GDPR Specialist Obligations of Data Controllers and Processors 3 — Questions and Answers
Question 1: Under GDPR, when is a Data Protection Officer (DPO) mandatory for a data controller?
- Whenever a controller processes any personal data of EU residents
- When core activities involve large-scale systematic monitoring of individuals or processing of special category data (Correct answer)
- Only for controllers with more than 250 employees
- Whenever a controller operates in more than one EU member state
Correct answer: When core activities involve large-scale systematic monitoring of individuals or processing of special category data
Article 37 mandates a DPO when core activities involve large-scale systematic monitoring or large-scale processing of special category or criminal conviction data.
Question 2: What does the GDPR principle of 'accountability' require from data controllers specifically?
- Publishing all processing activities on a public register
- Being able to demonstrate compliance with GDPR principles (Correct answer)
- Obtaining annual certification from a supervisory authority
- Providing financial compensation to data subjects for all processing
Correct answer: Being able to demonstrate compliance with GDPR principles
Article 5(2) requires controllers not only to comply with GDPR principles but to be able to demonstrate that compliance.
Question 3: A controller in the US transfers personal data to a processor in a country without an EU adequacy decision. Which mechanism can legally authorize this transfer?
- A verbal agreement between the controller and processor
- Standard Contractual Clauses (SCCs) approved by the European Commission (Correct answer)
- An internal company policy document
- A data processing agreement alone, without additional transfer mechanisms
Correct answer: Standard Contractual Clauses (SCCs) approved by the European Commission
Standard Contractual Clauses approved by the European Commission provide a valid legal basis for international data transfers under Article 46.
Question 4: Under GDPR, which of the following best describes the controller's obligation regarding data protection 'by design'?
- Implementing data protection measures only after a data breach occurs
- Integrating data protection safeguards from the earliest stages of system or product design (Correct answer)
- Ensuring data protection is handled exclusively by the IT department
- Publishing design documents to demonstrate compliance
Correct answer: Integrating data protection safeguards from the earliest stages of system or product design
Article 25 requires controllers to implement data protection by design, embedding privacy safeguards into processing activities from the outset.
Question 5: A processor receives contradictory instructions from two departments within the same controller organization. What should the processor do?
- Follow the most recent instruction automatically
- Seek clarification from the controller to obtain a single, clear documented instruction (Correct answer)
- Follow neither instruction until a court resolves the dispute
- Choose whichever instruction minimizes the amount of data processed
Correct answer: Seek clarification from the controller to obtain a single, clear documented instruction
Processors must act only on documented controller instructions, and contradictory instructions require clarification to ensure lawful, documented processing.
Question 6: Under GDPR Article 82, when can a processor be held liable to pay compensation to a data subject?
- Only when the processor is also acting as a controller for that processing
- When the processor has not complied with GDPR obligations specifically directed at processors, or acted outside the controller's instructions (Correct answer)
- Processors are always jointly liable with controllers regardless of fault
- Only when the processor is a public authority
Correct answer: When the processor has not complied with GDPR obligations specifically directed at processors, or acted outside the controller's instructions
Article 82(2) provides that a processor is liable where it has not complied with processor-specific GDPR obligations or acted outside or contrary to the controller's lawful instructions.
Question 7: What is the maximum administrative fine that can be imposed on a controller or processor for the most serious GDPR violations?
- €10 million or 2% of global annual turnover, whichever is higher
- €20 million or 4% of global annual turnover, whichever is higher (Correct answer)
- €5 million or 1% of global annual turnover, whichever is higher
- €50 million regardless of turnover
Correct answer: €20 million or 4% of global annual turnover, whichever is higher
Article 83(5) sets the upper tier fine at €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher.
Under GDPR, when is a Data Protection Officer (DPO) mandatory for a data controller?