Which organizations need to comply with the General Data Protection Regulation (GDPR)?
Options:
A.
Only organizations that have employees in the European Union (EU).
B.
Only organizations that have their headquarters in the European Union (EU).
C.
All organizations anywhere in the world.
D.
All organizations located in the European Union and also organizations outside the European Union that offer goods or services to data subjects in the EU.
This is a question that has the most doubts: “Who needs to adapt?". For example: 1 - If you have a company in Brazil and sell products or services and process personal data from residents in the EU, in this case your company must conform to the GDPR. 2- If you have a company located in the EU and handle personal data.
Transcribing here part of Article 3 of the GDPR:
1.This Regulation applies to the processing of personal data carried out in the context of the activities of an establishment of a controller or a subcontractor located in the territory of the Union, regardless of whether the processing takes place inside or outside the Union.
2.This Regulation applies to the processing of personal data of holders residing in the territory of the Union, carried out by a controller or processor not established in the Union, when the processing activities are related to:
a)The provision of goods or services to such data subjects in the Union, regardless of the requirement for data subjects to make a payment;
b)Control of their behavior, provided that such behavior takes place in the Union.
Question # 25
A controller wants to switch processors. What is necessary to review before making this change, so that it remains GDPR compliant?
Options:
A.
The matrix location of this new processor.
B.
Require the old processor to erase data.
C.
Require the old processor to port the data.
D.
Verify that the new processor has sufficient security guarantees.
Verify that the processor has sufficient security guarantees that are essential for the Controller to remain in
compliance with the GDPR. Remember that the responsibility is always of the controller who must take care of the data of the data subjects that have been entrusted to him.
Recital 81 mentions the following:
(81) To ensure compliance with the requirements of this Regulation in respect of the processing to be carried out by the processor on behalf of the controller, when entrusting a processor with processing activities, the controller should use only processors providing sufficient guarantees, in particular in terms of expert knowledge, reliability and resources, to implement technical and organizational measures which will meet the requirements of this Regulation, including for the security of processing. The adherence of the processor to an approved code of conduct or an approved certification mechanism may be used as an element to demonstrate compliance with the obligations of the controller.