IAPP CIPM Question Answer
MULTI-SELECT – Select 3
A multinational manufacturing company is considering outsourcing its HR data processing to a third-party vendor based in a country with less strict data protection laws. The company has a large database of employee information, including personal and sensitive data such as national ID numbers, medical information and employment contracts. The third-party vendor has a reputation for providing cost-effective services and has assured the company that it can handle the data securely.
The data protection officer (DPO) should ensure which of the following contractual requirements are included in the agreement with the third-party vendor?

