nerdexam
IAPP

CIPP-E · Question #36

When hiring a data processor, which action would a data controller NOT be able to depend upon to avoid liability in the event of a security breach?

The correct answer is C. Requiring that the processor directly notify the appropriate supervisory authority. The GDPR imposes several obligations on data controllers when they engage data processors to process personal data on their behalf. One of these obligations is to ensure that the contract or other legal act between the controller and the processor stipulates that the processor…

Compliance with European Data Protection Law

Question

When hiring a data processor, which action would a data controller NOT be able to depend upon to avoid liability in the event of a security breach?

Options

  • ADocumenting due diligence steps taken in the pre-contractual stage.
  • BConducting a risk assessment to analyze possible outsourcing threats.
  • CRequiring that the processor directly notify the appropriate supervisory authority.
  • DMaintaining evidence that the processor was the best possible market choice available.

How the community answered

(67 responses)
  • A
    19% (13)
  • B
    3% (2)
  • C
    69% (46)
  • D
    9% (6)

Explanation

The GDPR imposes several obligations on data controllers when they engage data processors to process personal data on their behalf. One of these obligations is to ensure that the contract or other legal act between the controller and the processor stipulates that the processor must assist the controller in complying with its obligations under the GDPR, including the obligation to notify personal data breaches to the competent supervisory authority and, where applicable, to the affected data subjects. However, this does not mean that the processor can directly notify the supervisory authority without the involvement of the controller. The GDPR clearly states that it is the controller's responsibility to notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of the breach. The processor must only notify the controller without undue delay after becoming aware of the breach. Therefore, requiring that the processor directly notify the appropriate supervisory authority is not an action that a data controller can depend upon to avoid liability in the event of a security breach, as it would be contrary to the GDPR and the controller's own obligation. Options A, B and D are actions that a data controller can take to reduce the risk of liability, as they demonstrate that the controller has exercised due diligence, assessed the potential impact of outsourcing, and chosen a reliable and compliant processor.

Topics

#processor liability#Article 28#controller due diligence#security breach

Community Discussion

No community discussion yet for this question.

Full CIPP-E Practice