CCSP - Legal, Risk and Compliance - Section 6.2

Understand privacy issues.

Difference between contractual and regulated private data, country-specific legislation, jurisdictional differences in data privacy, and standard privacy requirements.

personally identifiable information (PII)GDPRcontractual versus regulated dataISO/IEC 27018Generally Accepted Privacy Principles

Practice question for this objective

Free sampleLegal, Risk and Compliancemedium

A privacy officer needs to explain the difference between contractual data and regulated data to an engineering team. Which statement correctly describes regulated data?

  • ARegulated data is data whose protection obligations arise from a private agreement between two commercial parties.
  • BRegulated data is any data an organisation voluntarily chooses to classify as sensitive in its internal policy.
  • CRegulated data is data that has been anonymised so that it no longer identifies any individual.
  • DRegulated data is data whose handling requirements are imposed by law or statute, such as health or personal financial information. Correct
Recognise that regulated data derives its protection obligations from law, whereas contractual data derives them from private agreement. The regulated-versus-contractual distinction is about the source of the obligation. Regulated data is governed by statute or regulation that mandates specific handling, while contractual data is protected only because parties agreed to protect it. Health and personal financial data are classic regulated categories.

Why A is wrong: This describes contractual data, where obligations flow from an agreement such as a payment card scheme or a customer contract, not from statute.

Why B is wrong: Internal classification is a discretionary business decision; it does not make data regulated, which requires an external legal mandate.

Why C is wrong: Anonymisation removes identifiability and typically takes data out of privacy-law scope, which is the opposite of data being regulated.

Why D is correct: Regulated data carries protection duties set by legislation or regulation, so categories like health records under health-privacy law are the defining example.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Legal, Risk and Compliance objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.