A CISO claims that GDPR security of processing is fully satisfied by completing PCI-DSS checklists alone. Which statement best corrects that claim?
Select an answer to reveal the explanation.
Short Explanation
PCI is a useful toolkit for card data—not a substitute passport for every GDPR processing risk. The legal bar is appropriate TOMs matched to what you actually do with personal data. One industry checklist cannot swallow that whole standard.
Full Explanation
Article 32 sets a risk-based obligation to implement appropriate technical and organisational measures for personal data processing. Sector frameworks such as PCI-DSS may inform controls for payment-card environments but do not redefine or exhaust the GDPR security standard for all personal data. Adequacy must be judged against the processing risks, nature of the data, and organisational context—not by checklist substitution alone.