A cloud-based human resources software-as-a-service (SaaS) provider located in the United States hosts employee performance records on behalf of its corporate enterprise clients operating within the European Union. The clients determine which employee data is collected and how long it should be retained. Under the General Data Protection Regulation (GDPR), which role and legal obligation best describes the SaaS provider's compliance status regarding this employee data?
- Data processor, which must handle personal data strictly in accordance with the data controller's documented instructions and implement appropriate technical security controls.Answer
- BData controller, which holds primary legal responsibility for determining the overall purpose and business necessity of collecting the employee personal data.
- CData owner, which maintains sole legal authority to establish classification labels and define data retention schedules without requiring client authorization.
- DData custodian, which is legally exempt from maintaining security controls because physical infrastructure management is transferred to a public cloud host.
Answer
The SaaS provider acts as a data processor that must process personal data strictly according to the controller's instructions while maintaining appropriate technical and organizational safeguards.
The correct option correctly identifies the SaaS vendor as a data processor. Under data privacy regulations like GDPR, an entity that processes personal data on behalf of a data controller (the enterprise client) must follow the controller's instructions and maintain appropriate security controls to safeguard data confidentiality and integrity.
Step-by-Step Solution
Key Concept
Data Privacy Roles and Responsibilities (Data Controller vs. Data Processor)
Estimated Time:1m 15s