Question 1 of 30
\"Globex Enterprises, a multinational corporation headquartered in Germany, is migrating its customer relationship management (CRM) data, which contains Personally Identifiable Information (PII) of EU citizens, to a cloud service provider (CSP) based in a country that does not have an adequacy decision from the European Commission under GDPR. Globex is implementing ISO 27018 controls to manage privacy risks associated with cloud services. The CSP is not part of the Globex corporate group. To ensure compliance with GDPR requirements for international data transfers, which of the following mechanisms should Globex primarily implement, considering the CSP\'s location and its external relationship to Globex, to legitimize the transfer of PII while adhering to ISO 27018 guidelines for data protection in the cloud?\"
Implement Standard Contractual Clauses (SCCs) with the cloud service provider, incorporating ISO 27018 controls as contractual obligations.
Rely on obtaining explicit consent from each data subject for the specific data transfer to the cloud service provider.
Establish Binding Corporate Rules (BCRs) applicable to Globex and require the cloud service provider to adhere to them.
Utilize the Privacy Shield framework for data transfers to the cloud service provider.