D1 — Legal, Regulatory, Compliance & Intellectual Property
The exam's legal vocabulary is GDPR/US-anchored, not DGSSI/Loi 09-08 — this lesson gives the specific framework the exam actually tests: GDPR breach notification, contract/liability basics, and the four IP protection types, each precisely distinguished from the others.
Learning Objectives
- → State GDPR's breach notification timeline precisely, including what starts the clock
- → Distinguish the exam's international/US-anchored legal framework from region-specific frameworks like Morocco's Loi 09-08/DGSSI regime
- → Distinguish the four intellectual property protection types by what each protects and for how long
- → Apply the CISSP mindset to a data breach scenario involving multiple jurisdictions
This is the specific pocket inside Domain 1 worth treating as a genuine cold-start gap, even though the rest of D1's governance and risk vocabulary maps closely onto your operational experience: the exam's legal content is anchored in international and U.S. frameworks (GDPR, HIPAA, common-law IP concepts), not the Loi 09-08 / CNDP / DGSSI regime you actually operate under day to day in Morocco. The concepts often rhyme, but the exam tests the specific international vocabulary — and this lesson deliberately keeps the two frameworks distinct rather than letting them blur together.
GDPR breach notification — the specific timeline
GDPR Article 33 requires notification to the relevant supervisory authority without undue delay and, where feasible, within 72 hours of the controller becoming aware of the breach — not from when the breach actually occurred. This distinction between "occurrence" and "awareness" is deliberately tested: an organization isn't penalized for the detection gap between when a breach happened and when it was discovered, but the clock starts ticking the moment awareness exists, and "we were still assessing" is not, by itself, grounds for unlimited delay.
A second, related notification requirement (Article 34) applies to the data subjects themselves (not just the regulator): notification "without undue delay" is required when the breach is likely to result in a high risk to individuals' rights and freedoms — a higher bar than the regulator-notification trigger, and on a different (less rigidly defined) timeline.
Worth naming explicitly, since it's a genuine and easy source of confusion: Morocco's own data protection regime (Loi 09-08, overseen by the CNDP) has its own separate notification and compliance requirements, distinct from GDPR's — the exam does not test Loi 09-08 specifics, but a real-world breach affecting both EU residents' data and Moroccan-processed data would trigger obligations under both frameworks independently. Knowing which framework the exam is testing (GDPR/international) versus which framework governs your actual operational context (Loi 09-08/DGSSI) is itself the skill this lesson is building.
Intellectual property — four distinct protections
CISSP expects precise recall of what each IP protection type covers, because scenario questions are built around picking the correct one for a described situation, not just recognizing the general concept of "IP":
| Protection | What it protects | Typical duration | Key limitation |
|---|---|---|---|
| Copyright | Original creative/expressive works (software code, documentation, media) | Author's life + 70 years (typical; varies by jurisdiction) | Protects the specific expression, not the underlying idea |
| Patent | A novel, useful, non-obvious invention or process | ~20 years from filing | Requires public disclosure of how the invention works |
| Trademark | A brand identifier (name, logo, symbol) distinguishing goods/services | Indefinite, with active renewal/use | Lost through non-use or failure to defend against infringement |
| Trade secret | Confidential business information providing competitive advantage (e.g. a proprietary algorithm kept undisclosed) | Indefinite, as long as secrecy is maintained | Protection is lost entirely and permanently once the secret becomes public, even accidentally |
The exam-relevant distinction most worth internalizing: a patent requires public disclosure in exchange for a time-limited legal monopoly, while a trade secret requires the opposite — permanent secrecy — in exchange for protection with no fixed expiration, but only for as long as the secrecy actually holds. Choosing between filing a patent and simply keeping something a trade secret is a real strategic trade-off scenario questions are built to test.
The CISSP mindset: manager vs technician
A company discovers a breach affecting both EU customer data and data from Moroccan customers. The security team immediately begins technical remediation and, once the fix is deployed a week later, considers the incident closed.
The technician answer: the vulnerability is patched, remediation is complete, the incident is resolved.
The manager (CISSP) answer: technical remediation alone leaves a legal and regulatory exposure gap open. If EU residents' data was affected, the 72-hour GDPR notification clock started at the moment of awareness, not at the moment remediation finished — waiting a full week to even consider the notification question likely already breaches that timeline. Separately, the same incident may independently trigger Loi 09-08/CNDP obligations for the Moroccan-customer data, a distinct legal track the GDPR analysis doesn't cover. The CISSP-correct response runs the legal/regulatory notification track in parallel with technical remediation from the moment of detection, not sequentially after — treating "the bug is fixed" and "the legal obligations are satisfied" as two separate, simultaneously-running requirements, not one gating the other.
A breach affecting EU residents' personal data actually occurred on a Monday, but the organization's monitoring didn't detect it until the following Thursday. The organization notifies the supervisory authority the following Monday (4 days after detection). Did they meet the GDPR notification requirement? Justify your answer using the specific trigger for the 72-hour clock.
Did they meet the requirement, and what specifically determines this?
A company develops a novel data-compression algorithm. Leadership is deciding between filing a patent (which requires publicly disclosing exactly how the algorithm works) and keeping it as a trade secret (never disclosing it, relying on internal confidentiality controls). Explain the core trade-off between these two choices.
What is the core trade-off between filing a patent and keeping the algorithm a trade secret?
A breach affects both EU customers' data and Moroccan customers' data processed under Morocco's Loi 09-08 regime. A junior compliance analyst argues that since the organization is notifying the GDPR supervisory authority, the Moroccan notification requirement is effectively covered too. Explain why this reasoning is incorrect.
Why is this reasoning incorrect?