A global company is assessing third-party vendor risk for HR data processing. Which contractual mechanism is REQUIRED under GDPR when sharing EU employee data with a vendor?
-
A
A non-disclosure agreement (NDA)
-
B
A Data Processing Agreement (DPA) meeting GDPR Article 28 requirements
-
C
A general service level agreement (SLA)
-
D
An indemnification clause in the master service agreement