InterviewStack.io LogoInterviewStack.io
🛡️

Security Governance, Risk & Privacy Topics

Governance, compliance frameworks, regulatory requirements, compliance implementation, and compliance-driven risk management. Covers compliance frameworks (SOX, GDPR, HIPAA, FCPA, etc.), regulatory interpretation, compliance control design, audit and control effectiveness evaluation, and compliance process management. For operational security implementation and technical threat mitigation, see Security Engineering & Operations.

Research Ethics and Consent

Handling personal data in research responsibly: informed consent for studies, research ethics review, participant protection, and secondary-use limits. Covers designing user research and data-collection studies that respect participants and comply with privacy obligations. Includes balancing research value against participant privacy.

0 questions

Data Subject Rights and Request Handling

Operationalizing individual rights: access, rectification, erasure, portability, restriction, and objection requests. Covers identity verification, response timelines, locating data across systems to fulfill a request, and handling edge cases and exemptions. Includes designing systems that can execute deletion and export reliably at scale.

0 questions

GDPR Principles and Compliance

The General Data Protection Regulation in depth: the six lawful bases, data subject rights, accountability and records obligations, DPO requirements, and enforcement and fines. Covers how GDPR principles translate into concrete engineering and product controls. Includes controller and processor obligations and demonstrating compliance.

0 questions

Privacy by Design and Default

Embedding privacy into architecture and the development lifecycle: the privacy-by-design principles, privacy-protective defaults, and on-device or edge processing to minimize data exposure. Covers integrating privacy controls into product and program design and into engineering workflows rather than bolting them on. Includes designing privacy-first solutions and reference architectures.

0 questions

Communicating Security and Privacy Risk to Stakeholders and Leadership

Translating technical security, compliance, and privacy risk into language that executives, boards, and non-technical stakeholders can act on. Covers framing risk in business terms, influencing leadership on investment and strategy, tailoring the message to the audience, and driving decisions through communication. The persuasion-and-translation skill, distinct from the metrics themselves.

0 questions

Privacy in Emerging Technologies

Privacy challenges raised by newer technologies and business models: AI and machine learning, biometrics, IoT, and other data-intensive innovations, plus how regulators are responding. Covers anticipating future privacy risks and adapting practices ahead of formal rules. Includes reasoning about privacy in novel data uses where guidance is still forming.

0 questions

US State Privacy Laws (CCPA/CPRA)

California and other US state privacy statutes: consumer rights to know, delete, correct, and opt out of sale or sharing, sensitive-data limits, and the patchwork of state regimes. Covers how US law differs from GDPR in scope and mechanics and how to operationalize opt-out and disclosure duties. Includes the compliance obligations these laws place on data-handling systems.

0 questions

Platform Trust, Safety, and Regulatory Compliance

Regulatory and policy compliance for online platforms and consumer-facing products. Covers trust and safety program requirements, content and platform regulation, and translating platform-liability and consumer-protection obligations into product policy and controls. Product-and-policy view of compliance for platform businesses, distinct from infrastructure security.

0 questions

Global Privacy Regulations and Data Protection Frameworks

The landscape of privacy and data protection law and how core frameworks fit together: controllers vs processors, personal vs sensitive data, lawful processing, and cross-framework concepts. Covers foundational privacy terminology and how to reason about which regimes apply to a given data flow. Serves as the orientation layer beneath the regulation-specific topics.

0 questions
Page 1/2