21°C

broken clouds

TFL Updates
London Daily News

The same question, asked by 3 regulators: GDPR, HIPAA, and PCI DSS

Partner Content
The same question, asked by 3 regulators: GDPR, HIPAA, and PCI DSS

A hospital in Cleveland, a payment processor in Warsaw, and an insurer in Dublin have little in common on paper. Different products, different customers, regulators an ocean apart. Ask each one the same question and the resemblance shows: who touched this record, and can anyone prove it? That question sits underneath GDPR, HIPAA, and PCI DSS, even though the 3 were written decades apart. A single access-control gap can trip GDPR in Frankfurt, HIPAA in Ohio, and PCI DSS in Warsaw inside the same fiscal quarter. Few internal security teams are staffed to answer for all 3 at once, which is why demand for outside data governance services keeps growing. The rules didn’t change overnight. The number of them stacking on top of a single company did.

None of the 3 regulations use that phrase, of course. GDPR talks about lawful processing and accountability. For HIPAA, the concern is safeguards over protected health information. PCI DSS, meanwhile, is written around controls over cardholder data. Strip away the vocabulary and each one asks a company to know where sensitive data lives, who can reach it, and what happens when something goes wrong. Building that oversight into daily operations, instead of assembling it after an auditor calls, is what a data governance program is for. It sounds simple, until the map gets drawn: 3 regulators, each with a different definition of what counts as sensitive, and 3 clocks running on how fast a breach must be reported.

3 Origins, the Same Habit of Mind

GDPR came out of Brussels in 2016 and took effect in 2018, built on the idea that people have a right to know what companies do with their data, and to say no. Its reach runs wider than most American businesses expect; a single sale into the EU can be enough. The bite is real: European regulators pushed the total value of GDPR fines past €7.1 billion by January 2026, with roughly €1.2 billion of that landing in 2025 alone, while breach notifications climbed to an average of 443 a day, a 22% jump from the year before, according to DLA Piper’s annual survey. Numbers like that don’t move because regulators got bored. They move because more companies are collecting more data than they can account for.

HIPAA is older and narrower by design. Congress passed it in 1996 to let workers keep health insurance between jobs; the privacy and security rules came later, once regulators saw that a portable insurance market needed a leash on medical records. It binds providers, insurers, and the vendors those 2 groups hire, from a hospital’s server room to the payroll firm processing claims. The failure mode looks familiar year after year. Rarely is it a hacker cracking a firewall; more often it’s a badly configured system, an old account nobody deactivated, or an inbox missing multi-factor authentication.

PCI DSS answers to nobody in government at all. Visa, Mastercard, and the other card networks built it in 2004, then handed enforcement to their own contracts. Any business processing card payments has to comply, and the standard keeps adding teeth. Version 4.0.1 finished its transition period on March 31, 2025, when a set of previously optional controls, including multi-factor authentication, became mandatory across the board. Card networks can now fine a non-compliant merchant up to $100,000 a month.

Where the Paperwork Starts to Look the Same

Line the requirements up side by side, and the differences start to shrink. GDPR calls for records of processing activity. A risk analysis is what HIPAA wants instead. PCI DSS calls for a defined scope of the cardholder data environment. Same homework, wearing 3 different labels. A company that knows where its data lives, who can reach it, and how fast it can prove that to an auditor has cleared most of the bar for all 3 regulators. That kind of clarity is what people mean by “data governance services,” whether a company buys it from outside or builds it in-house, and most compliance rebuilds start from the same short list of gaps:

  • Data nobody has mapped, sitting on a server nobody remembers provisioning
  • Access rights granted years ago and never once revisited
  • Audit logs that exist on paper but that nobody reviews
  • A breach-notification clock that starts before legal even hears about it

Email shows how small the gap can be. Compromised email accounts caused close to 25% of last year’s large healthcare breaches, and another 61.5% traced back to exposed or stolen data on network servers. Neither cause needed a nation-state attacker. Both needed, at some point, for someone to stop checking who still had access to what.

Building the Structure Once, Not 3 Times

The practical fix rarely means running 3 separate compliance projects side by side, though that is exactly what happens by default. GDPR usually reports to legal, HIPAA lands with a compliance officer, and PCI DSS answers to whoever owns the payment stack. Nobody owns the whole picture. Firms that specialise in data governance services, N-iX among them, start by building 1 map of where sensitive data sits, then layer each regulator’s rule on top instead of drawing the map 3 separate times. The strictest applicable rule wins for any given data type, which leaves most companies running tighter access controls than any single regulator would demand.

That single map does something else too. It turns audit season from a fire drill into paperwork. When the same evidence trail satisfies a GDPR data subject request, a HIPAA risk assessment, and a PCI DSS report on compliance, the marginal cost of adding a 4th regulation later drops sharply. Not to zero. Just sharply.

Coordinating that kind of program across legal, security, and engineering is unglamorous work, and it rarely fits inside any one department’s headcount. That gap is why a growing number of businesses look outside for help, treating the work less like a project with an end date and more like ongoing upkeep. For instance, N-iX has built parts of its practice around that kind of long-running engagement, mapping data once and maintaining the map as regulations shift under it.

Conclusion

GDPR, HIPAA, and PCI DSS were never built to talk to each other. One comes from a government, one from healthcare law, and the third from private card networks. But look past the specialised vocabulary and the requirements converge: locate the data, restrict access, and document everything. Companies that build a unified foundation to meet those shared demands upfront avoid building three separate fixes later – turning audit season into a routine paperwork review rather than a crisis.

 

Feature image by Pixabay from Pexels

Pin It on Pinterest