CIPP-E - European Data Protection: Scope and Accountability - Section 4.1

Understand what constitutes establishment and non-establishment in the EU and know the GDPR's scope of processing and the exemptions it allows, including EDPB guidelines on territorial scope.

Understand the Article 3 GDPR establishment test and the targeting criterion for non-EU organisations, and distinguish the processing activities each limb covers. Apply EDPB guidelines on territorial scope to determine whether a given controller or processor must comply with the GDPR.

Article 3 GDPRterritorial scopeestablishmenttargeting criterion

Practice question for this objective

Free sampleEuropean Data Protection: Scope and Accountabilityhard

A controller signs a processing agreement that gives its processor a general written authorisation to engage sub-processors. The processor later adds two sub-processors deep in its supply chain. The controller's compliance team, mindful of recent EDPB guidance on controller and processor obligations along a processing chain, asks what the controller itself must still do despite having granted the general authorisation. Which obligation continues to rest on the controller?

  • ANothing further, because a general written authorisation transfers full responsibility for vetting every sub-processor onto the lead processor alone
  • BPersonally negotiate and sign a separate Article 28 contract directly with each sub-processor before that sub-processor may begin work
  • CNotify the lead supervisory authority of each new sub-processor and obtain its prior approval before processing may continue
  • DVerify that sufficient guarantees are provided throughout the chain and be able to demonstrate it, retaining the means to obtain information about the sub-processors engaged Correct
Even under a general sub-processor authorisation, the controller retains an Article 28(1) duty to ensure and demonstrate sufficient guarantees throughout the processing chain. EDPB Opinion 22/2024 clarifies that a controller's accountability for choosing processors that provide sufficient guarantees does not stop at the first processor. The controller remains responsible across the sub-processing chain, must be able to verify those guarantees, and should retain the practical ability to obtain information about which sub-processors are engaged, so it can demonstrate compliance with Article 28(1).

Why A is wrong: This is the common misreading the guidance warns against; a general authorisation lets the processor add sub-processors without case-by-case sign-off, but it does not extinguish the controller's own accountability for the chain.

Why B is wrong: Article 28(4) requires the back-to-back contractual obligations to be imposed by the processor on its sub-processor, not signed directly by the controller; the controller is not made a party to each sub-processor contract.

Why C is wrong: There is no GDPR requirement to seek supervisory authority approval for adding sub-processors; the control mechanism is the controller's own verification of guarantees and the processor's contractual flow-down, not regulator pre-clearance.

Why D is correct: EDPB Opinion 22/2024 confirms that the controller's duty under Article 28(1) to use only processors offering sufficient guarantees extends across the whole chain; the controller must be able to verify and demonstrate this and should be able to obtain the identities of sub-processors, even under a general authorisation.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all European Data Protection: Scope and Accountability objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.