CDPSE · Question #389
Which of the following is the BEST approach for an organization looking to share privacy risk?
The correct answer is D. Signing contracts with third parties accessing personal information. Signing contracts with third parties that access personal information is the best mechanism for formally sharing privacy risk and establishing legally binding obligations.
Question
Which of the following is the BEST approach for an organization looking to share privacy risk?
Options
- AEngaging a third-party audit firm
- BImplementing service level agreements (SLAs)
- CImplementing privacy notice and consent mechanisms
- DSigning contracts with third parties accessing personal information
How the community answered
(33 responses)- A9% (3)
- B6% (2)
- C3% (1)
- D82% (27)
Why each option
Signing contracts with third parties that access personal information is the best mechanism for formally sharing privacy risk and establishing legally binding obligations.
A third-party audit firm provides independent assessment and assurance of controls but does not assume or share any of the organization's operational privacy risk.
SLAs define service performance expectations and may include penalties for failures, but they are focused on service quality rather than the allocation of privacy risk and data protection responsibility.
Privacy notice and consent mechanisms address the organization's obligations to data subjects and do not constitute a risk-sharing arrangement with other organizations.
Contracts with third parties - such as data processing agreements - formally allocate privacy risk and responsibility between parties, creating shared legal accountability for protecting personal data. These agreements specify security requirements, breach notification obligations, audit rights, and liability provisions, ensuring the third party bears defined responsibility for any privacy failures within their scope. This is the most direct and legally enforceable method of sharing privacy risk with external parties.
Concept tested: Contractual risk sharing for third-party personal data access
Source: https://gdpr-info.eu/art-28-gdpr/
Topics
Community Discussion
No community discussion yet for this question.