A processor subcontracts hosting of the controller’s personal data to another provider without informing the controller or obtaining the required authorisation. Which GDPR theme is primarily violated?
Select an answer to reveal the explanation.
Short Explanation
The processor cannot quietly pass your data to a new host like a hot potato. Controllers must authorise sub-processors—specifically or generally—and get transparency when the chain changes. Price tags do not skip that rule.
Full Explanation
Article 28 GDPR requires that a processor not engage another processor without prior specific or general written authorisation of the controller, and general authorisation includes informing the controller of intended changes so objections can be raised. Subcontracting hosting of personal data without that authorisation and transparency undermines controller oversight of the processing chain. Cost savings do not create an exception.