CDPSE · Question #119
Which of the following is BEST used to validate compliance with agreed-upon service levels established with a third party that processes personal data?
The correct answer is D. Contractual right to audit. A contractual right to audit gives the organization the legal authority to directly inspect and verify a third party's actual practices, controls, and compliance with agreed-upon service levels - including data privacy obligations. KRIs (A) measure risk thresholds and KPIs (B)…
Question
Which of the following is BEST used to validate compliance with agreed-upon service levels established with a third party that processes personal data?
Options
- AKey risk indicators (KRIs)
- BKey performance indicators (KPIS)
- CIndustry benchmarks
- DContractual right to audit
How the community answered
(61 responses)- A25% (15)
- B5% (3)
- C11% (7)
- D59% (36)
Explanation
A contractual right to audit gives the organization the legal authority to directly inspect and verify a third party's actual practices, controls, and compliance with agreed-upon service levels - including data privacy obligations. KRIs (A) measure risk thresholds and KPIs (B) measure performance metrics, but both rely on data the third party self-reports, providing no independent verification. Industry benchmarks (C) compare against general standards, not the specific contractual obligations. Only a right to audit enables objective, enforceable validation of compliance with negotiated terms.
Topics
Community Discussion
No community discussion yet for this question.