CCSP Legal, Risk, and Compliance Practice Question
Under the General Data Protection Regulation (GDPR), if a cloud service provider (acting as a data processor) suffers a personal data breach, what is the provider's obligation regarding notification?
⚠ Common exam trap
CCSP often tests the controller-versus-processor notification chain, baiting candidates with the familiar 72-hour supervisory authority deadline that actually belongs to the controller, not the processor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The processor must notify the data controller without undue delay upon becoming aware of the breach.
Under GDPR Article 33(2), a processor must notify the controller without undue delay after becoming aware of a personal data breach. The controller — not the processor — is the party responsible for notifying the supervisory authority within 72 hours (Article 33(1)) and, where required, the data subjects (Article 34). The processor's obligation is limited to informing the controller so the controller can meet its own regulatory deadlines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The processor must notify the data controller without undue delay upon becoming aware of the breach.
Why this is correct
Article 33 obliges the processor to notify the controller without undue delay after becoming aware of a personal data breach. The controller then assesses and notifies the supervisory authority within 72 hours; the processor holds no direct regulator notification duty.
- ✗
The processor must notify the supervisory authority within 72 hours.
Why it's wrong here
The 72-hour supervisory authority deadline under Article 33 binds the controller, not the processor; the processor notifies the controller without undue delay. The 72-hour figure is tempting because it dominates breach discussions, yet it applies to the controller's authority notification, a different obligation.
- ✗
The processor does not have any notification obligation under GDPR.
Why it's wrong here
Article 33 requires a processor to notify the controller without undue delay after becoming aware of a personal data breach. Claiming no obligation is tempting because the controller faces the supervisory authority and data subjects, but the processor's controller-notification duty is explicit and independent.
- ✗
The processor must notify the affected data subjects directly within 72 hours.
Why it's wrong here
Under GDPR Article 33, the processor notifies the controller without undue delay; the controller, not the processor, informs data subjects. Direct subject notification is tempting because Article 34 imposes it, but that duty falls on the controller, and only when the breach poses high risk.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.