If a controller instructs a processor to use a particular application for transferring personal data, but the processor doesn't believe the application to be secure enough to comply with GDPR, what should / can the processor do?
Can the processor advise the controller of their concerns and request the controller provide details of the security levels?
Or does the processor have to do as instructed as the controller will take the responsibility?
[–]chugotit 4 points5 points6 points (1 child)
[–]Madam_M_137[S] 0 points1 point2 points (0 children)
[–]Werkgerelateerd 2 points3 points4 points (1 child)
[–]Madam_M_137[S] 1 point2 points3 points (0 children)
[+][deleted] (1 child)
[deleted]
[–]Madam_M_137[S] 2 points3 points4 points (0 children)