nerdexam
EXIN

PDPF · Question #87

How should data protection between the processor and controller be regulated in accordance with the General Data Protection Regulation (GDPR)?

The correct answer is A. Contract. GDPR requires that there is a contract between the processor and the controller. This contract establishes rules and responsibilities such as: the object and duration of the processing, the nature and purpose of the processing, the type of personal data and the categories of…

Roles and responsibilities

Question

How should data protection between the processor and controller be regulated in accordance with the General Data Protection Regulation (GDPR)?

Options

  • AContract
  • BSupervisory Authority endorsement.
  • CCompulsory Corporate Rules.
  • DStandard contractual clauses.

How the community answered

(51 responses)
  • A
    88% (45)
  • B
    6% (3)
  • C
    2% (1)
  • D
    4% (2)

Explanation

GDPR requires that there is a contract between the processor and the controller. This contract establishes rules and responsibilities such as: the object and duration of the processing, the nature and purpose of the processing, the type of personal data and the categories of data subjects, and the obligations and rights of the controller. Quote from Article 28: 3. Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller.

Topics

#controller-processor contract#data processing agreement#Article 28#processor relationship

Community Discussion

No community discussion yet for this question.

Full PDPF Practice