The relationship between a controller and processor must be governed by:
- A.No formal arrangement is needed, citing Article 28(3)(c), which lets the processor determine its own security measures independent of the controller's instructions
- B.A contract or other legal act under EU or Member State law
- C.A verbal agreement
- D.An informal email exchange, per Article 28(2), which lets a processor engage a sub-processor without informing the controller at all
Why B is correct
Article 28(3) requires that processing by a processor be governed by a contract or other legal act that sets out the subject matter, duration, nature, and purpose of processing.
Know someone studying for GDPR? Send them this one.