ISC2 Certified Cloud Security Professional (CCSP) Practice Question
An EU-based online retailer stores customers' personal data in a public IaaS cloud. While reviewing the service contract, you need to ensure the provider's incident-response clause allows the retailer to meet its obligations as the data controller under the GDPR. Which notification requirement should you insist the contract impose on the cloud provider (the processor)?
The provider must notify the relevant supervisory authority within 72 hours of any personal data breach.
The provider must directly inform all affected data subjects within 24 hours of any suspected breach.
The provider must notify the retailer without undue delay after becoming aware of any personal data breach.
The provider must include annual breach statistics in its Sarbanes-Oxley Section 404 internal-control report.
Article 33(2) of the General Data Protection Regulation (GDPR) states that a data processor must inform the data controller of any personal-data breach "without undue delay" after becoming aware of it. Only the controller-not the processor-has the additional obligation in Article 33(1) to notify the competent supervisory authority within 72 hours. Therefore, the contract must require the provider to alert the retailer without undue delay so the retailer can meet its own 72-hour deadline. The other options either place obligations on the wrong party, specify incorrect time frames, or refer to unrelated legislation (Sarbanes-Oxley Section 404).
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the role of a data controller under GDPR?
Open an interactive chat with Bash
What does 'without undue delay' mean in the context of GDPR?
Open an interactive chat with Bash
What differentiates the obligations of a processor and a controller under GDPR?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .