CIPPE Module 3 - Controllers and Processors Flashcards
1
Q
What are the four key roles in GDPR?
A
- Data Subject - natural person about whom data is collected.
- Data Controller - determines what/how data is collected.
- Data Processor - has no autonomy over the data; they only do what the controller tells them to do.
- Supervisory Authority
2
Q
Who is a data controller?
A
A natural or legal person, public authority, agency, which alone or jointly with others determines the purpose and means of processing personal data.
3
Q
Who is a data processor?
A
A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
4
Q
What are the obligations of the data processor?
A
- Process personal data only on the documented instructions of the data controller, including with regards to data transfers outside the EEA
- Only authorized persons
- Implement security measures
- Sub-processor obligations
- Assist the controller with their obligations
- Delete/return data to the controller at the end
- Help controller demonstrate compliance.