Courseiva
Asset SecuritymediumMultiple ChoiceObjective-mapped

CISSP Asset Security Practice Question

Under GDPR, a company processes personal data on behalf of a data controller. Which role does the company fulfill?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data processor

A data processor processes data on behalf of the controller, subject to strict contractual and regulatory obligations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data custodian

    Why it's wrong here

    A data custodian is a general term referring to an individual or entity responsible for the safe custody, transport, and storage of data, ensuring its integrity and availability. While a custodian performs vital data management functions, this role is not a specific legal entity defined by GDPR as processing personal data on behalf of another company. GDPR delineates precise roles like controller and processor to assign specific legal obligations and liabilities.

  • Data controller

    Why it's wrong here

    A data controller is the entity that determines the purposes and means of the processing of personal data. While central to GDPR, the controller is the principal party for whom the data is processed, not the entity performing the processing 'on behalf of' another. The controller establishes the 'why' and 'how' of data processing, often engaging a separate processor to execute these operations.

  • Data processor

    Why this is correct

    Under GDPR, a data processor is an entity that processes personal data strictly on behalf of, and according to the documented instructions of, a data controller. This relationship is typically formalized through a data processing agreement (DPA), which outlines the scope, nature, and purpose of processing. The processor does not determine the purposes or means of processing independently but acts as a service provider executing tasks delegated by the controller.

  • Data subject

    Why it's wrong here

    A data subject is the identified or identifiable natural person to whom personal data relates. This individual is the owner of the personal data and the focus of GDPR's protections, possessing rights such as access, rectification, and erasure. The data subject is the individual whose data is being processed, not a company or entity that processes data on behalf of another organization.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.