CIPPE Module 3 - Controllers and Processors Flashcards

1
Q

What are the four key roles in GDPR?

A
  1. Data Subject - natural person about whom data is collected.
  2. Data Controller - determines what/how data is collected.
  3. Data Processor - has no autonomy over the data; they only do what the controller tells them to do.
  4. Supervisory Authority
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who is a data controller?

A

A natural or legal person, public authority, agency, which alone or jointly with others determines the purpose and means of processing personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who is a data processor?

A

A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the obligations of the data processor?

A
  1. Process personal data only on the documented instructions of the data controller, including with regards to data transfers outside the EEA
  2. Only authorized persons
  3. Implement security measures
  4. Sub-processor obligations
  5. Assist the controller with their obligations
  6. Delete/return data to the controller at the end
  7. Help controller demonstrate compliance.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly