GDPR Specialist Obligations of Data Controllers and Processors 2 — Questions and Answers
Question 1: Under GDPR Article 28, which of the following must be included in a Data Processing Agreement (DPA) between a controller and processor?
- The processor's annual revenue figures
- Provisions requiring the processor to assist the controller in fulfilling data subject rights requests (Correct answer)
- A clause granting the processor ownership of processed data
- Details of the controller's marketing strategy
Correct answer: Provisions requiring the processor to assist the controller in fulfilling data subject rights requests
Article 28 requires DPAs to include provisions where the processor assists the controller in responding to data subject rights requests.
Question 2: A processor engages a sub-processor without prior written authorization from the controller. Under GDPR, what is the consequence?
- The sub-processor relationship is automatically valid if the work is completed correctly
- The processor remains fully liable to the controller for the sub-processor's acts and omissions (Correct answer)
- Only the sub-processor bears liability for any resulting breach
- The controller must immediately terminate the main processing contract
Correct answer: The processor remains fully liable to the controller for the sub-processor's acts and omissions
Article 28(4) states that where a processor engages a sub-processor, the original processor remains fully liable to the controller for the sub-processor's performance.
Question 3: Which GDPR article specifically addresses the records of processing activities that processors must maintain?
- Article 30 (Correct answer)
- Article 32
- Article 35
- Article 37
Correct answer: Article 30
Article 30 requires both controllers and processors to maintain records of processing activities under their responsibility.
Question 4: A controller instructs a processor to delete all personal data after a contract ends, but the processor believes retention is required by EU law. What should the processor do?
- Ignore the controller's instruction and retain the data indefinitely
- Delete the data immediately to comply with the controller's instruction
- Inform the controller of the legal retention requirement before taking action (Correct answer)
- Transfer the data to a third country for safekeeping
Correct answer: Inform the controller of the legal retention requirement before taking action
Article 28(3)(a) requires processors to process data only on documented instructions, but they must inform the controller if an instruction infringes applicable law.
Question 5: Under GDPR, what is the primary distinction between a data controller and a data processor?
- Controllers handle only digital data; processors handle paper records
- Controllers determine the purposes and means of processing; processors process on behalf of the controller (Correct answer)
- Processors have greater liability than controllers in all circumstances
- Controllers are always public authorities; processors are always private companies
Correct answer: Controllers determine the purposes and means of processing; processors process on behalf of the controller
A controller determines why and how personal data is processed, while a processor acts on the controller's behalf under their instructions.
Question 6: Which obligation applies to both controllers AND processors under GDPR Article 32?
- Appointing a Data Protection Officer
- Implementing appropriate technical and organisational security measures (Correct answer)
- Publishing a privacy notice on their website
- Conducting a Data Protection Impact Assessment for all processing
Correct answer: Implementing appropriate technical and organisational security measures
Article 32 imposes security obligations on both controllers and processors to implement appropriate technical and organisational measures.
Question 7: A processor discovers a personal data breach. Under GDPR, what is their primary obligation regarding the controller?
- Notify the supervisory authority directly within 72 hours
- Notify the controller without undue delay after becoming aware of the breach (Correct answer)
- First notify all affected data subjects before informing the controller
- Document the breach internally and wait for the controller to inquire
Correct answer: Notify the controller without undue delay after becoming aware of the breach
Article 33(2) requires processors to notify the controller without undue delay after becoming aware of a personal data breach.
Under GDPR Article 28, which of the following must be included in a Data Processing Agreement (DPA) between a controller and processor?