hardMultiple Choice
CCSP Practice Question: A cloud customer is subject to the EU General…
A cloud customer is subject to the EU General Data Protection Regulation (GDPR) and uses a cloud provider that subcontracts data processing to a third party without notification. Which GDPR requirement is violated?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sub-processor authorization
GDPR requires that data controllers obtain prior authorization before a processor engages a sub-processor. The customer (controller) was not notified, violating the requirement for sub-processor authorization. Other rights like erasure are unrelated to this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data protection by design
Why it's wrong here
Data protection by design concerns embedding safeguards into processing systems and operations, not the authorisation of sub-processors. It tempts because both address processor governance, yet it is correct when designing systems with privacy safeguards, whereas unnotified subcontracting breaches Article 28.
- ✗
Data breach notification
Why it's wrong here
The violation is failure to notify the controller before engaging a sub-processor, breaching Article 28 authorisation duties. Breach notification is tempting because it also concerns third parties, but it is correct when personal data is actually compromised, not when a sub-processor is appointed.
- ✓
Sub-processor authorization
Why this is correct
GDPR Article 28 requires the controller to authorise sub-processors and be notified of intended changes, so a provider engaging a third party without notification breaches the sub-processor authorisation requirement, regardless of security or breach-notification controls.
- ✗
Right to erasure
Why it's wrong here
Erasure concerns deleting a data subject's personal data on request; the stem describes a sub-processor change without notification, which breaches Article 28 obligations on authorisation and transparency of sub-processors. Erasure is tempting because it is a well-known data subject right, and would be the answer if the customer had asked the provider to delete their data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.