Question

Difficulty: MediumRegulatory Compliance and Legal Requirements Management

A cloud-based human resources software-as-a-service (SaaS) provider located in the United States hosts employee performance records on behalf of its corporate enterprise clients operating within the European Union. The clients determine which employee data is collected and how long it should be retained. Under the General Data Protection Regulation (GDPR), which role and legal obligation best describes the SaaS provider's compliance status regarding this employee data?

  1. Data processor, which must handle personal data strictly in accordance with the data controller's documented instructions and implement appropriate technical security controls.Answer
  2. B
    Data controller, which holds primary legal responsibility for determining the overall purpose and business necessity of collecting the employee personal data.
  3. C
    Data owner, which maintains sole legal authority to establish classification labels and define data retention schedules without requiring client authorization.
  4. D
    Data custodian, which is legally exempt from maintaining security controls because physical infrastructure management is transferred to a public cloud host.

Answer

The SaaS provider acts as a data processor that must process personal data strictly according to the controller's instructions while maintaining appropriate technical and organizational safeguards.
The correct option correctly identifies the SaaS vendor as a data processor. Under data privacy regulations like GDPR, an entity that processes personal data on behalf of a data controller (the enterprise client) must follow the controller's instructions and maintain appropriate security controls to safeguard data confidentiality and integrity.

Step-by-Step Solution

1
Analyze the organizational relationship and operational scope in the scenario.
The corporate client determines why and what employee data is collected, while the SaaS vendor provides the system to store and process it.
Regulatory frameworks differentiate entities based on operational control over data processing purposes.
2
Map the roles to GDPR definitions.
The client is the Data Controller (determines purposes and means), and the SaaS vendor is the Data Processor (processes data on behalf of the controller).
A third-party hosting service operating under customer direction fulfills the regulatory definition of a data processor.
3
Identify the key legal obligations of a Data Processor.
Process data solely on documented instructions from the controller and implement robust administrative and technical controls.
GDPR mandates specific contractual and technical duties for processors to ensure data privacy.

Key Concept

Data Privacy Roles and Responsibilities (Data Controller vs. Data Processor)
Estimated Time:1m 15s
Rate this question