General Data Protection Regulation (GDPR)
2.1 Overview
GDPR (Regulation EU 2016/679) came into force on 25 May 2018, replacing Directive 95/46/EC. It
is the most comprehensive and influential data protection law globally, establishing a unified
framework across all EU member states with extraterritorial reach.
Feature Details
Full Name General Data Protection Regulation (EU) 2016/679
Effective 25 May 2018
Jurisdiction All EU/EEA member states; applies to non-EU organisations
processing EU residents' data
Enforcer National Data Protection Authorities (DPAs) — e.g., ICO (UK), CNIL
(France), DPC (Ireland)
Max Fine (Upper) €20 million or 4% of global annual turnover — whichever is higher
Max Fine (Lower) €10 million or 2% of global annual turnover — whichever is higher
2.2 Key Principles of GDPR (Article 5) — The 7 Pillars
Every organisation processing personal data of EU residents must adhere to these seven principles:
Principle Meaning Practical Implication
1. Lawfulness, Fairness Processing must have a legal Privacy notices, consent forms, lawful
& Transparency basis; individuals must be basis documentation
informed clearly
2. Purpose Limitation Data collected for specified Cannot reuse customer email collected for
purposes cannot be used for billing to send marketing without consent
incompatible ones
3. Data Minimisation Only collect what is strictly A hospital app should not collect social
necessary media logins just for appointment booking
4. Accuracy Data must be kept accurate Regular data audits; individuals must be
and up to date able to correct their data
5. Storage Limitation Data must not be kept longer Deleting ex-employee records after the
than necessary legally required period (often 6–7 years)
6. Integrity & Appropriate technical and Encryption, access controls, staff training,
Confidentiality organisational measures to pseudonymisation
(Security) protect data
7. Accountability Controllers must demonstrate Maintain Records of Processing Activities
compliance; not just comply, (RoPA), conduct DPIAs, appoint DPO
but prove it
Page 5 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
2.3 Lawful Bases for Processing (Article 6)
Processing personal data is unlawful unless at least one of these six bases applies:
• Freely given, specific, informed, unambiguous. Must be as easy to withdraw as to give.
Pre-ticked boxes = invalid.: Consent
• Processing necessary to fulfil or enter into a contract with the data subject: Contract
• Processing required by law (e.g., tax records, employment law): Legal Obligation
• Necessary to protect life (e.g., hospital sharing patient data in an emergency): Vital
Interests
• Exercising official authority or public interest function (e.g., government services):
Public Task
• The controller's interests that override the data subject's rights — requires a balancing
test: Legitimate Interests
2.4 Rights of Data Subjects (Articles 12–22)
Right Article Description Time Limit
Right to be Informed Art. Must be told: what is collected, why, At point of collection
13–14 retention period, third parties
Right of Access Art. 15 Request a copy of all personal data held 1 month (extendable to
(SAR) (Subject Access Request) 3)
Right to Rectification Art. 16 Have inaccurate/incomplete data 1 month
corrected
Right to Erasure Art. 17 'Right to be Forgotten' — delete data 1 month
when no longer needed or consent
withdrawn
Right to Restrict Art. 18 Limit how data is used while a complaint 1 month
Processing is resolved
Right to Data Art. 20 Receive data in machine-readable 1 month
Portability format (JSON/CSV) to transfer
elsewhere
Right to Object Art. 21 Object to processing for direct Immediate for marketing
marketing, research, or legitimate
interests
Rights re: Automated Art. 22 Not to be subject to purely automated 1 month
Decisions decisions with significant effects (e.g.,
loan rejection by AI)
🌍 Real-World Example: GDPR Rights in Action — Google Spain Case (2014)
Before GDPR, the European Court of Justice established the 'Right to be Forgotten' in Google
Spain SL v. AEPD (2014).
Page 6 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Mario Costeja González requested removal of outdated newspaper links from Google search
results about his debt proceedings.
The Court ruled Google must de-index results upon request if information is inadequate, irrelevant,
or excessive.
This case directly shaped GDPR Article 17. Since GDPR (2018), Google has received over 1
million erasure requests.
2.5 Obligations of Data Controllers
2.5.1 Privacy by Design and Default (Article 25)
Privacy must be built into systems from the start, not added on afterwards.
• Embed data protection into technical architecture and business processes from
inception: Privacy by Design
• Default settings must always be the most privacy-protective option (e.g., no pre-ticked
marketing consent boxes): Privacy by Default
Example: A new mobile banking app must encrypt data, minimise what is collected, and default to no
sharing with third parties — before launch, not as an afterthought.
2.5.2 Records of Processing Activities — RoPA (Article 30)
Controllers with 250+ employees (and smaller ones doing high-risk processing) must maintain a
RoPA documenting:
• Name and contact details of controller and DPO
• Purposes of processing
• Categories of data subjects and personal data
• Recipients of the data (including third countries)
• Retention periods
• Technical and organisational security measures
Page 7 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
2.5.3 Data Protection Impact Assessment — DPIA (Article 35)
A DPIA is a structured assessment required BEFORE starting high-risk processing. It is mandatory
when:
• Large-scale processing of sensitive data (health, biometric, criminal records)
• Systematic monitoring of public areas (CCTV, employee monitoring)
• Automated processing including profiling that significantly affects individuals (e.g., AI-based
loan decisions)
To Identify Privacy Risks in Advance
DPIA helps organisations detect:
Security vulnerabilities
Risk of data misuse
Risk of discrimination or profiling
Possible harm to individuals
It ensures problems are identified before implementation.
To Protect Rights and Freedoms
GDPR focuses on protecting:
Privacy
Reputation
Financial security
Freedom from discrimination
DPIA ensures that personal data processing does not negatively affect these rights.
To Ensure Legal Compliance
DPIA helps organisations:
Comply with GDPR obligations
Demonstrate accountability
Avoid heavy penalties
Failure to conduct a DPIA when required can result in fines.
To Reduce Legal and Financial Risk
By identifying risks early, organisations can:
Implement safeguards
Avoid data breaches
Prevent regulatory fines
Avoid civil litigation
Page 8 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
To Promote Transparency and Trust
DPIA increases:
Organisational transparency
Customer confidence
Ethical data governance
DPIA Process:
Step Activity
1. Describe Describe the processing: what data, why, how, who
2. Assess Is it necessary and proportionate for the purpose?
Necessity
3. Identify Risks What risks does it pose to individuals' rights and freedoms?
4. Identify What safeguards will mitigate those risks?
Measures
5. Consult DPA If residual risk remains high, consult the supervisory authority before proceeding
2.5.4 Data Breach Notification (Articles 33–34)
Notification To When Timeframe Content Required
Supervisory Authority Breach likely to result in risk Within 72 hours of Nature of breach,
(DPA) to individuals' awareness categories/number of
rights/freedoms affected individuals,
likely consequences,
measures taken
Data Subjects Breach likely to result in Without undue Clear, plain language
HIGH risk delay description of breach
and what affected
individuals should do
🌍 Real-World Example: British Airways Data Breach (2018)
BA suffered a breach affecting approximately 500,000 customers — hackers diverted users to a
fraudulent site collecting payment card details.
ICO (UK) initially proposed a £183 million fine (1.5% of annual turnover) under GDPR.
Final fine: £20 million (reduced due to COVID-19 financial impact on the airline sector).
Key failure: Inadequate security measures and delayed detection of the breach.
Lesson: GDPR's Integrity & Confidentiality principle and mandatory breach notification obligations
require proactive, not reactive, security.
Page 9 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
2.6 Data Protection Officer (DPO) — Articles 37–39
Mandatory appointment when the organisation is a:
• Public authority or body
• Controller or processor carrying out large-scale regular systematic monitoring (e.g.,
behavioural advertising)
• Controller or processor of special category data at large scale (e.g., hospitals, insurance
companies)
DPO Function Description
Advisory Informs and advises the controller/processor and employees on GDPR
obligations
Monitoring Monitors internal compliance including staff training and data protection
audits
DPIA Advisor Advises on DPIAs and monitors their performance
DPA Liaison Acts as contact point for the supervisory authority and cooperates with
them
Data Subject Contact Contact point for data subjects exercising their rights
2.7 International Data Transfers (Chapter V)
Personal data of EU residents cannot be transferred outside the EU/EEA (European Economic Area-
Norway, Iceland , Liechtenstein) unless adequate protection is guaranteed. Transfer mechanisms
include:
Mechanism Description Examples
Adequacy Decision European Commission officially UK, Japan, South Korea,
recognises destination country as Canada (commercial), New
providing equivalent protection Zealand, Switzerland
Standard Contractual Pre-approved contract terms binding Google using SCCs for
Clauses (SCCs) importer to GDPR-equivalent standards transferring EU user data to US
servers
Binding Corporate Internal privacy policies approved by a IBM, Microsoft internal BCRs
Rules (BCRs) DPA for intra-group transfers in
multinationals
Derogations (Art. 49) Exceptional cases: explicit consent, Hospital sending patient record
contract necessity, vital interests, public to foreign specialist with patient
interest consent
Adequacy Decision
An Adequacy Decision is issued by the European Commission declaring that a non-EU
country provides data protection standards equivalent to GDPR.
Page 10 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
If a country has adequacy status:
Data can flow freely
No additional safeguards are required
Examples of Adequate Countries:
United Kingdom
Japan
South Korea
Canada (commercial organisations)
New Zealand
Switzerland
Why important?
Simplest transfer mechanism
Reduces compliance burden
Standard Contractual Clauses (SCCs)
What are SCCs?
SCCs are pre-approved legal contract clauses issued by the European Commission.
They:
Bind the data importer (foreign organisation)
Require GDPR-equivalent protection
Provide legal remedies to data subjects
Example:
Google using SCCs to transfer EU user data to servers in the US.
Key Features:
Legally binding contract
Must not be modified
Requires risk assessment
Often used when no adequacy decision exists
Why needed?
Page 11 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Countries like the US do not have full adequacy, so companies rely on SCCs.
Binding Corporate Rules (BCRs)
What are BCRs?
BCRs are internal data protection policies used by multinational companies to transfer
data within their corporate group internationally.
They must:
Be approved by a Data Protection Authority (DPA)
Be legally binding on all group entities
Ensure consistent GDPR-level protection
Examples:
IBM internal BCR framework
Microsoft internal BCR policies
Used for:
Intra-group transfers
Large multinational corporations
Advantage:
Long-term solution for global companies
Strong internal compliance structure
Derogations (Article 49 GDPR)
Derogations are exceptional situations where data can be transferred without adequacy,
SCCs, or BCRs.
These are used only in specific cases, not for regular large-scale transfers.
Situations include:
✔ Explicit consent of the data subject
✔ Contract necessity
Page 12 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
✔ Vital interests (life-saving situations)
✔ Important public interest
✔ Legal claims
Example:
A hospital sends a patient’s medical record to a foreign specialist with the patient’s explicit
consent.
⚖ Case Study: Meta Ireland — €1.2 Billion GDPR Fine (2023)
Background: Meta (Facebook) transferred EU users' personal data to US servers relying on
Standard Contractual Clauses (SCCs) after the Schrems II ruling invalidated the Privacy Shield
framework.
Finding: Ireland's DPC ruled that the SCCs Meta used were insufficient to protect EU data from
US government surveillance (under FISA 702 / Executive Order 12333).
Penalty: Record €1.2 billion fine — the largest GDPR fine ever. Meta ordered to suspend data
transfers to the US.
Outcome: The EU–US Data Privacy Framework was adopted in 2023 as the new adequacy
decision, allowing lawful transfers.
Lesson: Chapter V international transfer rules are strictly enforced. Organisations cannot simply
paper over structural legal incompatibility with contracts.
Page 13 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
SECTION 3: California Consumer Privacy Act (CCPA) and CPRA
3.1 Overview
The California Consumer Privacy Act (CCPA) came into effect on 1 January 2020, making California
the first US state with a comprehensive consumer privacy law. It was significantly amended and
strengthened by the California Privacy Rights Act (CPRA), effective 1 January 2023.
Feature CCPA (2020) CPRA (2023 Amendments)
Applicability Businesses meeting size/revenue Same, with added category of
thresholds processing CA 'sensitive personal information'
residents' data
New Regulator California Attorney General California Privacy Protection
Agency (CPPA) — dedicated
agency
New Rights Added Know, Delete, Opt-Out, Non- Correct, Limit use of sensitive PI,
Discrimination Opt-Out of automated decision-
making
Employee Data Initially exempt Employee data included from
January 2023
B2B Data Initially exempt B2B data included from January
2023
3.3 Consumer Rights under CCPA/CPRA
Right Description Example Use Case
Right to Know Know what personal information Consumer requests a list of all data
is collected, used, disclosed, sold Amazon holds about them
Right to Delete Request deletion of personal User demands a retailer delete their
information collected from them purchase history
Right to Opt-Out of Stop the business from Clicking 'Do Not Sell My Personal
Sale/Sharing selling/sharing their PI to third Information' link on website
parties
Right to Correct Request correction of inaccurate Correcting wrong home address held by
personal information (CPRA an insurer
addition)
Right to Limit Sensitive Restrict use of sensitive PI to Limiting use of health data to processing
PI necessary purposes (CPRA) insurance claim only
Right to Non- Cannot be denied services or Cannot charge higher price for opting
Discrimination charged more for exercising out of data sale
rights
Page 14 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Right Description Example Use Case
Right re: Automated Opt-out of automated profiling for Opting out of AI-based credit scoring
Decision-Making significant decisions (CPRA)
Practical Example
Right to Know (CCPA)
A customer asks an online retailer:
“What personal data have you collected about me?”
The company must provide:
Categories of data
Purpose of collection
Third parties with whom it was shared
Right to Delete (CCPA)
A customer closes their account and requests:
“Delete all my personal information.”
The company must erase data unless legally required to retain it.
Right to Correct (Added by CPRA)
A customer notices their birthdate is wrong in records.
They can request correction, and the company must update it.
Right to Limit Use of Sensitive Personal Information (CPRA)
Sensitive PI includes:
Social Security numbers
Precise geolocation
Biometric data
Health information
Example:
A mobile app collecting precise GPS data must allow users to limit its use.
Employee Data Inclusion (CPRA)
Before 2023:
Employee HR records were exempt.
After 2023:
Employees can:
Request access to performance records
Page 15 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Ask for deletion of unnecessary personal data
B2B Data Inclusion (CPRA)
If a supplier’s representative shares:
Name
Business email
Phone number
They now have privacy rights under CPRA.
3.2 Who Must Comply with CCPA?
A for-profit business doing business in California that meets ANY ONE of:
• Annual gross revenue exceeding $25 million
• Buys, sells, or receives/shares personal information of 100,000+ consumers or households
annually
• Derives 50% or more of annual revenue from selling consumers' personal information
3.4 GDPR vs. CCPA — Key Comparison
Dimension GDPR (EU) CCPA/CPRA (California, USA)
Approach Rights-based: opt-in by default Market-based: opt-out of sale
Opt-In vs. Opt-Out Requires opt-in consent for most Defaults to data collection allowed;
processing opt-out of sale
Sensitive Data Explicit list; requires explicit consent Sensitive PI category; right to limit use
Scope Any organisation processing EU For-profit businesses meeting
residents' data California thresholds
Enforcement DPAs; individuals can sue California AG; CPPA; private right of
action for data breaches
Fines Up to €20M or 4% global turnover Up to $7,500 per intentional violation
DPO Required? Yes, in certain cases No equivalent requirement
🌍 Real-World Example: CCPA in Practice — Sephora Settlement (2022)
California AG sued Sephora (cosmetics retailer) for selling consumer data to third parties without
disclosing it as a 'sale' and without honouring opt-out requests.
Settlement: $1.2 million fine. Sephora required to add 'Do Not Sell My Personal Information' links
and honour opt-out browser signals (Global Privacy Control).
This was the first major CCPA enforcement action and set the precedent for how opt-out
mechanisms must function.
Lesson: Under CCPA, sharing data with analytics providers for advertising constitutes a 'sale' —
even without money changing hands.
Page 16 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Page 17 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
SECTION 4: Information Security Standards — ISO/IEC 27001 &
ISO/IEC 27701
4.1 What are Information Security Standards?
Information security standards are internationally recognised frameworks of best practices, controls,
and requirements designed to help organisations systematically protect information assets. They
provide a structured, auditable approach to managing information security risks.
Standards are developed by bodies such as the International Organisation for Standardisation (ISO)
and the International Electrotechnical Commission (IEC). Compliance with standards can be certified
by accredited third-party auditors.
4.2 ISO/IEC 27001 — Information Security Management System (ISMS)
4.2.1 Overview
ISO/IEC 27001 is the world's leading international standard for Information Security Management
Systems (ISMS). It specifies requirements for establishing, implementing, maintaining, and
continually improving an ISMS.
Aspect Details
Full Title ISO/IEC 27001:2022 — Information Security, Cybersecurity and Privacy
Protection
Purpose Provide a systematic approach to managing sensitive company
information so it remains secure
Certification Organisations can be certified by accredited certification bodies (third-
party audit)
Core Framework Plan-Do-Check-Act (PDCA) cycle for continuous improvement
Annex A Controls 93 controls across 4 themes: Organisational, People, Physical,
Technological
4.2.2 Three Objectives of ISO 27001 — The CIA Triad
Objective Meaning Example Control
Confidentiality Information is accessible only to Access control, encryption, need-to-know
authorised individuals policies
Integrity Accuracy and completeness of Hash verification, checksums, audit logs,
information is maintained and version control
protected
Availability Authorised users can access Redundant systems, backups, disaster
information when needed recovery, DDoS protection
Page 18 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
4.2.3 ISMS Components
An Information Security Management System (ISMS) under ISO 27001 includes:
• Identify information assets, threats, vulnerabilities, and impact: Risk Assessment
• Apply controls from Annex A or justify exclusions in a Statement of Applicability (SoA):
Risk Treatment
• Written policies covering acceptable use, incident response, access control, etc.:
Security Policies
• Inventory of all information assets with designated owners: Asset Management
• Procedures for detecting, responding to, and learning from security incidents: Incident
Management
• Regular audits to verify ISMS effectiveness: Internal Audit
• Senior leadership reviews ISMS performance periodically: Management Review
• Corrective actions and ongoing enhancement of the ISMS: Continual Improvement
Risk Assessment
(Identify assets, threats, vulnerabilities, and impact)
The organization identifies:
Information assets
Possible threats
Weaknesses (vulnerabilities)
Impact if something goes wrong
Example (E-commerce Company)
Element Example
Asset Customer payment database
Threat Hacker attack
Vulnerability Weak password policy
Impact Financial loss, legal penalty, reputational damage
The company calculates risk level (High/Medium/Low).
