Courseiva
Legal, Risk, and Compliance →mediumMultiple Choice

CCSP Legal, Risk, and Compliance Practice Question

A cloud customer operates a SaaS-based HR platform in the EU and receives a data subject access request (DSAR) from an employee. The provider's standard contract states it will only assist with DSARs on a 'reasonable efforts' basis and bills hourly for that assistance. Under GDPR Article 28, which contractual element must the customer ensure is in place before relying on this SaaS platform?

⚠ Common exam trap

The trap here is assuming that a transfer mechanism such as SCCs or BCRs, or a voluntary certification, substitutes for the mandatory Article 28 processing contract that establishes the processor's assistance duties to the controller.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A data processing agreement (DPA) that obligates the processor to assist the controller in responding to data subject requests.

GDPR Article 28(3) requires the controller and processor to be bound by a contract or other legal act that sets out the processor's obligations, including assisting the controller with data subject requests. Without a DPA containing that assistance obligation, the customer has no enforceable basis to compel the provider's help, regardless of the provider's internal practices or certification status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A Standard Contractual Clause (SCC) module three signed with the SaaS provider to legitimize onward transfers.

    Why it's wrong here

    SCCs are an Article 46 transfer tool used when personal data leaves the EEA; module three covers processor-to-processor transfers. They address transfer legality, not the domestic processor obligations owed to the controller under Article 28. Since the platform is described as EU-hosted, the binding gap is the DPA's assistance clause, not an SCC.

  • ✓

    A data processing agreement (DPA) that obligates the processor to assist the controller in responding to data subject requests.

    Why this is correct

    Article 28(3)(e) requires the processor to assist the controller by appropriate technical and organisational measures in responding to data subject requests, and Article 28(3) requires the processing to be governed by a binding contract. A DPA is therefore the mandatory instrument, and reasonable-efforts language plus hourly billing does not discharge the provider's Article 28 duty to assist.

  • ✗

    A binding corporate rules (BCR) approval from the lead supervisory authority covering the provider's intra-group transfers.

    Why it's wrong here

    BCRs are an Article 47 transfer mechanism used by multinational corporate groups for intra-group transfers to third countries. They do not govern the controller-processor relationship for an EU-hosted SaaS platform and do not create DSAR assistance obligations for the customer. The scenario does not involve an intra-group transfer, so BCR approval is irrelevant here.

  • ✗

    A certification under an approved Article 42 code of conduct demonstrating the provider's accountability framework.

    Why it's wrong here

    Article 42 certifications can demonstrate appropriate safeguards and may support transfers, but they are voluntary and do not replace the Article 28(3) contract terms. A certification does not obligate the provider to assist with a specific DSAR or prevent hourly billing for that assistance. The customer still needs a DPA establishing the assistance duty.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.