Question 1 of 30
Agnes runs a rapidly growing e-commerce business specializing in personalized gift items. Her company collects a wide range of customer data, including names, addresses, purchase history, and personalized message preferences. To streamline operations and enhance customer experience, Agnes outsources her customer support and order fulfillment to two separate third-party companies. According to ISO 29100:2011, which role does Agnes\'s company primarily fulfill, and what are her core responsibilities concerning the personal data collected from her customers? Consider the obligations related to defining processing purposes, ensuring regulatory compliance, and maintaining transparency with data subjects.
Agnes's company acts as the data controller, bearing primary responsibility for defining the purposes and means of processing customer data, ensuring compliance with privacy regulations, and maintaining transparency with data subjects regarding their rights and data usage.
Agnes's company is a data processor, responsible solely for executing the data processing instructions provided by the third-party customer support and order fulfillment companies, with limited accountability for data protection.
Agnes's company operates as a data subject, possessing rights over the personal data collected, but lacking direct responsibility for defining processing purposes or ensuring regulatory compliance, as these tasks are delegated to the outsourced companies.
Agnes's company functions as a data custodian, primarily responsible for the secure storage and maintenance of customer data, while the third-party companies handle all aspects of data processing and regulatory compliance, relieving Agnes of any privacy-related obligations.

Preparing for ISO 14040:2006 Lead Implementer? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free