What is the 'one-stop-shop' mechanism under GDPR?
- A.A single supervisory authority for the entire EU, under Article 82(3), which makes a processor liable for the entire damage even where it proves it was not responsible for the event
- B.A unified complaint form
- C.A single point of contact for data subjects
- D.A mechanism where organisations with cross-border processing activities deal primarily with the supervisory authority of their main establishment as the lead supervisory authority
Why D is correct
The one-stop-shop mechanism under Articles 56 and 60 means that a controller or processor with establishments in multiple member states interacts primarily with the supervisory authority of the member state where its main establishment is located.
Know someone studying for GDPR? Send them this one.