CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityEasy

A cloud-based analytics company regularly processes large-scale, sensitive personal data belonging to EU residents as a core part of its business. Under the GDPR, which role must this organization appoint to oversee data protection strategy and act as a contact point for supervisory authorities?

  1. AData Custodian
  2. BCompliance Auditor
  3. CData Protection Officer (DPO)
  4. DChief Information Officer (CIO)
Show answer & explanation

Correct answer: C. Data Protection Officer (DPO)

The GDPR requires certain organizations, particularly those engaged in large-scale, systematic monitoring or processing of sensitive data, to appoint a Data Protection Officer (DPO) responsible for overseeing data protection compliance and serving as a liaison with regulators.

Why the other options are wrong

  • A. Data custodian is an operational role managing data storage, not a formal GDPR-mandated oversight position.
  • B. A compliance auditor evaluates adherence to standards but is not the specific role GDPR requires be appointed.
  • D. A CIO oversees IT strategy broadly but is not the GDPR-mandated compliance role.

Data Protection Officer (DPO)

A role required under GDPR for organizations that conduct large-scale or systematic processing of sensitive personal data, responsible for overseeing data protection compliance and liaising with regulators.

  • Required for public authorities and large-scale sensitive data processors
  • Acts as point of contact for data subjects and supervisory authorities
  • Monitors GDPR compliance internally
  • Must operate independently, reporting to top management

Memory trick: 'DPO = Data's Personal Officer' guarding privacy for regulators.

More Governance, Risk, Compliance and Security questions