A SaaS vendor processing municipal customer data suffers a personal-data breach. The city asks who notifies the supervisory authority under the GDPR. Which allocation of duties is correct?
Select an answer to reveal the explanation.
Short Explanation
The vendor rings the city first—fast. The city, as controller, then decides about the regulator and the people. Hosting the boxes does not automatically make the processor the public notifier.
Full Explanation
Article 33(2) GDPR requires a processor to notify the controller without undue delay after becoming aware of a personal data breach. The controller then assesses risk and carries out any required notification to the supervisory authority under Article 33(1) and to data subjects under Article 34. Hosting responsibility alone does not shift the primary SA-notification duty away from the controller.