CCSP Legal, Risk, and Compliance Practice Question
A cloud customer stores personal data of EU residents in a SaaS application. The customer's contract with the SaaS provider includes a data processing addendum. The customer's legal team wants to understand the allocation of GDPR responsibilities. Which of the following best describes the roles of the customer and the SaaS provider under GDPR?
⚠ Common exam trap
The trap here is assuming that the cloud provider is always just a processor, when in fact it can also be a controller for certain activities, or conversely assuming that hosting data makes the provider the controller.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer is the controller and the SaaS provider is the processor, unless the provider processes data for its own purposes, in which case it may also be a controller for those specific activities
In a typical SaaS arrangement, the customer is the controller and the provider is the processor. The provider may become a controller for specific processing done for its own purposes, such as service analytics or marketing. This dual role is recognized in GDPR and should be addressed in the data processing addendum.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The customer is the processor and the SaaS provider is the controller because the provider hosts the data
Why it's wrong here
Hosting data does not make the provider the controller. The controller is the entity that determines the purposes and means of processing. The customer decides what data to upload and why, so it is the controller. Reversing these roles would incorrectly place GDPR obligations on the provider for processing that is directed by the customer, contrary to the standard cloud service model.
- ✗
The SaaS provider is the sole controller because it owns the infrastructure and determines the security measures
Why it's wrong here
Owning infrastructure and choosing security measures does not equate to controllership for the customer's data. Security measures are often part of the processor's obligations under Article 32. The provider processes personal data on behalf of the customer, so it is a processor, not the sole controller. This option confuses operational control with legal controllership.
- ✓
The customer is the controller and the SaaS provider is the processor, unless the provider processes data for its own purposes, in which case it may also be a controller for those specific activities
Why this is correct
Under GDPR, the customer typically determines the purposes and means of processing and is the controller. The SaaS provider acts as a processor when it processes personal data solely on the customer's instructions. However, if the provider uses data for its own purposes, such as improving its services or marketing, it becomes a controller for those activities. This nuanced allocation is common in cloud contracts and data processing addenda.
- ✗
Both the customer and the SaaS provider are joint controllers for all processing activities
Why it's wrong here
Joint controllership arises when two or more controllers jointly determine the purposes and means of processing. In a typical SaaS arrangement, the customer determines why data is processed, while the provider processes on the customer's behalf. Treating them as joint controllers for all activities is inaccurate and would misallocate responsibilities, especially for the provider's own service improvement activities, which may be separate controllership.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.