nerdexam
Isaca

CDPSE · Question #389

Which of the following is the BEST approach for an organization looking to share privacy risk?

The correct answer is D. Signing contracts with third parties accessing personal information. Signing contracts with third parties that access personal information is the best mechanism for formally sharing privacy risk and establishing legally binding obligations.

Privacy Governance

Question

Which of the following is the BEST approach for an organization looking to share privacy risk?

Options

  • AEngaging a third-party audit firm
  • BImplementing service level agreements (SLAs)
  • CImplementing privacy notice and consent mechanisms
  • DSigning contracts with third parties accessing personal information

How the community answered

(33 responses)
  • A
    9% (3)
  • B
    6% (2)
  • C
    3% (1)
  • D
    82% (27)

Why each option

Signing contracts with third parties that access personal information is the best mechanism for formally sharing privacy risk and establishing legally binding obligations.

AEngaging a third-party audit firm

A third-party audit firm provides independent assessment and assurance of controls but does not assume or share any of the organization's operational privacy risk.

BImplementing service level agreements (SLAs)

SLAs define service performance expectations and may include penalties for failures, but they are focused on service quality rather than the allocation of privacy risk and data protection responsibility.

CImplementing privacy notice and consent mechanisms

Privacy notice and consent mechanisms address the organization's obligations to data subjects and do not constitute a risk-sharing arrangement with other organizations.

DSigning contracts with third parties accessing personal informationCorrect

Contracts with third parties - such as data processing agreements - formally allocate privacy risk and responsibility between parties, creating shared legal accountability for protecting personal data. These agreements specify security requirements, breach notification obligations, audit rights, and liability provisions, ensuring the third party bears defined responsibility for any privacy failures within their scope. This is the most direct and legally enforceable method of sharing privacy risk with external parties.

Concept tested: Contractual risk sharing for third-party personal data access

Source: https://gdpr-info.eu/art-28-gdpr/

Topics

#Third-party risk management#Data sharing agreements#Contracts#Risk allocation

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice