CCSP Legal, Risk, and Compliance Practice Question
A cloud customer's security team learns that a provider's subprocessor experienced a breach affecting the customer's data. The customer's contract requires the provider to notify the customer of subprocessor breaches. Under the GDPR, within what timeframe must the cloud provider, acting as a processor, notify the controller of a personal data breach?
⚠ Common exam trap
The trap here is applying the controller's 72-hour supervisory authority deadline to the processor's obligation to notify the controller, which is instead 'without undue delay.'
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Without undue delay after becoming aware of the breach
GDPR Article 33(2) requires a processor to inform the controller without undue delay after becoming aware of a personal data breach. The 72-hour clock applies to the controller's notification to the supervisory authority, not to the processor's notice to the controller. This sequencing lets the controller assess the breach and meet its own regulatory and contractual duties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Without undue delay after becoming aware of the breach
Why this is correct
Article 33(2) requires a processor to notify the controller without undue delay after becoming aware of a personal data breach. 'Without undue delay' is deliberately not a fixed number of hours; it means as soon as reasonably possible given the circumstances. The controller then decides whether to notify the supervisory authority within its own 72-hour window.
- ✗
Within 30 calendar days of completing its internal forensic investigation
Why it's wrong here
GDPR does not permit a processor to wait until forensics are complete before notifying the controller. The obligation triggers on awareness of the breach, not on completion of an investigation. A 30-day post-investigation window would delay the controller's ability to meet its own regulatory deadlines and would breach the 'without undue delay' standard.
- ✗
Within 72 hours of becoming aware of the breach
Why it's wrong here
The 72-hour deadline is the controller's obligation under Article 33 to notify the supervisory authority, not the processor's deadline to inform the controller. The processor's duty to notify the controller is 'without undue delay' after becoming aware. Confusing these two timelines is a common error because both involve breach notification but apply to different parties.
- ✗
Within 24 hours of confirming that the breach involves personal data
Why it's wrong here
No 24-hour processor notification deadline exists in GDPR. The only 24-hour figure sometimes referenced is the NIS Directive's early warning for operators of essential services, which is a different legal regime. For GDPR processor-to-controller notification, the standard is 'without undue delay,' not a fixed one-day window.
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.