List of questions
Related questions
Question 201 - CIPP-E discussion
SCENARIO
Please use the following to answer the next question:
Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta (EU).
People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.
The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.
The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a
Are the cybersecurity assessors required to sign a data processing agreement with the company in order to comply with the GDPR''
No, the assessors do not quality as data processors as they only have access to encrypted data.
No. the assessors do not quality as data processors as they do not copy the data to their facilities.
Yes. the assessors a-e considered to be joint data controllers and must sign a mutual data processing agreement.
Yes, the assessors are data processors and their processing of personal data must be governed by a separate contract or other legal act.
0 comments
Leave a comment first