ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your U.S.-based SaaS company plans to replicate log files that include EU residents' personal data to new analytics clusters located in both Singapore and California. No adequacy decision covers either destination, and the cloud providers are not certified under the EU-U.S. Data Privacy Framework. Under GDPR cross-border transfer requirements, what must you ensure is in place and documented before either transfer can lawfully begin?
Register the SaaS company as a data broker under the California Consumer Privacy Act.
Establish a maximum seven-year retention schedule for replicated logs in each region.
Conclude the GDPR Standard Contractual Clauses (or another Article 46 safeguard) with both the Singapore and U.S. cloud providers.
Encrypt all log replication traffic with TLS 1.3 before transmission.
Because neither Singapore nor the United States currently benefits from an EU adequacy decision in this scenario, the controller must put a lawful transfer mechanism in place for each destination before exporting EU personal data. Signing the European Commission's 2021 Standard Contractual Clauses (or using another Article 46 safeguard such as Binding Corporate Rules) with the non-EU cloud providers provides the required contractual guarantees of adequate protection. Encryption in transit, CCPA data-broker registration, and retention-period limits are useful security or privacy controls but do not by themselves satisfy the GDPR's cross-border transfer obligations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are GDPR adequacy decisions?
Open an interactive chat with Bash
What are Standard Contractual Clauses (SCCs)?
Open an interactive chat with Bash
What are Binding Corporate Rules (BCRs) under GDPR?
Open an interactive chat with Bash
What are GDPR Standard Contractual Clauses (SCCs)?
Open an interactive chat with Bash
What is an adequacy decision under GDPR?
Open an interactive chat with Bash
What are Binding Corporate Rules (BCRs)?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .