Option B all the way! The controller is the one holding the bag, so they better be able to prove they're doing it right. Wouldn't want to end up like that guy who got fined for losing track of his data, yikes!
I think option B is the way to go. The controller has to be able to show they're following the GDPR requirements. Anything less is just asking for trouble!
Hmm, I'm not sure about option B. Doesn't the GDPR also require controllers to conduct legitimate interests assessments for direct marketing? I'll need to double-check that.
I think the basis of the accountability and data governance obligation is B) The controller shall be responsible for and be able to demonstrate compliance with the data protection principles.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Genevieve
6 hours agoAliza
4 days agoRosita
7 days agoTresa
11 days agoLaura
28 days agoEarleen
1 months agoMarkus
1 months ago