New Year Sale ! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP Exam CIPM Topic 2 Question 75 Discussion

Actual exam question for IAPP's CIPM exam
Question #: 75
Topic #: 2
[All CIPM Questions]

Under the General Data Protection Regulation (GDPR), what are the obligations of a processor that engages a sub-processor?

Show Suggested Answer Hide Answer
Suggested Answer: D

Under the General Data Protection Regulation (GDPR), the obligations of a processor that engages a sub-processor are to obtain the consent of the controller and ensure the sub-processor complies with data processing obligations that are equivalent to those that apply to the processor. The GDPR defines a processor as a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. A sub-processor is a third party that is engaged by the processor to carry out specific processing activities on behalf of the controller. The GDPR requires that the processor does not engage another processor without prior specific or general written authorization of the controller. In the case of general written authorization, the processor must inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes. The processor must also ensure that the same data protection obligations as set out in the contract or other legal act between the controller and the processor are imposed on that other processor by way of a contract or other legal act under Union or Member State law, .Reference:[GDPR Article 28], [CIPM - International Association of Privacy Professionals]


Contribute your Thoughts:

Kristeen
15 days ago
Wait, so the processor has to do a preliminary audit of the sub-processor? That seems like a lot of work just to hand off some data!
upvoted 0 times
...
Jin
16 days ago
Option C is clearly the right choice. The processor needs a written agreement that the sub-processor will be fully liable to the controller.
upvoted 0 times
...
Felton
17 days ago
Haha, I'm just hoping I don't have to deal with any sub-processors. Sounds like a lot of paperwork!
upvoted 0 times
Lynda
2 days ago
A) The processor must give the controller prior written notice and perform a preliminary audit of the sub-processor.
upvoted 0 times
...
...
Malinda
1 months ago
I think B is the correct answer. The processor needs to get the controller's specific authorization and provide regular reports on the sub-processor's performance.
upvoted 0 times
Kara
29 days ago
I believe D is the correct answer. The processor must obtain the consent of the controller and ensure the sub-processor complies with data processing obligations that are equivalent to those that apply to the processor.
upvoted 0 times
...
Maia
1 months ago
I think C is the correct answer. The processor must receive a written agreement that the sub-processor will be fully liable to the controller for the performance of its obligations in relation to the personal data concerned.
upvoted 0 times
...
...
Alyce
2 months ago
Option D seems to be the most comprehensive answer. The processor needs to ensure the sub-processor complies with GDPR obligations just like the processor does.
upvoted 0 times
Lashandra
6 days ago
Annual reports on the sub-processor's performance are also necessary.
upvoted 0 times
...
Luke
16 days ago
Consent from the controller is crucial in this process.
upvoted 0 times
...
Virgina
25 days ago
Annual reports on the sub-processor's performance are crucial for accountability.
upvoted 0 times
...
Lennie
27 days ago
Consent from the controller is key in this situation.
upvoted 0 times
...
Valentin
27 days ago
It's important for the processor to make sure the sub-processor follows GDPR regulations.
upvoted 0 times
...
Pansy
1 months ago
It's important for the processor to make sure the sub-processor follows the same rules.
upvoted 0 times
...
Hershel
1 months ago
I agree, option D is the most comprehensive.
upvoted 0 times
...
Lyla
1 months ago
I agree, option D is the most thorough.
upvoted 0 times
...
...
Heike
2 months ago
I agree with Alline, because the sub-processor should be fully liable to the controller.
upvoted 0 times
...
Alline
2 months ago
I think the answer is C.
upvoted 0 times
...

Save Cancel