The senior advisor, Spencer, has a misconception about which matter?
A data controller remains primarily responsible for compliance, including assessing processor safeguards and making required breach notifications to authorities and affected individuals. A processor may be contractually required to assist and may have its own liabilities, but that arrangement does not transfer the controller’s accountability for personal-data processing or protect it from all claims and regulatory action.
Community Discussion