A processor markets 'GDPR certification' stickers but cannot show encryption, access control, or incident response capable of protecting the personal data. What should the controller prioritise?
Select an answer to reveal the explanation.
Short Explanation
Stickers don't encrypt databases. Dig into real controls and the contract—access locks, crypto, incident plans—before trusting a 'GDPR certified!' badge. Marketing is loud; measures are what protect people.
Full Explanation
Controllers must ensure processors implement appropriate TOMs and binding contractual terms. Unverified marketing claims or decorative 'GDPR certification' stickers without demonstrated controls do not substitute for substantive security assurance and Article 28-style contractual obligations.