ExamOps Practice free

CompTIA Data+ DA0-002 · Free study guide

Objective 5.2 — Understand data compliance

Compliance turns external obligations and internal commitments into rules for collecting, storing, using, sharing, retaining, and reporting data. The correct action depends on the data, people, purpose, location, contract, and applicable authority. A familiar acronym alone is not enough.

Retention, storage, and replication

A retention schedule defines how long a category of data must or may be kept and what happens at the end of that period. Some rules establish a minimum period for evidence; privacy and minimization rules may also create a maximum. Keeping everything forever expands breach exposure, discovery burden, and storage cost.

A legal hold suspends ordinary deletion for records relevant to a dispute or investigation. A valid erasure request does not authorize an analyst to destroy records under hold. The request must be recorded and handled through the approved exception process.

Storage choices affect location, access, durability, and disposal. Moving data to an archive does not remove compliance duties. Backups, caches, temporary exports, and test copies remain in scope when they contain the regulated data.

Replication creates additional copies for availability or performance. It can cross jurisdictions, expand access, and complicate correction or deletion. Teams need an inventory of replicas and a rule for propagating retention, legal holds, and approved changes. Replication is not a substitute for backup history because corruption can replicate immediately.

Jurisdiction and data location

Jurisdictional requirements depend on the laws and authorities connected to the organization, person, transaction, and processing location. Data residency describes where data is stored. Data sovereignty emphasizes that data is subject to rules of the jurisdiction where it is located or processed.

A cloud provider region selection can support a residency requirement, but region alone does not prove compliance. Support access, backups, logs, subprocessors, and disaster-recovery copies may cross the stated boundary. Document the complete flow and obtain specialist review for cross-border transfers.

Do not assume the organization’s headquarters determines every applicable obligation. Rules can follow the individuals whose data is processed or the market where services are offered.

GDPR

The General Data Protection Regulation, or GDPR, governs personal-data processing within its scope and can apply to organizations outside the European Union when they offer goods or services to, or monitor, people in the EU.

Exam-relevant principles include a lawful and transparent purpose, collecting only what is necessary, keeping data accurate, limiting retention, protecting it, and demonstrating accountability. Individuals may have rights concerning access, correction, deletion, restriction, portability, and objection, subject to legal conditions and exceptions.

Consent is one possible legal basis, not the only one, and it is not valid merely because a box exists. A new analytical use must be compatible with the original purpose or supported by an approved basis. Analysts should route rights requests and suspected breaches through the formal process because identity checks, exceptions, and notification deadlines require coordinated handling.

PCI DSS

The Payment Card Industry Data Security Standard, or PCI DSS, is an industry security standard for environments that store, process, or transmit payment-card data. It is not a general privacy law for every customer field.

For analytics, minimize card data and avoid distributing full primary account numbers into warehouses, spreadsheets, and reports. Trend analysis normally needs amount, time, merchant, and a controlled token, not a readable card number. Controls include restricting access, protecting transmissions and storage, logging activity, managing vulnerabilities, testing controls, and maintaining policy.

Tokenization or truncation can reduce exposure, but implementation and scope require approved assessment. Renaming a card-number column, password-protecting an email attachment, or limiting a production copy to “internal use” does not make uncontrolled sharing compliant.

Classification and audit evidence

Data classification assigns handling levels based on sensitivity, impact, and obligation. Labels such as Public, Internal, Confidential, and Restricted should drive access, encryption, sharing, retention, monitoring, and disposal rules. A label without enforced handling requirements is decoration.

An audit evaluates whether stated controls exist and operate. Evidence may include approved policies, access reviews, tickets, data inventories, lineage, training records, test results, retention jobs, immutable logs, and incident records. Evidence should show who did what, when, under which approval, and with what result.

Logs must themselves be protected. An administrator who can alter both the sensitive data and the only audit trail defeats independent accountability.

Ethical collection and analysis

An action can be legally permitted and still be misleading or harmful. Data ethics asks whether collection and analysis are fair, necessary, transparent, representative, and proportionate to the decision.

Analysts should avoid deceptive survey wording, selective exclusion of unfavorable results, unjustified proxy variables, and claims of causation unsupported by the design. Historical labels may encode past discrimination. Small-group reporting can reveal individuals even when direct identifiers are removed.

Ethical practice documents limitations, tests outcomes across relevant groups, minimizes data, and provides review when analysis affects people. Sponsor pressure does not justify suppressing a material result.

Security incidents, breaches, and reporting

A security incident is an event that may threaten confidentiality, integrity, or availability. A data breach is a confirmed exposure, access, loss, or disclosure meeting the organization’s or applicable rule’s definition. Not every alert is a breach, but analysts should not delay escalation while trying to decide alone.

Follow the incident plan: detect and record, contain safely, preserve evidence, assess affected data and people, remediate the cause, make required notifications through authorized owners, and document lessons. Reporting obligations and timelines vary by jurisdiction, contract, and data type.

Do not destroy logs or silently correct records in a way that erases evidence. Communicate through approved channels; an unverified public statement can create additional harm.

Scenario: an international payment export

A retailer exports EU customer orders, including full card numbers, to a U.S. analytics workspace. Copies also exist in a test bucket and disaster-recovery region. An access log suggests a contractor downloaded the export.

The response activates the incident process and preserves logs rather than asking the contractor informally. The team inventories affected fields, people, locations, replicas, and access. Privacy and security owners assess GDPR, PCI DSS, contracts, and jurisdictional notification requirements. Access is contained without destroying evidence. Full card numbers are removed from the analytical design in favor of approved tokens or truncation. Classification drives tighter access and encryption. Retention and deletion cover the primary export, test copy, backups, and replicas, subject to any legal hold. The post-incident audit records decisions, notifications, remediation, and control tests.

Exam traps

Readiness checklist

Practice this objective

A free ExamOps account gives you 10 DA0-002 questions a day, with a written explanation on every one. No card required.

Start practicing free