Which Regulation Covers Individual Data Rights Like Access and Erasure?

Which of the following addresses individual rights such as the right to be informed, the right of access, and the right to be forgotten?

  1. GDPR Source Reference Answer
  2. PCI DSS
  3. NIST
  4. ISO

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to differentiate between privacy regulations and security standards, with the common trap being confusion between NIST (a standards organization) and GDPR (a privacy regulation).

The GDPR is the regulation that establishes individual rights such as the right to be informed, the right of access, and the right to be forgotten, distinguishing it from security standards like PCI DSS, NIST, and ISO frameworks.

Choosing NIST is a common mistake because it is widely known in cybersecurity, but it is a standards framework, not a regulation granting individual privacy rights.

Community Discussion (3 comments)

Syl0 👍 2
GDPR - General Data Protection Regulation NIST - Network institute of standards and technology, so doesn't have that. PCI DSS - Payment Card Industry Data security standards ISO - International standard for Standardisation
jafyyy 👍 1
A - Addressed individual rights to be informed, access or to be forgotten among other rights.
b82faaf 👍 2 Selected: A
A. GDPR

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The GDPR (General Data Protection Regulation) is a comprehensive privacy regulation that explicitly grants individuals rights such as the right to be informed, the right of access, and the right to be forgotten. These rights are central to GDPR's data protection framework. Community comment [2] correctly identifies that GDPR addresses these individual rights directly, and comment [1] reinforces this by categorizing the other options appropriately.

Why the Other Options Are Wrong

PCI DSS is a security standard for payment card data, focused on protecting cardholder information, not individual privacy rights. NIST is the National Institute of Standards and Technology, a US agency that publishes cybersecurity frameworks, but it doesn't grant rights to individuals. ISO is an international standard-setting organization; while ISO/IEC 27701 relates to privacy, it is a management standard, not a regulation that grants legally enforceable individual rights.

Community Comment Notes

Comment [1] provides a useful breakdown: NIST is "Network institute of standards and technology" (a typo, but the correct context), PCI DSS is payment card industry standards, and ISO is international standards. Comment [2] directly states that GDPR addresses the rights named in the question. Comment [3] simply confirms the answer is A. These comments align with the consensus that GDPR is the correct choice.

Official Reference

Exam Strategy

When asked about individual rights such as data access or erasure, immediately think of the GDPR. Memorize the key GDPR rights (informed, access, rectification, erasure, restriction, portability, objection) and remember that standards like NIST and ISO are not regulations.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide