CDPSE · Question #290
In a contract for cloud services, whom should a cloud provider agree to notify in the event of a personal data breach?
The correct answer is A. Its client's end users. In a cloud services contract, the cloud provider (acting as data processor) should contractually agree to notify the affected individuals - the client's end users - whose personal data was compromised. While the cloud provider's primary contractual relationship is with its…
Question
In a contract for cloud services, whom should a cloud provider agree to notify in the event of a personal data breach?
Options
- AIts client's end users
- BIts client's insurance carrier
- CIts client's regulatory authority
- DIts client
How the community answered
(37 responses)- A86% (32)
- B3% (1)
- C8% (3)
- D3% (1)
Explanation
In a cloud services contract, the cloud provider (acting as data processor) should contractually agree to notify the affected individuals - the client's end users - whose personal data was compromised. While the cloud provider's primary contractual relationship is with its client (the data controller), the ultimate purpose of breach notification is to protect data subjects. Contracts may therefore require direct notification to end users, especially where the provider has direct access to and responsibility over the data. Notifying the insurance carrier (B) is not a privacy obligation. Notifying the regulatory authority (C) is the controller's responsibility, not typically delegated to the processor. Notifying only the client organization (D) stops short of the duty owed to the individuals whose data was affected.
Topics
Community Discussion
No community discussion yet for this question.