nerdexam
(ISC)2

CCSP · Question #220

Under EU law, a cloud customer who gives sensitive data to a cloud provider is still legally responsible for the damages resulting from a data breach caused by the provider; the EU would say that it…

The correct answer is C. Due diligence. The customer's failure to adequately evaluate a cloud provider's security and reliability before entrusting them with sensitive data is an example of insufficient due diligence.

Submitted by stefanr· Apr 18, 2026Legal, Risk and Compliance

Question

Under EU law, a cloud customer who gives sensitive data to a cloud provider is still legally responsible for the damages resulting from a data breach caused by the provider; the EU would say that it is the cloud customer's fault for choosing the wrong provider. This is an example of insufficient ____________.

Options

  • AProof
  • BEvidence
  • CDue diligence
  • DApplication of reasonableness

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    11% (2)
  • C
    84% (16)

Why each option

The customer's failure to adequately evaluate a cloud provider's security and reliability before entrusting them with sensitive data is an example of insufficient due diligence.

AProof

Proof refers to evidence or argument establishing a fact, not the prior investigation process.

BEvidence

Evidence refers to information used to prove a point, which is distinct from the proactive investigation of due diligence.

CDue diligenceCorrect

Due diligence refers to the reasonable steps an organization must take to investigate and understand the risks associated with a decision or relationship, such as selecting a cloud provider. Under EU law (like GDPR), a data controller (customer) is legally responsible for ensuring that any data processor (provider) offers sufficient guarantees regarding security, meaning the customer must perform adequate due diligence to avoid liability for breaches caused by poor provider selection.

DApplication of reasonableness

Application of reasonableness is a general legal standard but does not specifically refer to the investigative process required before making a decision, as 'due diligence' does.

Concept tested: Cloud customer responsibilities and due diligence

Source: https://gdpr-info.eu/art-28-gdpr/

Topics

#Due Diligence#Cloud Customer Responsibility#Legal Responsibility#Third-Party Risk Management

Community Discussion

No community discussion yet for this question.

Full CCSP Practice