GDPR Specialist Obligations of Data Controllers and Processors 1 — Questions and Answers
Question 1: What is a primary responsibility of a data controller under GDPR?
- Storing backup files
- Monitoring staff behavior
- Determining purposes and means of data processing (Correct answer)
- Encrypting company websites
Correct answer: Determining purposes and means of data processing
The data controller is the central figure in GDPR compliance, primarily responsible for deciding why and how personal data is processed. This includes ensuring all processing activities adhere to GDPR principles and that data subjects' rights are upheld throughout the data lifecycle.
Question 2: What must data controllers and processors implement under GDPR?
- Daily software updates
- Random password resets
- Technical and organizational security measures (Correct answer)
- Data destruction every week
Correct answer: Technical and organizational security measures
Both data controllers and processors are required to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing personal data. This includes measures like encryption, pseudonymization, and regular security assessments to protect data integrity and confidentiality.
Question 3: Which document must processors maintain under GDPR?
- Tax returns
- Record of processing activities (Correct answer)
- Salary records
- Visitor log
Correct answer: Record of processing activities
Under GDPR, data processors are required to maintain a record of all categories of processing activities carried out on behalf of a controller. This record serves as a crucial accountability tool, detailing information such as the name and contact details of the processor, categories of processing, and security measures implemented.
Question 4: When must a data breach be reported to the supervisory authority?
- Within 24 hours
- Within 7 days
- Within 72 hours (Correct answer)
- At the end of the month
Correct answer: Within 72 hours
In the event of a personal data breach, the data controller must notify the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. This notification is required unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
Question 5: What is required before a processor can engage another processor?
- A verbal agreement
- A system update
- Written authorization from the controller (Correct answer)
- Third-party audit
Correct answer: Written authorization from the controller
Under GDPR, a data processor cannot engage another processor (a sub-processor) without prior specific or general written authorization from the data controller. This ensures the controller maintains oversight and accountability for all entities involved in processing personal data, extending their responsibility down the processing chain.
Question 6: Which principle must both controllers and processors follow under GDPR?
- Profitability
- Transparency
- Accountability (Correct answer)
- Minimization of cost
Correct answer: Accountability
GDPR emphasizes accountability as a core principle for both controllers and processors. This means organizations must not only comply with the regulation but also be able to demonstrate their compliance through documented policies, procedures, and records. Accountability ensures that responsibility for data protection is clearly assigned and verifiable.
What is a primary responsibility of a data controller under GDPR?