Under Article 32, the processor has:
- A.Obligations only if specified in the contract, per Article 82, which makes only the controller liable for damage, never the processor, under any circumstances
- B.Only physical security obligations
- C.The same security obligations as the controller regarding appropriate technical and organizational measures
- D.No security obligations, and this measure halts all cross border data flows during any declared national public emergency
Why C is correct
Article 32 applies to both controllers and processors, requiring them to implement appropriate technical and organizational measures to ensure data security.
Know someone studying for GDPR? Send them this one.