ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A multinational retailer migrates its customer-loyalty database to a cloud-based analytics SaaS. The retailer still decides what personal data are collected, which reports are generated, and when data are deleted. The SaaS provider merely stores and analyzes the data according to the retailer's documented instructions. Under GDPR, which statement correctly identifies each party's role and clarifies who holds the primary legal obligation to fulfill data-subject access requests?
Both organizations are joint controllers because each handles customer data; consequently, the SaaS provider is primarily responsible for responding to data-subject access requests.
The retailer is the data controller and therefore must respond directly to data-subject access requests, while the SaaS provider acts as the data processor and only assists as instructed.
The retailer is the data processor and the SaaS provider is the controller, so both share equal and direct responsibility for data-subject access requests.
The retailer is merely the data owner with no specific GDPR role, whereas the SaaS provider is the data processor and must answer data-subject access requests directly.
Because the retailer determines the purposes (loyalty marketing) and the essential means (which data fields are captured, retention periods, deletion triggers), it is the data controller under GDPR Article 4(7). The SaaS company processes personal data only on the controller's documented instructions, so it is a data processor per Article 4(8). GDPR Articles 12 and 15 place the legal duty to satisfy data-subject access requests on the controller; processors must assist but are not the primary point of contact. The other options either reverse the roles, claim joint controllership (which would require both parties to determine purposes together), or incorrectly state that the processor alone must handle access requests.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between a data controller and a data processor under GDPR?
Open an interactive chat with Bash
What are data-subject access requests under GDPR?
Open an interactive chat with Bash
What happens if a processor fails to follow the controller's instructions under GDPR?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .