CAS-004 Governance, Risk, and Compliance Practice Question
A multinational retailer must transfer employee personal data from its European Union subsidiary to a processing center in a country without an adequacy decision. Legal counsel wants a transfer mechanism that imposes enforceable data protection obligations on the importer and includes a documented transfer impact assessment. Which mechanism best matches these requirements?
⚠ Common exam trap
The trap here is treating any listed transfer mechanism as automatically sufficient, when the scenario specifically requires enforceable importer obligations plus a documented transfer impact assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Standard Contractual Clauses supplemented by a transfer impact assessment and additional safeguards
Cross-border transfers outside an adequacy decision require a valid Chapter V mechanism. Standard Contractual Clauses impose enforceable obligations on the importer, and following Schrems II they must be accompanied by a transfer impact assessment and supplementary measures where destination laws undermine protection. Consent, codes of conduct, and improperly approved Binding Corporate Rules do not meet the combined contractual and assessment requirements described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An explicit consent obtained from each employee once at the time of hire for all future transfers
Why it's wrong here
Consent is a derogation intended for occasional, non-repetitive transfers, not routine multinational HR data flows, and it must be freely given, specific, and withdrawable. Using a single blanket consent at hire for indefinite future transfers is invalid in an employment context due to power imbalance and does not provide the enforceable importer obligations the counsel requested.
- ✗
A certification under an approved code of conduct registered with the subsidiary's data protection authority
Why it's wrong here
Approved codes of conduct can support transfers only when the importer makes binding and enforceable commitments, and the mechanism is still maturing with limited approved codes. It does not by itself deliver the specific enforceable contractual obligations and transfer impact assessment the counsel demanded, making it a weaker fit than clauses designed precisely for that purpose.
- ✓
Standard Contractual Clauses supplemented by a transfer impact assessment and additional safeguards
Why this is correct
Standard Contractual Clauses are pre-approved contractual terms that create enforceable obligations on the data importer, and after the Schrems II ruling they must be paired with a transfer impact assessment of the destination country's laws plus supplementary technical or organizational measures when needed. This combination directly satisfies the requirement for enforceable importer obligations and a documented assessment.
- ✗
Binding Corporate Rules approved only by the subsidiary's local supervisory authority without any further analysis
Why it's wrong here
Binding Corporate Rules are a valid transfer tool for intra-group transfers, but they require approval from the competent supervisory authority and are not simply granted by a local authority on request. They also do not eliminate the need to assess destination-country surveillance laws, so this option misstates both the approval path and the assessment obligation in the scenario.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.