CISA Binding Corporate Rules (BCRs) Practice Question
An IS auditor is assessing the organization's compliance with privacy regulations regarding cross-border data transfers. Which TWO of the following are acceptable mechanisms to legitimize such transfers under the GDPR?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Binding corporate rules (BCRs) approved by a supervisory authority
Under GDPR, the two primary mechanisms for legitimizing cross-border data transfers are Binding Corporate Rules (BCRs) approved by a supervisory authority and Standard Contractual Clauses (SCCs) adopted by the European Commission. Adequacy decisions, while a valid basis for transfers to specific countries, are not a mechanism that organizations can directly implement; they are a determination by the European Commission. Encryption does not legitimize a transfer, and explicit consent alone is generally not considered sufficient as a transfer mechanism under GDPR.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Binding corporate rules (BCRs) approved by a supervisory authority
Why this is correct
BCRs approved by a supervisory authority are an appropriate safeguard under GDPR and can legitimize transfers within a corporate group.
- ✗
Encryption of data prior to transfer
Why it's wrong here
Encryption is a security measure but does not provide a legal basis for cross-border data transfers under GDPR.
- ✓
Standard contractual clauses (SCCs) adopted by the European Commission
Why this is correct
SCCs adopted by the European Commission are a standard contractual mechanism that provides adequate safeguards for data transfers.
- ✗
Adequacy decision by the European Commission for the recipient country
Why it's wrong here
An adequacy decision by the European Commission determines that a country ensures an adequate level of data protection. However, it is not a mechanism that organizations can directly implement; it is a status. Therefore, it is not one of the acceptable mechanisms for organizations to use for transfers.
- ✗
Explicit consent from the data subjects
Why it's wrong here
Explicit consent can be used as a derogation for specific situations, but it is generally not considered a sufficient mechanism for regular cross-border transfers under GDPR.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.