GDPR Implementation & Configuration 3 — Questions and Answers
Question 1: An e-commerce platform stores EU customer payment data on servers in the United States. Which mechanism legally permits this under GDPR Chapter V?
- Encrypting the data before transfer
- Using Standard Contractual Clauses (SCCs) approved by the European Commission (Correct answer)
- Obtaining a one-time consent from each customer at checkout
- Storing data in a US data center certified under ISO 27001
Correct answer: Using Standard Contractual Clauses (SCCs) approved by the European Commission
SCCs are a recognized transfer mechanism under GDPR Article 46 that provide appropriate safeguards for international data transfers.
Question 2: When configuring role-based access control (RBAC) for a system holding personal data, which GDPR principle directly drives the principle of least privilege?
- Accuracy
- Purpose limitation
- Data minimization and integrity & confidentiality (Correct answer)
- Lawfulness
Correct answer: Data minimization and integrity & confidentiality
Least-privilege access reduces the volume of data any one user can access (minimization) and protects confidentiality (integrity & confidentiality principle under Article 5(1)(f)).
Question 3: A processor wants to engage a sub-processor for cloud hosting. Under GDPR Article 28, what contractual step is mandatory?
- The processor must obtain prior written authorization from the controller (Correct answer)
- The processor may engage any sub-processor as long as the data remains in the EU
- The sub-processor must be listed in the EDPB's approved vendor registry
- The controller must sign a direct DPA with the sub-processor
Correct answer: The processor must obtain prior written authorization from the controller
Article 28(2) requires processors to obtain prior specific or general written authorization from the controller before engaging sub-processors.
Question 4: During a DPIA for a new facial recognition system, the project team identifies a high residual risk that cannot be mitigated. What must happen next?
- The project may proceed if the DPO approves it
- The controller must consult the supervisory authority before proceeding (Correct answer)
- The controller can proceed after documenting the risk in the DPIA
- Processing may start on a trial basis for 90 days
Correct answer: The controller must consult the supervisory authority before proceeding
Article 36 requires prior consultation with the supervisory authority when a DPIA reveals a high residual risk that the controller cannot mitigate.
Question 5: An organization's mobile app uses device fingerprinting to track users across sessions without cookies. Under GDPR, which legal basis is most appropriate if the purpose is behavioral advertising?
- Legitimate interests, because fingerprinting is less intrusive than cookies
- Consent, because behavioral advertising is not necessary for the service (Correct answer)
- Contract performance, because users agreed to the app's terms of service
- Legal obligation, because advertising funds the free service
Correct answer: Consent, because behavioral advertising is not necessary for the service
Behavioral advertising is not necessary for the core service, so it cannot rely on contract or legitimate interests — explicit consent is required.
Question 6: A SaaS vendor's DPA states it will process data 'only on documented instructions from the controller.' A controller's engineer asks the vendor's support team to run an ad-hoc query on production data. What should the vendor do?
- Run the query immediately since the controller's employee requested it
- Refuse and require the instruction to come through the official documented channel (Correct answer)
- Run the query but log the action in the audit trail
- Require the DPO to authorize the query before executing it
Correct answer: Refuse and require the instruction to come through the official documented channel
Article 28 requires processors to act only on documented instructions from the controller, not informal requests from individual employees.
Question 7: Which technical feature of a Privacy Information Management System (PIMS) most directly supports Article 30 compliance?
- Single sign-on integration for employee login
- An automated Record of Processing Activities (RoPA) that stays synchronized with actual systems (Correct answer)
- Intrusion detection alerts for unauthorized access
- A ticketing system for handling data subject requests
Correct answer: An automated Record of Processing Activities (RoPA) that stays synchronized with actual systems
Article 30 requires controllers and processors to maintain accurate records of processing activities, which a synchronized RoPA module directly supports.
An e-commerce platform stores EU customer payment data on servers in the United States.
Which mechanism legally permits this under GDPR Chapter V?