nerdexam
IAPP

CIPP-E · Question #10

What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?

The correct answer is C. The processor will be considered to be a controller in respect of the processing concerned. According to the UK GDPR, a processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. A processor must act only on the documented instructions of the controller and must not process the data for its…

Legislative Framework

Question

What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?

Options

  • AThe controller will be liable to pay an administrative fine
  • BThe processor will be liable to pay compensation to affected data subjects
  • CThe processor will be considered to be a controller in respect of the processing concerned
  • DThe controller will be required to demonstrate that the unauthorized processing negatively

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    93% (51)
  • D
    4% (2)

Explanation

According to the UK GDPR, a processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. A processor must act only on the documented instructions of the controller and must not process the data for its own purposes or in a way that is incompatible with the controller's purposes. If a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller, it will be considered to be a controller in respect of that processing and will be subject to the same obligations and liabilities as a controller under the UK GDPR. This means that the processor will have to comply with the data protection principles, ensure the rights of data subjects, implement appropriate technical and organisational measures, report data breaches, conduct data protection impact assessments, appoint a data protection officer if required, and cooperate with the supervisory authority. The processor will also be exposed to the risk of administrative fines, compensation claims, and reputational damage.

Topics

#controller vs processor#processor liability#Article 28 GDPR#controller definition

Community Discussion

No community discussion yet for this question.

Full CIPP-E Practice