Q: 9
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?
Options
Discussion
I was leaning toward B because data mapping isn't always specifically listed in Article 30, but thinking about it more, controllers do need to document categories of data and recipients. Not too confident here though, the wording is tricky.
A Article 30 doesn’t require keeping breach records specifically, only processing activities. That’s outlined separately under Article 33 I think. Disagree?
B, not A
Had something like this in a mock, it's A.
Probably A. Article 30 is about processing activities records, not breach incidents. Reporting breaches is under different GDPR articles if I remember right.
Be respectful. No spam.