CIPP-E - European Data Protection Law and Regulation - Section 2.4

Understand the principles of effective and responsible vendor management and know the key requirements for sharing personal data with third parties.

Understand the Article 28 GDPR requirement for a data processing agreement when a controller engages a processor, and the mandatory clauses it must contain. Apply vendor management principles to evaluate third-party risk and ensure data sharing arrangements remain lawful.

data processing agreementArticle 28 GDPRvendor managementthird-party transfers

Practice question for this objective

Free sampleEuropean Data Protection Law and Regulationhard

A cloud accounting provider receives a data subject access request from a sole trader. The trader's account file contains the personal data of three of their suppliers, whose names and bank details were uploaded by the trader. The provider acts as processor for the trader's records but is the controller for the requester's own login and billing data. How should the provider lawfully respond to the access request regarding the supplier data held in the account file?

  • ADirect the request to the trader as controller of the supplier records, while itself answering only for the personal data for which it is the controller. Correct
  • BDisclose the supplier data in full, because the requester is the account holder and the right of access entitles them to everything stored under their account.
  • CRefuse the request entirely as manifestly unfounded, because it would require disclosing the personal data of three other identifiable individuals.
  • DAnonymise the supplier names and provide the rest of the account file to the requester within one month under the right of access.
The right of access binds the controller of the relevant data and covers only the requester's own personal data, not third-party data they uploaded as a controller. A processor handling records on a controller's behalf cannot satisfy an access request for that data; the request must be routed to the controller, and the processor answers only for personal data it controls in its own right, such as the account holder's own login and billing details.

Why A is correct: Correct: the provider is a processor for the trader's records, so the access right to the supplier data must be exercised against the trader as controller, and the provider answers in its own right only for data it controls, such as login and billing data.

Why B is wrong: This is tempting because the data sits under the requester's account, but the right of access only covers the requester's own personal data, not third parties' data the requester uploaded as a controller in their own right.

Why C is wrong: This overreaches: the presence of some third-party data does not make the whole request manifestly unfounded, and the provider must still address the requester's own personal data rather than refusing outright.

Why D is wrong: This sounds balanced, but the provider is not the controller for the supplier records and cannot decide to disclose them at all, anonymised or not; the access obligation for that data rests with the trader.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all European Data Protection Law and Regulation objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.