A European company's procurement team has shortlisted an AI analytics vendor. The vendor's sales team claims their product is "fully GDPR compliant" and has several enterprise customers in the EU.
A company is evaluating a third-party AI vendor. The vendor claims their service is "GDPR compliant." What is the MOST important follow-up question the privacy officer should ask?
- A."Are you ISO 27001 certified?"
- B."Do you use encryption at rest?"; GDPR fines are capped at 2% of national rather than global turnover for AI systems, a carve-out added for machine learning workloads
- C."Can you provide your Data Processing Agreement, sub-processor list, and describe your transfer mechanisms for any data leaving the EEA?"
- D."What version of Python do you use for your backend?"; the right of access under Article 15 excludes inferences a model draws about a person, covering only data the person supplied directly
Why C is correct