Learn GDPR data processing vocabulary: DPA structure, data controller vs. processor, sub-processors, Standard Contractual Clauses (SCCs), and transfer impact assessments.
0 / 10 completed
1 / 10
Under GDPR, a company uses Salesforce CRM to store its customers' personal data. Salesforce processes the data only as instructed by the company. In this relationship, which role does each party hold?
The data controller determines the purposes and means of processing personal data (the company decides why and how customer data is stored). The data processor processes personal data on behalf of the controller and only under its documented instructions (Salesforce executes those instructions). GDPR Article 28 requires a Data Processing Agreement (DPA) between them.
2 / 10
A SaaS vendor's DPA mentions that it may engage AWS and Twilio to deliver its service, and that the customer's prior written consent is required before adding new ones. What are AWS and Twilio in this context?
A sub-processor is a third party engaged by the data processor to carry out processing activities on behalf of the controller. Under GDPR Article 28(2), the processor must obtain the controller's authorisation before engaging sub-processors. The DPA typically lists current sub-processors and establishes a notification mechanism (e.g., 30-day notice) for new ones.
3 / 10
After the Schrems II ruling invalidated the EU-US Privacy Shield, EU companies needed a new legal mechanism for transferring personal data to the US. What mechanism — updated by the European Commission in 2021 — is now most widely used for this purpose?
Standard Contractual Clauses (SCCs) are pre-approved contractual templates issued by the European Commission that provide appropriate safeguards for data transfers to third countries (GDPR Article 46(2)(c)). The 2021 SCCs replaced the outdated 2001/2010 versions and introduced a modular structure covering controller-to-controller, controller-to-processor, and processor-to-processor transfers.
4 / 10
Before transferring EU personal data to a country without an adequacy decision, a company must assess local laws that might undermine the transfer safeguards (e.g., government surveillance laws). What is this assessment called?
A Transfer Impact Assessment (TIA) — sometimes called a Transfer Risk Assessment — evaluates whether the legal framework of the destination country effectively protects the data as required by GDPR. It was made mandatory by the EDPB following Schrems II. The assessment examines laws on access by public authorities, available remedies for data subjects, and the practical likelihood of interference.
5 / 10
A DPA clause states: 'Processor shall implement appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk, including pseudonymisation and encryption of personal data.' What does 'pseudonymisation' mean in a GDPR context?
Pseudonymisation (GDPR Article 4(5)) means replacing directly identifying information (e.g., name, email) with a pseudonym (e.g., a token or hash), while storing the key that links pseudonym to identity separately and securely. Unlike anonymisation, pseudonymised data is still personal data under GDPR — it just has enhanced protection. It is a recommended technical measure under Article 25 (Data Protection by Design).
6 / 10
John, a junior developer, is reviewing a PR that uses the stripe.js library to process payments. The PRD mentions a Data Processing Agreement (DPA) with Stripe. Which of the following best describes the primary purpose of the DPA in this scenario?
The DPA is a legal document that governs the relationship between data controllers (your company) and data processors (Stripe). Its core purpose is to define the terms of processing personal data – in this case, financial information – ensuring compliance with regulations like GDPR. Option A focuses on debugging, which is part of development but not the DPA's primary function; options C & D are technical specifications or access details.
7 / 10
You're a DevOps engineer responding to a Slack message from the legal team. The message states: 'We need to ensure our DPA with CloudCorp includes robust data localization clauses given recent regulatory changes.' What does 'data localization' typically refer to in the context of a DPA?
Data localization is a critical element of many DPAs, particularly when dealing with GDPR. It dictates where personal data must be processed and stored – often requiring it to remain within specific geographic regions (like the EU) to maintain control and comply with regulations regarding access and transfer. Option A is too strict; option C relates to security protocols and option D defines processing activities.
8 / 10
During a standup meeting, your team lead asks: 'What's the difference between 'pseudonymisation' and 'anonymisation' when discussing TOMs in our DPA?'. Which statement best describes the distinction?
The key difference lies in reversibility. Anonymisation irreversibly removes identifiers, rendering the data truly anonymous and unlinkable. Pseudonymisation replaces identifying information with pseudonyms, allowing for potential re-identification if the keys or identifiers are recovered – it's a *reversible* process. Option C is incorrect; option D misrepresents the roles of technical measures and legal requirements.
9 / 10
You are drafting a PR description for a change that updates your company's Data Processing Agreement with DataSolutions. The new DPA includes a clause about 'data subject rights'. What does this term primarily relate to?
'Data subject rights' is a core concept in GDPR and other privacy regulations. It refers to the fundamental legal entitlements individuals possess regarding their personal data – including the right to access, correct, delete, or limit how their data is processed. Options A & C are related to enforcement/technical aspects; option D describes an audit process.
10 / 10
A colleague sends you a code review comment on a file transfer script: 'Ensure the implementation of appropriate Technical and Organisational Measures (TOMs) aligns with Article 32 of GDPR to protect personal data in transit.' What does 'in transit' specifically refer to within this context?
'In transit' refers to the phase of data transfer. GDPR requires specific safeguards (like encryption) to be applied *during* this movement – when the data is travelling between systems or locations via networks – to protect it from interception and unauthorized access. Options A & D are broader stages; option C limits the scope to storage only.
What will I practise in "Data Processing Agreement Vocabulary"?
Learn GDPR data processing vocabulary: DPA structure, data controller vs. processor, sub-processors, Standard Contractual Clauses (SCCs), and transfer impact assessments.
How many exercises are in this module?
This module has 10 multiple-choice exercises, each with instant feedback and a full explanation of the correct answer.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account, sign-up, or paywall.
Do I need to create an account to do these exercises?
No account is required. Just click an option to answer — your score for this session is tracked automatically in the progress bar above.
What happens if I choose the wrong answer?
You'll immediately see which answer was correct, plus a full explanation covering the vocabulary and reasoning behind it — mistakes are where most of the learning happens.
Can I retry the exercises if I want a higher score?
Yes — use the "Try again" button on the results screen to reset and go through all the questions again.
Is my progress saved if I close the page?
No. Progress is tracked only for your current visit; reloading or leaving the page resets the counter. This keeps the exercise simple and account-free.
Where can I find more Legal Contracts exercises?
Browse the full Legal Contracts hub for related drills, or check the "Next up" link below to continue with a connected topic.
How is this different from reading an article on the same topic?
Articles explain vocabulary and concepts in prose; this exercise tests and reinforces that vocabulary through active recall with immediate feedback — the two work best together.
Who writes these exercises?
Every exercise is written by the CoderSlingo team, drawing on real workplace English used in IT roles, then reviewed for accuracy and clarity.