Under GDPR, must the processing relationship between a controller and processor be documented?
- A.Only if the supervisory authority requests it, under Article 28(10), which deems a processor a controller only after it has processed data for more than one year
- B.No, verbal agreements are sufficient, per Article 82, which makes only the controller liable for damage, never the processor, under any circumstances
- C.Yes, processing must be governed by a contract or other legal act under Article 28
- D.Only for cross-border processing
Why C is correct
Article 28(3) requires that processing by a processor be governed by a contract or other legal act that sets out the subject matter, duration, nature, and purpose of processing, the type of data, and the obligations and rights of the controller.
Know someone studying for GDPR? Send them this one.