Differentiate controller responsibilities from processor obligations in common vendor-processing situations.
A new SaaS vendor will process customer data on the company's behalf. Sort each action by who primarily owns it. Primarily controller responsibility Primarily processor responsibility Shared but controller must verify Define the purpose for sending customer data to the vendor Choose a processor that provides sufficient guarantees Process the data only on documented instructions Ensure authorized vendor staff are bound by confidentiality Assist with subject-rights requests when the processor holds relevant data Manage sub-processor changes and allow the controller to object where required Delete or return the data at the end of the service according to the contract Notify…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in