Assume you are an IT security specialist for a large U.S. online retail organization that does business internationally. Your CIO has asked you to thoroughly review the new General Data Protection Regulation (GDPR) recently implemented in the European Union. He wants to understand exactly what the organization must do to comply with this regulation when doing business with EU customers.
Provide a detailed discussion about the rules for businesses and the rights of the EU citizens.
Include a discussion of the following:
- What does the GDPR govern?
- What rights do the EU citizens have with regard to their data?
- What is considered personal data under this regulation?
- What is considered data processing under this regulation?
- Describe the role of the data protection authorities (DPAs).
Discuss, in detail, how the GDPR will change business and security operations for your organization. Provide the CIO with a recommended checklist for GDPR compliance and discuss processes and policies that may need to be changed in order to comply with GDPR.
In your conclusion, address what you think will be the financial impact to the organization, both in terms of compliance and any lack of compliance.
Assignment Requirements
- The paper should be 3–4 pages.
- Use the rubric guide
- Use Times New Roman 12 pt font.
- Use APA formatting for paper, citations, and references.
- Be sure to cite your sources and provide the appropriate references
IT590 Unit 2 Assignment Rubric
Course: IT590 Legal and Ethical Issues in IT
Criteria 1
Level III Max
Points
45 points
Level II Max
Points
38.25 points
Level I Max
Points
31.5 points
Not Present
0 points
Criterion Score
Criteria 1:
GDPR
/ 45Meets all
criteria:
• Explains
what the
GDPR
governs.
• Discusses
the rights of
EU citizens
with regard to
their data.
• Describes
what is
considered
personal data
under
GDPR.
• Discusses
how business
processes and
policies will
change under
GDPR.
Meets three
criteria:
• Explains
what the
GDPR
governs.
• Discusses
the rights of
EU citizens
with regard to
their data.
• Describes
what is
considered
personal data
under GDPR.
• Discusses
how business
processes and
policies will
change under
GDPR.
Meets two
criteria:
• Explains
what the
GDPR
governs.
• Discusses
the rights of
EU citizens
with regard to
their data.
• Describes
what is
considered
personal data
under GDPR.
• Discusses
how business
processes and
policies will
change under
GDPR.
Does not meet
any criteria.
Criteria 2
Level III Max
Points
45 points
Level II Max
Points
38.25 points
Level I Max
Points
31.5 points
Not Present
0 points
Criterion Score
Unit 2 Assignment Dropbox – IT590 Legal and Ethical Issues in IT – Pu… https://purdueglobal.brightspace.com/d2l/lms/dropbox/user/folder_subm…
1 of 3 2/5/2023, 4:51 PM
https://purdueglobal.brightspace.com/d2l/home/243918
https://purdueglobal.brightspace.com/d2l/lms/dropbox/user/folders_list.d2l?ou=243918
https://purdueglobal.brightspace.com/d2l/lms/dropbox/user/folders_list.d2l?ou=243918
Criteria 2
Level III Max
Points
45 points
Level II Max
Points
38.25 points
Level I Max
Points
31.5 points
Not Present
0 points
Criterion Score
Criteria 2:
GDPR
Compliance
/ 45Meets all
criteria:
• Develops a
GDPR
checklist.
• Discusses
the financial
impact nf non‐
compliance
with GDPR.
• Describes
the role of the
DPAs.
Meets two
criteria:
• Develops a
GDPR
checklist.
• Discusses
the financial
impact nf non‐
compliance
with GDPR.
• Describes
the role of the
DPAs.
Meets one
criterion:
• Develops a
GDPR
checklist.
• Discusses
the financial
impact nf non‐
compliance
with GDPR.
• Describes
the role of the
DPAs.
Does not meet
any criteria.
Criteria 3
Level III Max
Points
10 points
Level II Max
Points
8.5 points
Level I Max
Points
7 points
Not Present
0 points
Criterion Score
Unit 2 Assignment Dropbox – IT590 Legal and Ethical Issues in IT – Pu… https://purdueglobal.brightspace.com/d2l/lms/dropbox/user/folder_subm…
2 of 3 2/5/2023, 4:51 PM
Total / 100
Overall Score
Criteria 3
Level III Max
Points
10 points
Level II Max
Points
8.5 points
Level I Max
Points
7 points
Not Present
0 points
Criterion Score
Criteria 3:
APA Style
and Writing
Conventions
/ 10Meets all
criteria:
● Applies
current APA
style to in‐text
citations and
references,
and document
formatting if
appropriate,
with minor to
no errors.
● Writing is
focused,
concise, and
organized and
articulates at a
college level,
with minor to
no errors.
● Uses
resources from
reliable and/or
scholarly
sources.
Meets two
criteria:
● Applies
current APA
style to in‐text
citations and
references,
and document
formatting if
appropriate,
with minor to
no errors.
● Writing is
focused,
concise, and
organized and
articulates at a
college level,
with minor to
no errors.
● Uses
resources from
reliable and/or
scholarly
sources.
Meets one
criterion:
● Applies
current APA
style to in‐text
citations and
references,
and document
formatting if
appropriate,
with minor to
no errors.
● Writing is
focused,
concise, and
organized and
articulates at a
college level,
with minor to
no errors.
● Uses
resources from
reliable and/or
scholarly
sources.
Does not meet
any criteria.
Level III
85.01 points minimum
Level II
70.01 points minimum
Level I
1 point minimum
Not Present
0 points minimum
Unit 2 Assignment Dropbox – IT590 Legal and Ethical Issues in IT – Pu… https://purdueglobal.brightspace.com/d2l/lms/dropbox/user/folder_subm…
3 of 3 2/5/2023, 4:51 PM