8.3 IT Governance, Regulatory Compliance & Data Privacy
Key Takeaways
- Compliance scope depends on the organization, data, processing, location, contract, and industry; a project manager verifies applicability rather than relying on labels.
- GDPR territorial scope concerns EU establishments and certain offering or monitoring of people in the EU, not citizenship alone.
- HIPAA applies to covered entities and relevant business associates handling protected health information, not every organization that holds health-related data.
- PCI DSS provides payment-account security requirements for entities that store, process, transmit, or can affect cardholder-data environments; compliance programs are managed by payment brands and acquirers.
- Data confidentiality requires identifying PII and PHI, applying relevant country, state, province, industry, and organizational rules, and documenting accountable controls.
IT Governance, Regulatory Compliance & Data Privacy
Project managers do not operate in a vacuum. Every project, especially in IT, is subject to a complex web of internal policies, industry standards, and government regulations. The CompTIA Project+ exam requires a solid understanding of IT governance frameworks, the critical nature of regulatory compliance, and the principles of data privacy. A project that delivers its technical objectives but violates a major privacy regulation is a failed project that can cost an organization millions in fines and reputational damage.
Understanding IT Governance
IT Governance is a formal framework that provides a structure for organizations to ensure that IT investments support business objectives. It is the process by which leadership directs and controls IT. Effective governance ensures that IT delivers value, manages risks effectively, and uses resources responsibly.
Without governance, IT departments can become disconnected from the business, pursuing "shadow IT" projects or adopting technologies that don't align with corporate strategy. Two major frameworks dominate the IT governance landscape:
- COBIT (Control Objectives for Information and Related Technologies): Created by ISACA, COBIT is a comprehensive framework focused heavily on risk management, regulatory compliance, and aligning IT goals with business goals. It provides a set of controls and metrics for IT management and auditors to evaluate the effectiveness of IT processes.
- ITIL (Information Technology Infrastructure Library): While COBIT focuses on "what" needs to be controlled, ITIL focuses on "how" to manage IT services. ITIL provides a detailed set of best practices for IT service management (ITSM), focusing on aligning IT services with the needs of the business, managing the lifecycle of IT services, and continuous improvement.
Project managers must understand which governance frameworks their organization utilizes. Projects must adhere to the change management processes, risk assessment protocols, and reporting structures defined by these frameworks.
Navigating Regulatory Compliance
Compliance refers to an organization's adherence to external laws, regulations, and industry standards. Governance includes internal policies and external obligations. Laws, regulations, contracts, and industry programs create different forms of compliance, so the project must identify which authority and scope apply.
Project managers must identify all relevant regulatory requirements during the initiation and planning phases of a project. Examples for practicing applicability and scope analysis include:
- GDPR (General Data Protection Regulation): An EU regulation whose territorial scope covers processing in the context of an EU establishment and certain processing by non-EU organizations when offering goods or services to, or monitoring, people in the EU. It is not based on EU citizenship alone. Controllers generally notify the competent supervisory authority without undue delay and, where feasible, within 72 hours unless the breach is unlikely to risk people’s rights and freedoms.
- HIPAA (Health Insurance Portability and Accountability Act): U.S. rules that apply to health plans, health care clearinghouses, certain health care providers, and relevant business associates. A project first determines whether a covered entity or business-associate relationship and protected health information (PHI) are involved; not every employer or health-data project is directly covered.
- PCI-DSS (Payment Card Industry Data Security Standard): An industry security standard for entities that store, process, or transmit cardholder or sensitive authentication data, or can affect the security of the cardholder-data environment. It is not a government statute; payment brands, acquirers, and other compliance-program operators determine requirements and validation obligations.
- Sarbanes-Oxley Act (SOX): A U.S. law designed to protect investors from fraudulent corporate accounting practices. It mandates strict controls over financial reporting and the IT systems that support financial data.
The Principles of Data Privacy
Data privacy is closely related to compliance but focuses specifically on the proper handling, processing, storage, and usage of personal data. At the core of data privacy is Personally Identifiable Information (PII). PII is any data that could potentially identify a specific individual (e.g., name, Social Security number, biometric records).
Project managers must ensure that projects respect data privacy principles:
- Data Minimization: Only collect the data absolutely necessary for the specific purpose of the project. If you don't need a user's date of birth, don't ask for it.
- Data Classification: Not all data is created equal. Organizations must classify data based on its sensitivity (e.g., Public, Internal, Confidential, Restricted). Security controls and handling procedures are then applied based on the classification level. A project manager must know the classification of the data their project handles.
- Data Sovereignty: Data location can affect legal, regulatory, and contractual obligations, but location is not the only factor. Assess where data subjects, controllers, processors, systems, and processing activities are located and which cross-border rules apply.
- Anonymization and Pseudonymization: When using data for testing or analytics, identifying details should be removed (anonymized) or replaced with artificial identifiers (pseudonymized) to protect privacy while still allowing the data to be useful.
Integrating Compliance into Project Management
A proactive project manager integrates compliance and privacy into the project lifecycle from day one. This involves identifying legal stakeholders early, conducting privacy impact assessments during the planning phase, and ensuring that security and compliance requirements are documented explicitly in the project scope and tested thoroughly before deployment.
Exam Trap: Do not confuse ITIL with COBIT. ITIL is about service management (how to run the IT helpdesk, how to handle incident management). COBIT is about governance and control (ensuring IT investments map to business strategy and risks are mitigated).
Apply Objective 4.3 by Scope, Not by Label
Data confidentiality starts by identifying sensitive data and the obligations attached to it. PII can identify a person. The objectives use “personal health information” for PHI; in U.S. HIPAA terminology, PHI means protected health information within a covered context. A classification label alone is not a control, so connect the data to permitted use, access, transmission, retention, disposal, incident handling, and evidence requirements.
Applicability may come from country-, state-, or province-specific privacy rules; contracts; industry programs; or organization-specific policy. Identify the authority, territorial or organizational scope, regulated data and activity, accountable owner, required controls, test evidence, and retention period. Do not infer that a rule applies merely because its acronym appears in a scenario, and do not assume that one national rule resolves state, provincial, contractual, or industry obligations. Escalate legal interpretation to qualified organizational authorities while the project manager maintains traceability.
An e-commerce project will store and process payment card account data. Which industry security standard is designed for this environment?
Which IT governance framework focuses primarily on aligning IT goals with business goals and providing a set of controls for risk management and auditing?
A U.S. company directs an online campaign to people located in France and Germany and processes their personal data. Which regulation requires a territorial-scope assessment?
A project manager dictates that the new customer database should only store names and email addresses, explicitly removing a request to store user birthdates because that information is not needed for the system to function. Which data privacy principle is the PM applying?