QuestionQ190

Designing for security and compliance

Your web application must meet the requirements of the European Union's General Data Protection Regulation (GDPR). You are responsible for its technical architecture. What should you do?

  • A Ensure that your web application only uses native features and services of Google Cloud Platform, because Google already has various certifications and provides ג€pass-onג€ compliance when you use native features.
  • B Enable the relevant GDPR compliance setting within the GCPConsole for each of the services in use within your application.
  • C Ensure that Cloud Security Scanner is part of your test planning strategy in order to pick up any compliance gaps.
  • D Define a design for the security of data in your web application that meets GDPR requirements.
Explanation

GDPR compliance requires workload-specific security and privacy controls. Cloud providers supply infrastructure controls and compliance resources, but the customer remains responsible for securing its application, data, access, configurations, and regulatory use case. The data-security design must therefore meet the applicable GDPR requirements.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!