ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A U.S.-based multinational uses a SaaS human-resources platform that stores backups in data centers located in Ireland and mainland China. The company receives a domestic subpoena from a U.S. regulator demanding the complete employee database for an investigation. The security team is concerned that a direct hand-over could breach both the EU GDPR and China's data-localization rules. Which action best addresses the conflict of laws before any disclosure is made?
First migrate the backups to a U.S. cloud region and then provide the data from there.
Ask the regulator to pursue the information through the applicable Mutual Legal Assistance Treaty channels in each country before any release.
Comply immediately, because the U.S. subpoena has extraterritorial reach under the CLOUD Act.
Strip all identifying fields from the records and send the remaining dataset so privacy laws no longer apply.
When a disclosure request from one jurisdiction threatens to violate privacy or data-localization laws in another, the preferred first step is to ask the requesting authority to obtain the data through the Mutual Legal Assistance Treaty (MLAT) or similar inter-governmental process. An MLAT request allows the foreign jurisdiction (Ireland or China) to review and, if appropriate, authorize the transfer under its own legal framework, thereby preventing the data controller from unilaterally breaching local statutes. Simply complying with the U.S. subpoena, copying the data to the United States, or anonymizing it without legal approval would still risk penalties under GDPR and China's Cybersecurity Law because the controller would have exported personal data without a lawful basis.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Mutual Legal Assistance Treaty (MLAT)?
Open an interactive chat with Bash
What are the EU GDPR and China's data-localization rules mentioned in the scenario?
Open an interactive chat with Bash
Why can't the company migrate backups to the U.S. or anonymize data to comply with the subpoena?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .