CIPP-E - European Data Protection: Scope and Accountability - Section 4.2

Understand the accountability requirements of controllers, joint controllers, and processors including data protection by design and by default, documentation requirements, and cooperation with regulators.

Describe the accountability obligations the GDPR places on controllers, joint controllers, and processors, including data protection by design and by default under Article 25 and Records of Processing Activities. Apply EDPB Opinion 22/2024 on reliance on processors and sub-processors to allocate responsibility along a chain of processing.

accountability principledata protection by designArticle 25 GDPRjoint controllersEDPB Opinion 22/2024

Practice question for this objective

Free sampleEuropean Data Protection: Scope and Accountabilityhard

A controller engages a SaaS payroll provider as its processor under an Article 28 contract that grants a general written authorisation to use sub-processors. The provider in turn engages a sub-processor in another Member State to run pension calculations, and that sub-processor uses a further hosting sub-processor of its own. The controller's privacy lead is mapping which accountability obligations genuinely apply along this processing chain. Drawing on Article 30, the EDPB Opinion 22/2024 on processors and sub-processors, and the accountability framework, which TWO statements correctly state an obligation that applies here? (Select TWO.)

  • ABecause the payroll provider employs fewer than 250 people, it is wholly exempt from keeping any record of the categories of processing it carries out for this controller.
  • BThe payroll provider, acting as processor, must maintain its own record of processing activities listing the categories of processing carried out on behalf of the controller. Correct
  • CBy engaging sub-processors in the chain, the payroll provider and its pension sub-processor become joint controllers who must agree an Article 26 arrangement.
  • DEven with a general authorisation, the controller stays responsible for ensuring sufficient guarantees exist throughout the chain, and the provider must impose equivalent data protection obligations on each sub-processor by contract. Correct
  • EEach sub-processor in the chain must contract its data protection obligations directly with the controller itself, bypassing the payroll provider that actually engaged it.
Along a processing chain, each processor keeps its own Article 30 record and flows down equivalent obligations, while the controller retains responsibility for verifying sufficient guarantees throughout. Article 30(2) obliges every processor to record the categories of processing it performs for each controller, and Article 28(4) read with EDPB Opinion 22/2024 makes the engaging processor impose equivalent obligations on each sub-processor while the controller keeps a residual duty to ensure sufficient guarantees exist throughout the chain. The strongest distractor, the 250-employee exemption, fails because that derogation does not cover regular, non-occasional processing such as payroll.

Why A is wrong: Tempting because the Article 30(5) derogation references 250 employees, but it does not apply where processing is regular rather than occasional, so a payroll processor must still keep a record.

Why B is correct: Article 30(2) requires each processor to keep a record of the categories of processing performed for every controller, so this is a genuine accountability obligation on the provider.

Why C is wrong: This confuses the chain with joint control, but the parties remain processor and sub-processor under Article 28 unless they jointly determine the purposes and means, which they do not here.

Why D is correct: Article 28(4) and EDPB Opinion 22/2024 confirm the controller's residual verification duty and the flow-down of equivalent obligations to every sub-processor along the chain.

Why E is wrong: This inverts Article 28(4): the engaging processor, not the controller, imposes the equivalent obligations on its sub-processor, so a direct controller contract is not what the chain requires.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all European Data Protection: Scope and Accountability objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.