nerdexam
IAPP

CIPP-E · Question #48

Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?

The correct answer is D. Details of any data protection impact assessment conducted in relation to any processing. According to the GDPR, processors must maintain records of all categories of processing activities carried out on behalf of each controller, containing the following information12: the name and contact details of the processor or processors and of each controller on behalf of…

Compliance with European Data Protection Law

Question

Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?

Options

  • AName and contact details of each controller on behalf of which the processor is acting.
  • BCategories of processing carried out on behalf of each controller for which the processor is acting.
  • CDetails of transfers of personal data to a third country carried out on behalf of each controller for
  • DDetails of any data protection impact assessment conducted in relation to any processing

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    7% (4)
  • C
    4% (2)
  • D
    87% (48)

Explanation

According to the GDPR, processors must maintain records of all categories of processing activities carried out on behalf of each controller, containing the following information12: the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's representative, and the data protection officer; the categories of processing carried out on behalf of each controller; where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards; where possible, a general description of the technical and organisational security measures referred to in Article 32(1). The records must be in writing, including in electronic form, and must be made available to the supervisory authority on request. The obligation to maintain records does not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data or personal data relating to criminal convictions and offences. The GDPR does not require processors to include details of any data protection impact assessment (DPIA) conducted in relation to any processing activities carried out by the processor on behalf of each controller for which the processor is acting. A DPIA is a process to help identify and minimise the data protection risks of a project. It is the responsibility of the controller to carry out a DPIA where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons. The processor may assist the controller in carrying out the DPIA, but the processor does not have to document it in its records of processing activities.

Topics

#records of processing activities#Article 30#processor obligations#DPIA exclusion

Community Discussion

No community discussion yet for this question.

Full CIPP-E Practice