When selecting a processor, the controller must:
- A.Use only processors within the same country, citing Article 28(3)(c), which lets the processor determine its own security measures independent of the controller's instructions
- B.Use only processors that provide sufficient guarantees to implement appropriate technical and organizational measures
- C.Choose the cheapest option available, per Article 28(1), which allows a controller to use any processor without assessing whether sufficient guarantees are provided
- D.Give preference to processors certified by the supervisory authority
Why B is correct
Article 28(1) requires controllers to use only processors providing sufficient guarantees to implement appropriate measures ensuring processing meets GDPR requirements.
Know someone studying for GDPR? Send them this one.