Execute an Article 28-compliant processor arrangement: Which missing control is most direct?
The missing control is a GDPR Article 28 arrangement addressing processor duties, not merely commercial performance or assessment documentation.
The question
Under the GDPR in the European Union, a retailer uses a forecasting supplier only on documented instructions. The draft agreement identifies the service but omits confidentiality, security, subprocessor authorization, assistance with rights, and return or deletion duties. Transfers and the DPIA are otherwise addressed. Which missing control is most direct?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Require a new DPIA focused only on supplier forecast accuracy.A DPIA addresses processing risk, whereas the stated gap is the contractual allocation of processor obligations.
- Execute an Article 28-compliant processor arrangement covering those duties. ✓The listed omissions are core processor-arrangement subjects, requiring a contract or legal act that assigns and supports those duties.
- Rely on the supplier’s general terms for processing details.General terms may not provide the specific Article 28 processor arrangements and documented responsibilities required for this relationship.
- Add a service-level target for forecast accuracy and uptime.Performance metrics govern service quality, not the processor obligations concerning confidentiality, security, rights, and data disposition.
The trap
Match omissions involving instructions, confidentiality, security, subprocessors, rights assistance, and deletion to processor-contract requirements. How to remember it
The missing control is a GDPR Article 28 arrangement addressing processor duties, not merely commercial performance or assessment documentation.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Map each processing purpose to its GDPR role: What is the most direct missing control? →
- Complete and document a GDPR Article 35 DPIA first: Which missing control is required before processing when →
- Consult the competent supervisory authority before: What is the most direct missing control before processing? →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.