CCSP Legal, Risk, and Compliance Practice Question
A US-based retail company stores customer personal data in a cloud provider's data center located in Germany. The company is subject to GDPR because it offers goods to EU residents. Which legal mechanism most directly establishes that the controller and the cloud provider may lawfully transfer personal data from the EU to the provider's US-based support team?
⚠ Common exam trap
The trap here is assuming that a data processing agreement or a security certification alone satisfies GDPR cross-border transfer requirements, when an Article 46 mechanism such as SCCs is also needed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Standard Contractual Clauses (SCCs) executed between the controller and the cloud provider
When EU personal data is accessible from a third country such as the United States, the controller needs a valid Chapter V transfer mechanism. Standard Contractual Clauses are pre-approved by the European Commission and are the most direct, widely used tool for controller-to-processor cloud transfers. A DPA governs processing but does not authorize the transfer, and security certifications or corporate-group rules do not fill that gap.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Standard Contractual Clauses (SCCs) executed between the controller and the cloud provider
Why this is correct
SCCs are pre-approved contractual terms adopted by the European Commission that provide an Article 46 transfer safeguard when personal data leaves the EEA. Because the provider's US support staff can access EU personal data, the controller needs a valid transfer tool, and SCCs are the most common and directly applicable mechanism for controller-to-processor transfers in a cloud engagement.
- ✗
A data processing agreement (DPA) alone, without any additional transfer safeguard
Why it's wrong here
A DPA is required by GDPR Article 28 to govern the processor's obligations, but it is not a Chapter V transfer mechanism. When personal data moves to a third country, the controller must also rely on an adequacy decision or an Article 46 tool such as SCCs. A DPA by itself does not satisfy the transfer requirement.
- ✗
A Binding Corporate Rules (BCR) approval granted to the cloud provider by its lead supervisory authority
Why it's wrong here
BCRs are intra-group transfer mechanisms available only to multinational corporate groups transferring data among their own affiliates. They do not cover transfers to an unrelated cloud provider unless that provider has its own approved BCRs, which is uncommon. For this controller-provider relationship, BCRs are not the mechanism the controller can rely on.
- ✗
The provider's ISO/IEC 27001 certification covering its German data center
Why it's wrong here
ISO/IEC 27001 certifies that a management system for information security meets a standard; it is not a legal transfer mechanism under GDPR. Certification may support due diligence and demonstrate security controls, but it does not by itself legitimize transferring EU personal data to a third country. The controller still needs an Article 46 safeguard such as SCCs.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.