Prepare for the Drug Discovery and Healthcare Systems Test. Access flashcards and multiple-choice questions with hints and explanations. Ace your exam with our comprehensive resources!

Multiple Choice

Which statement best describes GDPR?

GDPR is the European Union regulation that governs how personal data of individuals in the EU is processed, emphasizing consent, transparency, and accountability. It requires that processing be lawful, fair, and limited to specific purposes, with a valid basis such as consent or another lawful ground. Data subjects have strong rights, including access to their data, correction, deletion (the right to be forgotten), restriction of processing, data portability, and the ability to object to processing. For transfers of personal data outside the EU, GDPR mandates safeguards or an adequacy decision to ensure protections follow the data. The rule applies to organizations inside the EU and to outside entities that process EU residents’ data, making its reach effectively extraterritorial. Importantly, GDPR is not limited to marketing data; health data and other personal data are protected when they qualify as personal data. HIPAA, by contrast, is a US framework focused on protected health information within the United States. The description that GDPR governs personal data in the EU with strict consent, rights, and cross-border transfer rules best captures its scope.

GDPR is the European Union regulation that governs how personal data of individuals in the EU is processed, emphasizing consent, transparency, and accountability. It requires that processing be lawful, fair, and limited to specific purposes, with a valid basis such as consent or another lawful ground. Data subjects have strong rights, including access to their data, correction, deletion (the right to be forgotten), restriction of processing, data portability, and the ability to object to processing. For transfers of personal data outside the EU, GDPR mandates safeguards or an adequacy decision to ensure protections follow the data. The rule applies to organizations inside the EU and to outside entities that process EU residents’ data, making its reach effectively extraterritorial. Importantly, GDPR is not limited to marketing data; health data and other personal data are protected when they qualify as personal data. HIPAA, by contrast, is a US framework focused on protected health information within the United States. The description that GDPR governs personal data in the EU with strict consent, rights, and cross-border transfer rules best captures its scope.