Question 1 of 30
A multinational corporation, \"OmniCorp,\" headquartered in Switzerland, has implemented ISO 29100:2011 across its global operations. OmniCorp processes personal data of customers in the European Union (EU), California (USA), and Brazil. The company experiences a significant data breach affecting customers in all three regions. According to their internal policies, aligned with ISO 29100:2011, all data breaches are to be assessed and a determination made regarding the need for notification within 72 hours of discovery. Considering the relationship between ISO 29100:2011 and regional data protection regulations, what is OmniCorp\'s *primary* responsibility concerning data breach notification timelines in this scenario?
Comply with the specific data breach notification requirements of GDPR for EU customers, CCPA for California customers, and LGPD for Brazilian customers, irrespective of the internal 72-hour assessment policy.
Adhere strictly to the 72-hour notification timeline outlined in their internal policy, as ISO 29100:2011 compliance supersedes regional regulations.
Notify all affected customers globally within 72 hours, following the ISO 29100:2011 aligned internal policy, ensuring a uniform approach to data breach notification.
Delay notification until a comprehensive investigation is completed, regardless of regional regulatory timelines, to ensure accurate information is provided to data subjects.

Preparing for ISO 14040:2006 Lead Implementer? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free