Risk Treatment
Page 19 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
(Apply Annex A(Annex A of ISO/IEC 27001 is a structured list of 93 security controls
that organizations select and implement to treat identified information security risks
within their ISMS.) controls or justify exclusions in Statement of Applicability – SoA)
After identifying risks, the organization:
Selects appropriate security controls from Annex A
Or justifies why a control is not applicable
Documents this in the Statement of Applicability (SoA)
Example:
Risk: Unauthorized access to database
Treatment:
Implement Multi-Factor Authentication
Enable encryption
Apply role-based access control
If a control (e.g., physical data center security) is not applicable because the company uses
AWS cloud, it must justify this in the SoA.
Security Policies
Examples:
Acceptable Use Policy (no personal USB devices)
Access Control Policy
Password Policy
Incident Response Policy
Remote Work Policy
Example: Employees must use strong passwords (minimum 12 characters)
Asset Management
Maintain an inventory of all information assets and assign an owner.
Example:
Asset Owner
Customer Database IT Manager
Website Server Cloud Administrator
Employee Laptops HR Manager
Page 20 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Every asset must have a responsible person.
Incident Management
Procedures to detect, respond, and learn from security incidents.
Example:
Incident: Customer data breach
Steps:
1. Detect unusual database activity
2. Isolate affected server
3. Inform management
4. Notify affected customers
5. Conduct root cause analysis
6. Improve controls
The organization learns and prevents recurrence.
Internal Audit
Regular internal checks to verify if ISMS is working effectively.
Example:
Internal audit team checks:
Are access controls properly implemented?
Are logs monitored regularly?
Are policies updated?
If gaps are found, they are reported.
Management Review
Top management reviews ISMS performance periodically.
Example:
CEO reviews:
Number of security incidents
Audit findings
Risk levels
Page 21 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Compliance status
Decisions may include increasing cybersecurity budget.
Continual Improvement
Correct problems and continuously enhance the ISMS.
Example:
After a phishing attack:
Conduct employee awareness training
Upgrade email security filters
Improve password policy
Security keeps improving over time (PDCA cycle).
4.3 ISO/IEC 27701 — Privacy Information Management System (PIMS)
ISO/IEC 27701:2019 is an extension to ISO 27001 that specifically addresses privacy protection and
personal data management. It adds requirements for establishing a Privacy Information Management
System (PIMS).
Feature ISO 27001 ISO 27701 (Extension)
Focus Information security broadly Privacy and personal data
protection specifically
Framework Type ISMS PIMS — Privacy Information
Management System
Roles Addressed General information security Specifically addresses PII
(Personally Identifiable Information)
Controllers and Processors
GDPR Alignment Supports GDPR's security principle Directly maps to GDPR and other
privacy regulation requirements
Standalone? Yes — can be certified Requires ISO 27001 as a base;
independently extends it
4.4 How ISO Standards Protect Sensitive Customer Data
Consider an e-commerce company storing customer payment and address data:
Page 22 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Threat ISO 27001 Control ISO 27701 Addition
Unauthorised access to Annex A: Access control, multi-factor Restrict access to PII to only
customer database authentication, privileged access those who need it for
management processing purpose
Data breach / exfiltration Encryption of data at rest and in Privacy breach response
transit; DLP tools procedures; notification
obligations
Third-party vendor risk Supplier security assessments; Data processing agreements
contractual security clauses with vendors handling PII;
privacy assessments
Data retention beyond Data lifecycle management Retention schedules for PII
necessity procedures aligned with legal requirements
and purpose limitation
Insider threat Audit logging; separation of duties; Restricting access to PII to
background checks minimum necessary
🌍 Real-World Example: ISO 27001 Certification — HDFC Bank
HDFC Bank (India's largest private bank) has achieved ISO 27001 certification for its data centres
and critical IT infrastructure.
This certification assures regulators, customers, and business partners that customer financial
data is protected through a systematic, audited security management framework.
The certification covers controls across physical security of data centres, logical access to banking
systems, encryption of customer transactions, and incident response.
For GDPR compliance: multinational banks use ISO 27001 + ISO 27701 together to demonstrate
the 'appropriate technical and organisational measures' required under GDPR Article 32.
Page 23 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
SECTION 5: Data Retention Policies
5.1 What is Data Retention?
Data retention refers to the policies and procedures that govern how long an organisation keeps
personal or business data before it must be securely deleted, archived, or anonymised. It is a critical
component of data governance and legal compliance.
A Data Retention Policy is a formal document that specifies:
• What data is collected and stored
• The legal or business basis for retaining it
• How long each category of data is retained (retention schedule)
• When and how data is securely deleted or anonymised
• Who is responsible for enforcing retention schedules
5.2 Why Defined Retention Periods are Essential
• Laws mandate minimum or maximum retention periods for specific data types: Legal
Compliance
• Retaining data longer than necessary increases exposure in a data breach and
regulatory liability: Risk Reduction
• Unnecessary data retention wastes storage resources and creates management
overhead: Storage Cost
• Processing data beyond its original purpose violates GDPR and similar laws: Purpose
Limitation
• Clear policies demonstrate accountability and build customer and regulatory trust:
Trust
5.3 GDPR Data Retention Principles
GDPR does not prescribe specific retention periods for most data categories, but establishes
governing principles:
GDPR Principle Retention Implication Practical Requirement
Storage Limitation (Art. Data must not be kept in Define maximum retention period at
5(1)(e)) identifiable form longer than the time of collection; delete when
necessary for its original purpose purpose is achieved
Purpose Limitation (Art. Data collected for one purpose Separate datasets with distinct
5(1)(b)) cannot be retained for another retention schedules per purpose
incompatible purpose
Accountability (Art. 5(2)) Controllers must be able to Documented retention schedules in
demonstrate compliance with Records of Processing Activities
storage limitation (RoPA)
Page 24 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
GDPR Principle Retention Implication Practical Requirement
Right to Erasure (Art. 17) Individuals can demand deletion Systems must support reliable,
when data is no longer needed, verifiable data deletion on request
consent is withdrawn, or
processing was unlawful
Data Minimisation (Art. Avoid retaining more data than Regular data audits to identify and
5(1)(c)) necessary purge unnecessary records
5.4 The 7-Year Retention Policy
The 7-year retention rule is widely applied in financial, tax, and corporate contexts. It is not a single
law but a convergence of multiple regulatory requirements:
Jurisdiction / Law Data Type Retention Period Authority
UK — Companies Act Accounting records 6 years from HMRC / Companies
2006 financial year end House
UK — HMRC Guidance Tax records (self- 6 years after HMRC
employed/companies) relevant tax year
India — Companies Act Books of accounts and 8 years from date of Ministry of Corporate
2013 financial statements financial year Affairs
India — GST Act 2017 GST records and 6 years from due GSTN / GST Council
invoices date of annual
return
USA — IRS Code Tax records 7 years (if claiming IRS
loss for worthless
securities)
EU — Anti-Money KYC and transaction 5 years (extendable Financial regulators
Laundering Directive records to 10)
Banking — Basel III Transaction and risk 5–7 years typically Central banks /
records regulators
Key point: The '7-year rule' is a practical standard used by auditors and compliance teams to ensure
organisations retain sufficient financial and business records for regulatory inspections, litigation, or
audit purposes. After the period, data should be securely deleted or anonymised.
5.5 Purpose Limitation in Data Retention
Purpose limitation means that data may only be retained for the specific, documented purpose for
which it was originally collected. Once that purpose is fulfilled, the data must be deleted or
anonymised.
Page 25 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Data Type Original Purpose Retention Period What Happens After
Customer order Fulfil e-commerce Duration of order + Anonymised for sales
records transaction warranty period + legal analytics or deleted
limitation period (typically 6
years)
Employee payroll Pay employees and 6–7 years after employment Securely shredded /
records comply with tax law ends permanently deleted
CCTV footage in Physical security 30 days typically (longer if Automatically
office incident under overwritten
investigation)
Job applicant CVs Recruitment process 6 months (or as notified) Deleted; cannot be
(unsuccessful) used for future roles
without fresh consent
Medical records Patient treatment 8–10 years (UK: minimum 8 Archived then
years for adults) destroyed per NHS
records management
code
🌍 Real-World Example: Improper Retention — UK Fertility Clinic Case
A UK fertility clinic retained donor's genetic and contact data indefinitely 'just in case' future patients
or donor-conceived children contacted them.
ICO found this violated GDPR's Storage Limitation principle — data was kept long beyond the
clinical purpose and mandatory NHS retention period.
The clinic was ordered to implement a data retention schedule and conduct a purge of overdue
records.
Lesson: Indefinite retention 'just in case' is not a lawful basis. Every dataset needs a defined
deletion date aligned with its purpose.
Page 26 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
SECTION 6: Compliance and Data Protection Audits
6.1 What is Compliance in Data Protection?
Compliance in data protection means an organisation's practices, processes, policies, and systems
conform to applicable legal, regulatory, and contractual requirements for personal data handling. It is
ongoing — not a one-time achievement.
Compliance involves:
• Understanding applicable laws (GDPR, CCPA, IT Act, DPDPA, etc.)
• Implementing required technical and organisational measures
• Documenting and evidencing that measures are in place
• Continually monitoring, testing, and improving measures
• Training staff at all levels on their data protection obligations
6.2 Role of Compliance Programmes
A compliance programme is a structured set of policies, controls, and oversight mechanisms that
embed regulatory requirements into daily operations. Key elements:
Element Description
Data Protection Policy High-level statement of the organisation's commitment to data
protection; reviewed annually
Records of Processing Living document cataloguing all processing activities (mandatory under
Activities (RoPA) GDPR Art. 30)
Data Processing Contracts with third-party processors specifying their obligations (GDPR
Agreements (DPAs) Art. 28)
Privacy Notices Transparent information provided to data subjects at point of collection
Consent Management Systems for collecting, recording, and managing consents; easy
withdrawal mechanisms
Training Programmes Regular, role-specific data protection training for all staff
Incident Response Plan Documented procedure for detecting, containing, assessing, and
notifying data breaches
Data Protection Officer Independent oversight function (mandatory for many organisations
under GDPR)
6.3 Data Protection Compliance Audits
6.3.1 What is a Compliance Audit?
A data protection compliance audit is a systematic, independent examination of an organisation's
data protection practices to assess whether they comply with applicable laws, standards, and internal
Page 27 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
policies. Audits can be internal (conducted by the compliance team or DPO) or external (conducted
by a regulatory body or independent auditor).
6.3.2 Objectives of Data Protection Audits
• Verify that processing activities are lawful and match documented purposes
• Identify gaps between current practices and legal requirements
• Assess the effectiveness of technical and organisational security measures
• Evaluate data retention practices and deletion compliance
• Check third-party processor compliance (DPAs in place, sub-processor rules)
• Ensure data subject rights processes are functioning correctly
• Produce a gap analysis report with prioritised remediation recommendations
6.3.3 Process of Conducting a Data Protection Compliance Audit
Stage Activities
1. Planning Define scope, objectives, and methodology; gather background documentation;
identify key stakeholders; prepare audit checklist based on GDPR Articles or
relevant law
2. Data Discovery Map all data flows: what personal data is collected, from whom, stored where,
shared with whom; validate against RoPA
3. Documentation Review policies, privacy notices, consent records, DPAs, DPIA reports, training
Review records, breach logs
4. Technical Test access controls, encryption, vulnerability management, logging and
Assessment monitoring, backup integrity
5. Interviews & Speak with DPO, IT security, HR, marketing teams; observe actual practices vs
Observations documented procedures
6. Gap Analysis Compare findings against legal requirements; classify gaps by risk level
(High/Medium/Low)
7. Reporting Produce audit report: findings, evidence, non-conformities, recommendations,
suggested timelines for remediation
8. Remediation Monitor implementation of recommendations; schedule follow-up audit to verify
Tracking closure
6.4 How Compliance Audits Prevent Legal Penalties and Breaches
Proactive compliance audits provide several defensive advantages:
• Early detection of non-compliances before regulators discover them
• Demonstrate 'accountability' principle to regulators — reducing fines if breach occurs
• Identify technical vulnerabilities before they can be exploited
• Ensure data retention schedules are followed — reducing breach exposure surface
• Verify third-party processors are meeting contractual security obligations
Page 28 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
• Support legal defensibility: documented compliance programme is a mitigating factor in
regulatory investigations
⚖ Case Study: Marriott International Data Breach — £18.4 Million ICO Fine (2020)
Background: Marriott acquired Starwood Hotels in 2016 but failed to conduct adequate due
diligence on Starwood's IT systems. Hackers had been in Starwood's reservation system since
2014.
Breach discovered: November 2018 — 339 million guest records exposed, including passport
numbers, payment card data, and travel details of customers worldwide.
ICO Finding: Marriott failed to undertake sufficient due diligence during the Starwood acquisition;
technical security measures were inadequate; no proper review of data processing activities
inherited.
Fine: £18.4 million (reduced from initial proposed £99 million due to COVID-19 and mitigation steps
taken).
Audit Lesson: A pre-acquisition data protection audit of Starwood would have identified the lurking
breach and the inadequate security. GDPR Article 28 requires processor due diligence.
Compliance Programme Failure: No DPIA, no data mapping of acquired systems, no ISMS
assessment — all basic compliance audit activities that would have prevented or minimised this.
📝 Exam Tip
9-mark question: 'Evaluate how compliance audits help organisations avoid legal penalties and
data breaches.' — Cover: (1) What audits are (2) 8-stage audit process (3) Objectives (4) How
they prevent breaches (5) Real case — Marriott shows the cost of NOT auditing.
'Illustrate the consequences of improper data retention' — Use retention linked to breach exposure:
more data retained = larger breach impact = higher regulatory fine.
Page 29 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
SECTION 7: International Data Protection Standards
7.1 What are International Data Protection Standards?
International data protection standards are globally recognised frameworks, guidelines, and technical
specifications that provide consistent approaches to managing information security and privacy
across borders. Unlike national laws (which are binding in their jurisdiction), international standards
are generally voluntary but often become de facto requirements through regulatory expectations,
contractual obligations, or certification demands.
Standard / Framework Issuing Body Focus Area
ISO/IEC 27001:2022 ISO / IEC Information Security Management System
(ISMS)
ISO/IEC 27701:2019 ISO / IEC Privacy Information Management System
(PIMS) — extends 27001
ISO/IEC 27017:2015 ISO / IEC Cloud computing security controls
ISO/IEC 27018:2019 ISO / IEC Protection of PII in public cloud (cloud
processor standard)
NIST Privacy Framework (2020) NIST (USA) Privacy risk management for US
organisations
NIST CSF 2.0 (2024) NIST (USA) Cybersecurity risk management
framework
PCI-DSS v4.0 PCI Security Payment card data security
Standards Council
SOC 2 Type II AICPA Service organisation controls for security,
availability, confidentiality
OECD Privacy Guidelines OECD Principles for protection of personal data
across member countries
7.2 Significance of ISO 27001 and ISO 27701 in Global Data Protection
7.2.1 Global Recognition and Cross-Border Trust
ISO 27001 certification is accepted by organisations and regulators worldwide as evidence of robust
information security. It enables:
• Multinational organisations to demonstrate a consistent security baseline across all their
offices globally
• Cross-border data transfers with confidence that recipient meets adequate security standards
• Clients and partners to trust that a supplier's data handling meets internationally recognised
standards
• Easier compliance with multiple national laws — meeting ISO 27001 often satisfies the
'appropriate technical and organisational measures' required by GDPR, CCPA, DPDPA, and
similar laws
Page 30 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
7.2.2 How ISO 27001 + 27701 Together Support GDPR Compliance
GDPR Requirement ISO 27001 Control ISO 27701 Addition
Art. 5(1)(f) — Integrity & Access control, encryption, PII-specific access restrictions;
Confidentiality logging controls in Annex A privacy-preserving data handling
Art. 25 — Privacy by Risk assessment and treatment Integrate privacy requirements into
Design at design stage ISMS scope at system design
Art. 30 — Records of Asset management and risk PII processing records; identify data
Processing register flows; document lawful basis
Art. 33–34 — Breach Incident detection and response Privacy incident classification;
Notification procedures notification obligations for PII
breaches
Art. 35 — DPIA Risk assessment methodology Privacy risk assessment integrated
into ISMS; template for PII-specific
DPIAs
Art. 28 — Processor Supplier security assessments Data processor requirements under
Obligations PIMS; contractual privacy obligations
7.3 Benefits of Adopting International Data Protection Standards
• Single framework applicable across jurisdictions — reduces compliance complexity
for multinationals: Unified Framework
• ISO 27001/27701 certification signals trustworthiness to customers, partners, and
investors: Competitive Advantage
• Certification is evidence of accountability; regulators consider it a mitigating factor:
Regulatory Goodwill
• Large enterprises (e.g., banks, government contractors) increasingly require ISO 27001
from vendors: Supply Chain Security
• Annual surveillance audits and 3-year recertification cycles ensure standards evolve
with threats: Continuous Improvement
• ISO 27001 certification often reduces cyber insurance premiums: Cyber Insurance
7.4 Challenges of Implementing International Standards
• Initial implementation requires significant investment in gap analysis, documentation,
controls, and certification audit fees: Cost and Resource Intensive
• Staff at all levels must change behaviour and adopt security-conscious practices —
resistance is common: Cultural Change
• Deciding what is 'in scope' for certification is complex — too narrow is misleading; too
broad is unmanageable: Scope Definition
• Standards must be continuously maintained — policies updated, audits conducted,
risks reassessed annually: Maintenance Burden
Page 31 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
• Standards are not automatically accepted as legal compliance — must be mapped to
each jurisdiction's law: Jurisdictional Gaps
• Emerging technologies (AI, cloud, IoT) create new risks that standards address with a
lag: Keeping Pace with Technology
🌍 Real-World Example: How Multinationals Manage Data Privacy — Microsoft
Microsoft holds ISO 27001, ISO 27017, ISO 27018, and ISO 27701 certifications across its cloud
services.
For EU customers: Microsoft uses GDPR-compliant data processing agreements, EU Standard
Contractual Clauses for transfers, and EU Data Boundary (data stays within the EU).
For US government: Microsoft Government Cloud meets FedRAMP High and NIST 800-53
requirements.
For healthcare: Microsoft Azure Health Data Services meets HIPAA compliance requirements.
This multi-standard approach allows Microsoft to serve customers across 190 countries, each with
different privacy laws, while maintaining a consistent security baseline validated by ISO
certifications.
Page 32 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
SECTION 8: Ethical Considerations in Data Protection
8.1 Ethical Principles in Data Protection Practice
Ethical Principle Meaning in Data Protection Context Example
Transparency Individuals must know what data is Clear, plain-language privacy notice
collected and why; no hidden — not buried in 50-page terms
processing
Autonomy / Informed Individuals must have meaningful Granular consent for different
Consent choice and control over their data purposes; easy opt-out
Fairness Processing must not disadvantage or AI credit scoring must not use proxy
discriminate against individuals variables that discriminate by
race/gender
Accountability Organisations must own responsibility DPO, compliance programmes, audit
for how they handle data trails
Non-maleficence Processing should not cause harm — Health data breaches can cause
physical, financial, reputational, or insurance discrimination and
psychological psychological harm
Beneficence Processing should provide genuine Medical research using patient data
benefit to society or individuals, should demonstrably advance public
proportionate to risks health
Justice / Data collected and used must be CCTV in public spaces must be
Proportionality proportionate to the purpose justified by public safety needs — not
mass surveillance
8.2 Ethical Dilemmas in Data Protection
8.2.1 Business Interests vs. Privacy Rights
Organisations generate revenue through data-driven advertising, personalisation, and analytics. This
creates tension with individuals' rights to privacy.
🌍 Real-World Example: Targeted Advertising — Facebook (Meta) Business Model
Meta's core revenue model (advertising ~97% of revenue) depends on granular personal data
profiling of users.
Ethical tension: Users 'consent' to data collection as part of using a 'free' service — but the consent
is structurally coerced (no meaningful alternative for social connection).
GDPR (DPC Ireland, 2023): €390 million fine for relying on 'contract' as lawful basis for behavioural
advertising instead of consent. Meta ordered to obtain explicit consent.
Ethical dilemma: The business model itself was found incompatible with data protection law — not
just a compliance gap but a fundamental conflict between the monetisation model and privacy
rights.
Lesson: Legitimate interests and contract cannot be used to override the GDPR's core requirement
that individuals have genuine choice over how their data is used for advertising.
Page 33 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
8.2.2 Research and Public Interest vs. Individual Privacy
Using personal health or financial data for research can deliver enormous public benefit (e.g., COVID-
19 vaccine development using NHS patient data) but raises questions of consent, identifiability, and
secondary use.
8.2.3 Security vs. Privacy
Government surveillance for national security (e.g., bulk metadata collection by intelligence agencies)
conflicts with citizens' right to privacy. Courts and laws attempt to balance these interests through
oversight mechanisms, proportionality tests, and judicial authorisation requirements.
8.3 Ethical Responsibilities of Data-Driven Organisations
• Treat privacy as a genuine value, not a box-ticking exercise: Go beyond minimum
compliance
• Embed privacy into all products and services from inception: Design for privacy
• Explain automated decisions affecting individuals in clear language: Be transparent
about AI decisions
• Ensure that individuals can actually exercise their rights, not just nominally: Provide
meaningful redress
• Children, elderly, and marginalised groups require extra protection: Consider vulnerable
groups
• Regular ethics committee review of high-risk data use cases — not just legal review:
Conduct ethical reviews
Page 34 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
SECTION 9: Real-World Case Studies in Data Protection
9.1 Purpose of Case Studies in Data Protection
Real-world case studies illustrate how data protection principles and laws apply in practice. They
reveal the types of failures organisations make, the consequences they face, and the lessons that
can prevent future incidents. Regulators often publish case studies to guide organisations.
• Demonstrate the real-world cost of non-compliance (financial penalties, reputational damage)
• Show how abstract legal principles (e.g., Purpose Limitation) translate into concrete failures
• Provide precedents for how regulators interpret and apply rules
• Enable organisations to learn from others' mistakes rather than their own
9.2 Major Data Breach Cases and Lessons
⚖ Case Study: Case 1: Meta (Facebook) — €1.2 Billion Fine (2023)
Violation: International data transfer violation — EU users' data transferred to US servers without
adequate protection after Schrems II invalidated Privacy Shield.
Finding: SCCs used by Meta insufficient to protect EU data from US government surveillance law
(FISA Section 702).
Penalty: €1.2 billion — largest GDPR fine in history. Meta ordered to suspend US transfers and
delete unlawfully transferred data.
Legal/Ethical Lesson: Structural legal incompatibility between US surveillance law and EU privacy
rights cannot be papered over with contractual clauses.
Corrective Action: EU-US Data Privacy Framework (DPF) adopted in 2023 as new adequacy
decision — though already challenged by privacy advocates.
⚖ Case Study: Case 2: Amazon — €746 Million Fine (Luxembourg, 2021)
Violation: Advertising targeting system processed personal data without a valid lawful basis.
Consent given by users was deemed invalid — not freely given, not specific enough.
Context: Amazon's system for targeting ads to users based on behavioural profiling was found to
violate GDPR's transparency and lawful basis requirements.
Penalty: €746 million — second-largest GDPR fine. CNPD (Luxembourg DPA) issued the fine after
a complaint by French privacy rights group La Quadrature du Net.
Lesson: Consent for advertising profiling must meet the GDPR high bar: granular, specific, freely
given, and as easy to withdraw as to give. Amazon's consent mechanism failed this test.
⚖ Case Study: Case 3: British Airways — £20 Million ICO Fine (2020)
Breach: Hackers injected malicious code into BA's website, diverting customers to a fraudulent
site that harvested payment card details. ~500,000 customers affected.
Violation: GDPR Article 5(1)(f) — Integrity and Confidentiality; inadequate security measures
allowed the breach to persist undetected.
Page 35 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Original proposed fine: £183 million (1.5% of annual turnover). Final fine: £20 million (reduced due
to COVID-19 financial hardship and mitigation measures).
Technical Failure: Outdated software, lack of multi-factor authentication, insufficient monitoring
and anomaly detection.
Lesson: GDPR requires 'appropriate technical and organisational measures' proportionate to the
risk. Outdated legacy systems and absence of modern security monitoring violate this obligation.
⚖ Case Study: Case 4: WhatsApp (Meta) — €225 Million Fine (Ireland, 2021)
Violation: GDPR transparency obligations — WhatsApp failed to tell users in a clear and accessible
way how their data was being processed, including data shared with other Meta companies.
Finding: Privacy notices were confusing, vague, and did not adequately explain the legal basis for
processing or how data was shared across the Meta group.
Penalty: €225 million. WhatsApp ordered to bring its processing into compliance.
Transparency Lesson: GDPR Article 13 requires privacy information to be provided in a 'concise,
transparent, intelligible and easily accessible form, using clear and plain language.' Legal jargon
and buried disclosures are non-compliant.
⚖ Case Study: Case 5: Cambridge Analytica / Facebook (2018–2019)
Background: Cambridge Analytica harvested data of approximately 87 million Facebook users
without adequate consent, via a personality quiz app. Data was used to build psychographic
profiles for targeted political advertising (US 2016 election, Brexit).
Violations: Facebook breached its own platform policies; Cambridge Analytica used data far
beyond the original purpose of the quiz (purpose limitation violation).
