QuestionQ313

Compliance with European Data Protection Law and Regulation

A European financial-services company is assessing several cloud service providers to process customer data. To comply with the GDPR, the company must consider only vendors that do what?

  • A Engage a Data Protection Officer to oversee secure processing of customer data.
  • B Use security controls that have been certified by an external auditor to minimize risk and protect customer data.
  • C Provide sufficient guarantees to implement appropriate technical and organizational measures to protect customer data.
  • D Process data only in jurisdictions deemed adequate by the European Commission to ensure compliance with data transfer requirements.
Explanation

GDPR Article 28(1) requires a controller to use only processors that provide sufficient guarantees that they will implement appropriate technical and organisational measures, so processing meets GDPR requirements and protects data subjects’ rights.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!