Which Regulation Covers Individual Data Rights Like Access and Erasure?
Which of the following addresses individual rights such as the right to be informed, the right of access, and the right to be forgotten?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to differentiate between privacy regulations and security standards, with the common trap being confusion between NIST (a standards organization) and GDPR (a privacy regulation).
The GDPR is the regulation that establishes individual rights such as the right to be informed, the right of access, and the right to be forgotten, distinguishing it from security standards like PCI DSS, NIST, and ISO frameworks.
Choosing NIST is a common mistake because it is widely known in cybersecurity, but it is a standards framework, not a regulation granting individual privacy rights.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The GDPR (General Data Protection Regulation) is a comprehensive privacy regulation that explicitly grants individuals rights such as the right to be informed, the right of access, and the right to be forgotten. These rights are central to GDPR's data protection framework. Community comment [2] correctly identifies that GDPR addresses these individual rights directly, and comment [1] reinforces this by categorizing the other options appropriately.
Why the Other Options Are Wrong
PCI DSS is a security standard for payment card data, focused on protecting cardholder information, not individual privacy rights. NIST is the National Institute of Standards and Technology, a US agency that publishes cybersecurity frameworks, but it doesn't grant rights to individuals. ISO is an international standard-setting organization; while ISO/IEC 27701 relates to privacy, it is a management standard, not a regulation that grants legally enforceable individual rights.
Community Comment Notes
Comment [1] provides a useful breakdown: NIST is "Network institute of standards and technology" (a typo, but the correct context), PCI DSS is payment card industry standards, and ISO is international standards. Comment [2] directly states that GDPR addresses the rights named in the question. Comment [3] simply confirms the answer is A. These comments align with the consensus that GDPR is the correct choice.
Official Reference
Exam Strategy
When asked about individual rights such as data access or erasure, immediately think of the GDPR. Memorize the key GDPR rights (informed, access, rectification, erasure, restriction, portability, objection) and remember that standards like NIST and ISO are not regulations.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →