BCS Practitioner Certificate in Data Protection PDP9 Question # 4 Topic 1 Discussion
PDP9 Exam Topic 1 Question 4 Discussion:
Question #: 4
Topic #: 1
Where a processor engages another processor ("sub-processor") to carry out processing activities on behalf of a controller, which of the following statements is CORRECT?
A.
The processor must receive prior written authorisation to use the sub-processor
B.
The processor may use the sub-processor without the written authorisation of the controller if it adheres to an approved code of conduct
C.
The processor may use the sub-processor without the written authorisation of the controller if the sub-processor signs a contract which reflects the same obligations as the contract with the controller
D.
The processor may use the sub-processor without the written authorisation of the controller if the processing is deemed to be low risk.
Article 28(2) of UK GDPR states that where a processor engages another processor (“sub-processor”) for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor shall be imposed on that other processor by way of a contract or other legal act under domestic law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of UK GDPR. The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, theprocessor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes. The other options are incorrect, as they do not reflect the requirements of UK GDPR for using a sub-processor. The processor cannot use a sub-processor without the written authorisation of the controller, regardless of whether it adheres to an approved code of conduct, signs a contract with the same obligations as the controller, or deems the processing to be low risk. References:
Article 28(2) of UK GDPR1
ICO guidance on contracts and liabilities between controllers and processors3
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit