A project manager is overseeing the implementation of a global customer data platform that will aggregate and analyze user behavior across multiple countries. Early in planning, the team identifies that different regions have varying data privacy and residency requirements.
What should the project manager do first to ensure proper handling of data compliance requirements?
A. Collaborate with legal and compliance stakeholders to identify applicable regulations and define data handling requirements
B. Configure system-level security controls based on standard organizational policies to protect sensitive data
C. Prioritize high-value analytics features to ensure early delivery of business insights
D. Conduct a technical feasibility assessment to determine how data can be integrated across regions
HINT: Think about what must be clearly understood before designing or implementing a solution involving sensitive data across regions.
All our questions are updated to the latest
A Guide to the Project Management Body of Knowledge (PMBOK® Guide) standard. Stop by at
free.pm-exam-simulator.com/
and try the PM Exam Simulator free for 7 days. We are a trusted and experienced education provider.
Answer and Explanation:
The correct answer is A.
The first step in managing data compliance is to confirm applicable regulations and define requirements with legal and compliance stakeholders. This ensures that all sensitive data is handled according to privacy, security, and regulatory standards, and it prevents violations or costly rework.
By confirming compliance requirements first, the project manager aligns with project compliance requirements, establishing a foundation for secure and lawful data handling.
Details for each option:
A. Correct. The project manager should first collaborate with legal and compliance stakeholders to identify applicable laws, regulations, and organizational policies. This ensures that data handling requirements are clearly defined before design and implementation begin. Establishing compliance early reduces the risk of violations, rework, and legal exposure
B. Incorrect. This is premature because implementing controls without understanding regulatory requirements may lead to gaps or misalignment.
C. Incorrect. This option focuses on value delivery but ignores compliance obligations.
D. Incorrect. This is important but should occur after compliance constraints are understood, as these constraints directly influence technical feasibility.