A university DPO asks what “related legislation” to the GDPR means for CIPP/E exam preparation. Which set correctly reflects BoK-named related European instruments rather than CIPP/US statutes?
Select an answer to reveal the explanation.
Short Explanation
Stay on the European shelf. Related legislation in a CIPP/E sense means things like ePrivacy, NIS/NIS 2, and the EU AI Act sitting next to the GDPR—not California CCPA, HIPAA, or FCRA from the US privacy track. Standards like ISO 27001 can help security practice, but they are not that legislative set.
Full Explanation
CIPP/E’s legislative-framework competency situates the GDPR among related European instruments, including ePrivacy rules, NIS/NIS 2 cybersecurity legislation, and the EU AI Act as BoK-recognized related law. US statutes such as CCPA/CPRA, HIPAA, FCRA, GLBA, and FTC Section 5 belong to other privacy curricula (notably CIPP/US) and are not the GDPR’s European related-legislation package. ISO 27001 is a management standard, not a substitute for those EU instruments.