A global e-commerce company processes customer payment information from multiple regions, including the European Union and the United States. During a routine audit, it is discovered that EU customer data is being stored on U.S.-based servers without a proper legal mechanism in place to validate the transfer.
Which of the following actions should the organization take FIRST to comply with privacy and data protection requirements?
A. Encrypt all stored EU customer data using AES-256 encryption.
B. Implement Standard Contractual Clauses (SCCs) or another approved transfer mechanism.
C. Anonymize all EU customer data before storage in the U.S.
D. Notify the affected EU customers and supervisory authority of the violation.