Choose Your Reading Style
A professional-level summary covering key definitions, frameworks, and exam-relevant points.
Compliance Landscape by Sector
| Sector | Key Regulations | Primary Data Focus |
|---|---|---|
| Financial Services | Basel III/IV, SOX, MiFID II, BCBS 239 | Risk data, financial reporting, transaction data |
| Healthcare | HIPAA, GDPR (EU), HITECH | Protected health information (PHI) |
| Retail/E-commerce | GDPR, CCPA, PCI DSS | Customer personal data, payment card data |
| Public Sector | GDPR, Freedom of Information, sector-specific | Citizen data, public records |
| All Sectors (EU) | GDPR, NIS2, DORA (financial) | Personal data, cybersecurity |
Data Governance as the Foundation for Compliance
The capabilities required for data compliance — data inventory, data classification, data lineage, access controls, retention management, audit trails — are precisely the capabilities that a mature data governance programme provides. Organisations that invest in data governance find compliance significantly easier and less costly than those that treat compliance as a standalone initiative.
CDMP Exam Relevance
Data compliance appears across multiple CDMP knowledge areas, particularly Data Security and Data Governance. Key exam topics: the relationship between governance and compliance, the key regulations and their data management implications, and the governance capabilities required to demonstrate compliance. The CDMP exam tests whether candidates understand that compliance is a consequence of good governance, not a substitute for it.