2.5 Privacy Frameworks (GDPR/CCPA/HIPAA) & Business Continuity (BCP/DRP)
Master international and domestic privacy regulations (GDPR 72-hour breach notice, CCPA/CPRA consumer rights, HIPAA technical safeguards), alongside business continuity planning, disaster recovery site tiers (Hot/Warm/Cold), and RTO/RPO metrics.
🎯 Essential Technical Takeaways
- Under GDPR Article 33, personal data breaches posing risk to individuals must be reported to authorities within 72 hours of awareness.
- CCPA/CPRA grants consumers statutory rights to know, access, delete, correct, and opt-out of the sale/sharing of their personal information.
- HIPAA Technical Safeguards mandate unique user IDs, emergency 'break-glass' access, automatic logoff, and ePHI encryption.
- RPO measures maximum tolerable data loss in time (e.g., 15 mins); RTO measures maximum allowable downtime duration (e.g., 2 hours).
Organizations operating globally must comply with rigorous, overlapping privacy regulations. The European Union General Data Protection Regulation (GDPR) applies extraterritorially to any entity processing EU residents' data, establishing consumer rights (erasure, data portability) and mandating breach notification to supervisory authorities within 72 hours of becoming aware of a breach. Domestically, the California Consumer Privacy Act (CCPA/CPRA) grants consumers rights to know, delete, correct, and opt out of the sale or sharing of their personal information. In healthcare, the HIPAA Security Rule (45 CFR § 164.312) mandates technical safeguards including unique user IDs, audit logs, emergency break-glass procedures, and end-to-end ePHI encryption.
Operational resilience requires coordinated Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP). BCP is an enterprise-wide strategic framework ensuring continuous business operations, employee safety, crisis communication, and manual workarounds during a catastrophe. DRP is the technical IT subcomponent focused specifically on recovering computer systems, networks, and data.
Disaster recovery planning begins with a Business Impact Analysis (BIA) that establishes two critical metrics: Recovery Point Objective (RPO)—the maximum tolerable data loss measured backward in time, which dictates backup frequency—and Recovery Time Objective (RTO)—the maximum tolerable downtime before systems must be restored. Recovery facilities are tiered accordingly: Hot Sites provide live mirrored hardware and data for instantaneous failover; Warm Sites provide hardware requiring data restoration over days; and Cold Sites provide empty facility space requiring weeks of hardware installation.
⚠️ CPA Evolution Exam Traps & Control Pitfalls
- Confusing Business Continuity Planning (strategic, entity-wide operations) with Disaster Recovery Planning (technical IT restoration).
- Inverting Recovery Time Objective (downtime duration) with Recovery Point Objective (data loss volume/time).
- Believing cold sites can support recovery within minutes or hours (cold sites lack hardware and take weeks to operationalize).
Interactive Knowledge Checkpoint
A software company processing personal data of European Union residents suffers a confirmed cyber breach on Monday at 10:00 a.m. resulting in the unauthorized exfiltration of unencrypted customer financial records and passport scans. Under the EU General Data Protection Regulation (GDPR), within what timeframe must the data controller notify the competent supervisory authority?