A product owner claims that after adopting enterprise SaaS for EU customer CRM, only the cloud provider is the controller and the company has no further GDPR role. What is the usual correct framing?
Select an answer to reveal the explanation.
Short Explanation
Renting Salesforce-style CRM does not mean you tossed the controller hat onto the provider. You still decide why customer data are processed; they mostly host and run the tooling as processor. Shared security is not shared-away accountability.
Full Explanation
Controller status turns on who determines purposes and means of processing. Organisations using SaaS to manage their own customer relationships typically remain controllers; providers supplying the platform commonly process on documented instructions as processors (Art. 28), subject to factual nuance and possible joint-controller findings in edge cases. Cloud shared-responsibility models for security do not rewrite those roles or eliminate the customer's accountability under the GDPR.