According to the European Data Protection Board, if a controller that is not established in the EU but still subject to the GDPR becomes aware of a personal data breach, which supervisory authority or authorities must be notified?
A.
Only the supervisory authority of the EU member state in which the controller's EU representative (pursuant to Article 27) is established.
B.
Only one lead supervisory authority, as a controller benefits from the one-stop shop mechanism under the GDPR’s enforcement regime.
C.
Every supervisory authority of the EU member states where the controller is offering goods or services.
D.
Every supervisory authority for which affected data subjects reside in their EU member state.
A. Only the supervisory authority of the EU member state in which the controller's EU representative (pursuant to Article 27) is established.
Explanation:
According to the European Data Protection Board (EDPB), a controller that is not established in the EU but is subject to the GDPR must designate an EU representative (pursuant to Article 27). In the event of a personal data breach, the controller must notify the supervisory authority of the EU member state where its EU representative is established. This ensures that the controller has a clear point of contact within the EU for regulatory matters, including data breaches.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Ssourav
3 months, 3 weeks ago