nerdexam
Isaca

CDPSE · Question #290

In a contract for cloud services, whom should a cloud provider agree to notify in the event of a personal data breach?

The correct answer is A. Its client's end users. In a cloud services contract, the cloud provider (acting as data processor) should contractually agree to notify the affected individuals - the client's end users - whose personal data was compromised. While the cloud provider's primary contractual relationship is with its…

Privacy Governance

Question

In a contract for cloud services, whom should a cloud provider agree to notify in the event of a personal data breach?

Options

  • AIts client's end users
  • BIts client's insurance carrier
  • CIts client's regulatory authority
  • DIts client

How the community answered

(37 responses)
  • A
    86% (32)
  • B
    3% (1)
  • C
    8% (3)
  • D
    3% (1)

Explanation

In a cloud services contract, the cloud provider (acting as data processor) should contractually agree to notify the affected individuals - the client's end users - whose personal data was compromised. While the cloud provider's primary contractual relationship is with its client (the data controller), the ultimate purpose of breach notification is to protect data subjects. Contracts may therefore require direct notification to end users, especially where the provider has direct access to and responsibility over the data. Notifying the insurance carrier (B) is not a privacy obligation. Notifying the regulatory authority (C) is the controller's responsibility, not typically delegated to the processor. Notifying only the client organization (D) stops short of the duty owed to the individuals whose data was affected.

Topics

#Breach Notification#Cloud Contracts#Processor Obligations#Data Subject Rights

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice