Courseiva
hardMultiple Choice

CCSP Practice Question: A cloud customer is subject to the EU General…

A cloud customer is subject to the EU General Data Protection Regulation (GDPR) and uses a cloud provider that subcontracts data processing to a third party without notification. Which GDPR requirement is violated?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sub-processor authorization

GDPR requires that data controllers obtain prior authorization before a processor engages a sub-processor. The customer (controller) was not notified, violating the requirement for sub-processor authorization. Other rights like erasure are unrelated to this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data protection by design

    Why it's wrong here

    Data protection by design concerns embedding safeguards into processing systems and operations, not the authorisation of sub-processors. It tempts because both address processor governance, yet it is correct when designing systems with privacy safeguards, whereas unnotified subcontracting breaches Article 28.

  • ✗

    Data breach notification

    Why it's wrong here

    The violation is failure to notify the controller before engaging a sub-processor, breaching Article 28 authorisation duties. Breach notification is tempting because it also concerns third parties, but it is correct when personal data is actually compromised, not when a sub-processor is appointed.

  • ✓

    Sub-processor authorization

    Why this is correct

    GDPR Article 28 requires the controller to authorise sub-processors and be notified of intended changes, so a provider engaging a third party without notification breaches the sub-processor authorisation requirement, regardless of security or breach-notification controls.

  • ✗

    Right to erasure

    Why it's wrong here

    Erasure concerns deleting a data subject's personal data on request; the stem describes a sub-processor change without notification, which breaches Article 28 obligations on authorisation and transparency of sub-processors. Erasure is tempting because it is a well-known data subject right, and would be the answer if the customer had asked the provider to delete their data.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.