Consequences: Facebook fined $5 billion by FTC (USA); £500,000 by ICO (UK — maximum under
pre-GDPR law); Cambridge Analytica shut down.
GDPR Relevance: Had GDPR been in force, Facebook could have faced fines up to €1.6 billion
(4% of ~€40 billion turnover at the time).
Ethical/Legal Lesson: Third-party app developers accessing platform data must be contractually
bound and technically constrained to prevent secondary use. Purpose limitation applies to
downstream data users, not just the original collector.
Corrective Measures: Facebook introduced App Review, restricted API access, and implemented
data abuse bug bounty programmes.
⚖ Case Study: Case 6: Equifax Data Breach — $575 Million FTC Settlement (USA, 2019)
Breach: In 2017, Equifax (US credit bureau) suffered a breach exposing sensitive personal and
financial data of 147 million Americans, 15 million UK citizens, and ~19,000 Canadian consumers.
Root Cause: Failure to patch a known Apache Struts vulnerability (CVE-2017-5638) for over two
months after a patch was available. Inadequate network segmentation allowed lateral movement.
Penalty: $575 million FTC settlement; $575–700 million total settlements including with state AGs
and class actions. UK ICO: £500,000 (pre-GDPR maximum).
Violations: Failure to maintain adequate security measures; retaining sensitive data longer than
necessary; unencrypted storage of certain data.
GDPR Lesson: Under GDPR, Equifax's UK fine would have been up to €20 million or 4% of global
turnover — approximately €160 million at 4%.
Page 36 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Systemic Failure: No effective vulnerability management programme, inadequate security
monitoring, poor network architecture — all failures that a rigorous ISO 27001 ISMS would have
addressed.
9.3 Framework for Analysing a Data Breach Case Study
Use this structure to answer 9-mark case study questions:
Step Question to Answer
1. Facts What happened? Who was affected? What data was involved?
2. Violation Which specific legal obligations / GDPR Articles were violated?
3. Penalty What regulatory action / fine was imposed?
4. Root Cause What was the underlying technical, organisational, or process failure?
5. Lesson What should other organisations learn? What compliance measures would have
prevented this?
6. Corrective What did the organisation do (or should have done) to remediate?
Action
📝 Exam Tip
Q: 'Analyze a practical case of data protection failure and recommend corrective measures.' (9
marks)
Choose: British Airways (security failure), Meta (transfer failure), or Equifax (vulnerability
management). Use the 6-step framework above.
Q: 'Discuss a major data breach case study and its legal and ethical implications.' — Cover BOTH
legal (what law was violated, what fine) AND ethical (what rights were harmed, what trust was
broken).
Q: 'How can organisations learn from past data breach case studies?' — Answer: Regulatory
publications, industry information sharing (e.g., ISACs), post-incident reviews, compliance
programme updates.
Page 37 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
SECTION 10: Consolidated Quick Reference for Exam
10.1 Key Numbers and Timelines
Item Value / Timeframe
GDPR effective date 25 May 2018
GDPR upper tier fine €20 million or 4% of global annual turnover (higher of the
two)
GDPR lower tier fine €10 million or 2% of global annual turnover (higher of the
two)
GDPR breach notification to DPA Within 72 hours of becoming aware
GDPR response to data subject requests Within 1 month (extendable by 2 months for complex
cases)
CCPA effective date 1 January 2020
CPRA effective date 1 January 2023
CCPA fine per intentional violation Up to $7,500
7-year financial record retention (UK) 6 years from financial year end (Companies Act 2006)
India DPDPA enacted August 2023
ISO 27001 latest version ISO/IEC 27001:2022
ISO 27701 issued 2019 — Privacy extension to ISO 27001
Largest GDPR fine (as of 2024) €1.2 billion — Meta (DPC Ireland, 2023)
10.2 Definitions Cheat Sheet
Term Definition
Personal Data Any information relating to an identified or identifiable natural
person
Data Controller Entity that determines the purposes and means of processing
personal data
Data Processor Entity that processes personal data on behalf of a controller
Data Subject The natural person whose personal data is being processed
DPO (Data Protection Officer) Mandatory independent expert responsible for overseeing GDPR
compliance in certain organisations
DPIA (Data Protection Impact Structured risk assessment required before high-risk processing
Assessment) activities
RoPA (Records of Processing Mandatory documentation of all personal data processing activities
Activities) (GDPR Art. 30)
Page 38 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Term Definition
ISMS (Information Security Systematic framework of policies, processes, and controls for
Management System) managing information security (ISO 27001)
PIMS (Privacy Information Extension of ISMS focused on personal data protection (ISO
Management System) 27701)
CIA Triad Confidentiality, Integrity, Availability — the three core objectives of
information security
Adequacy Decision European Commission ruling that a third country provides
equivalent data protection to the EU
SCCs (Standard Contractual Pre-approved contract terms for lawful cross-border data transfers
Clauses) from the EU
Purpose Limitation Principle that data can only be used for the specific purpose for
which it was originally collected
Storage Limitation GDPR principle that data must not be kept longer than necessary
for its purpose
Pseudonymisation Replacing identifying information with a pseudonym/code, so data
cannot be attributed without additional information
Data Retention Policy Formal document specifying how long different categories of data
are kept before deletion
Compliance Audit Systematic independent review to verify an organisation's practices
conform to applicable laws and standards
Ethical Dilemma A situation where complying with legal requirements alone is
insufficient to ensure ethical use of data
10.3 Module 4 Syllabus Coverage Map
Syllabus Topic Section in These Notes Key 9-Mark Q Numbers
Government Regulatory Frameworks Sections 1, 2, 3 Q145, 146, 147, 151, 152, 153
— GDPR, CCPA
Security Standards (ISO 27001, ISO Section 4 Q157, 158, 159, 162
27701, CIA)
Data Retention Policies — GDPR, 7- Section 5 Q163, 164, 165, 172
Year Rule
Compliance and Audits Section 6 Q169, 170, 171, 172
International Standards Section 7 Q175, 176, 177, 178
Ethical Considerations Section 8 Q181, 182, 183, 184
Real-World Case Studies Section 9 Q187, 188, 189
End of Module 4 — Detailed Classroom Notes
Page 39 | Data Privacy & Ethics | Academic Use
Module 4 | Government Regulatory Frameworks & Data Protection •
Government Regulatory Frameworks | Data Protection | Security Standards | Retention | Compliance | International
Standards
Page 40 | Data Privacy & Ethics | Academic Use