Courseiva
Protection of Information AssetsmediumMultiple SelectObjective-mapped

CISA Binding Corporate Rules (BCRs) Practice Question

An IS auditor is assessing the organization's compliance with privacy regulations regarding cross-border data transfers. Which TWO of the following are acceptable mechanisms to legitimize such transfers under the GDPR?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Binding corporate rules (BCRs) approved by a supervisory authority

Under GDPR, the two primary mechanisms for legitimizing cross-border data transfers are Binding Corporate Rules (BCRs) approved by a supervisory authority and Standard Contractual Clauses (SCCs) adopted by the European Commission. Adequacy decisions, while a valid basis for transfers to specific countries, are not a mechanism that organizations can directly implement; they are a determination by the European Commission. Encryption does not legitimize a transfer, and explicit consent alone is generally not considered sufficient as a transfer mechanism under GDPR.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Binding corporate rules (BCRs) approved by a supervisory authority

    Why this is correct

    BCRs approved by a supervisory authority are an appropriate safeguard under GDPR and can legitimize transfers within a corporate group.

  • Encryption of data prior to transfer

    Why it's wrong here

    Encryption is a security measure but does not provide a legal basis for cross-border data transfers under GDPR.

  • Standard contractual clauses (SCCs) adopted by the European Commission

    Why this is correct

    SCCs adopted by the European Commission are a standard contractual mechanism that provides adequate safeguards for data transfers.

  • Adequacy decision by the European Commission for the recipient country

    Why it's wrong here

    An adequacy decision by the European Commission determines that a country ensures an adequate level of data protection. However, it is not a mechanism that organizations can directly implement; it is a status. Therefore, it is not one of the acceptable mechanisms for organizations to use for transfers.

  • Explicit consent from the data subjects

    Why it's wrong here

    Explicit consent can be used as a derogation for specific situations, but it is generally not considered a sufficient mechanism for regular cross-border transfers under GDPR.

About these practice questions

This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.