During a lawful investigation, a supervisory authority requests information from a controller, and the controller refuses all cooperation without a recognised legal ground. Which accountability rule is breached?
Select an answer to reveal the explanation.
Short Explanation
When the referee asks for the match sheet mid-game, walking off is not a strategy. GDPR expects controllers and processors to cooperate with supervisory authorities doing their jobs. Waiting until after a fine, or blaming an internal ‘silence policy,’ misses the duty.
Full Explanation
Article 31 requires the controller and the processor and, where applicable, their representatives to cooperate with the supervisory authority on request in the performance of its tasks. The duty is not limited to processors or postponed until after penalties. Internal preference for non-cooperation does not override Article 31. Recognised legal privileges or limits may apply in specific contexts but blanket refusal is non-compliant.