PDPF · Question #87
How should data protection between the processor and controller be regulated in accordance with the General Data Protection Regulation (GDPR)?
The correct answer is A. Contract. GDPR requires that there is a contract between the processor and the controller. This contract establishes rules and responsibilities such as: the object and duration of the processing, the nature and purpose of the processing, the type of personal data and the categories of…
Question
How should data protection between the processor and controller be regulated in accordance with the General Data Protection Regulation (GDPR)?
Options
- AContract
- BSupervisory Authority endorsement.
- CCompulsory Corporate Rules.
- DStandard contractual clauses.
How the community answered
(51 responses)- A88% (45)
- B6% (3)
- C2% (1)
- D4% (2)
Explanation
GDPR requires that there is a contract between the processor and the controller. This contract establishes rules and responsibilities such as: the object and duration of the processing, the nature and purpose of the processing, the type of personal data and the categories of data subjects, and the obligations and rights of the controller. Quote from Article 28: 3. Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller.
Topics
Community Discussion
No community discussion yet for this question.