Certified Information Privacy Professional – United States (CIPP/US) — Question 181

In a data sharing arrangement, which of the following organizations would determine the rules that apply to the processing of the data being shared?

Answer options

Correct answer: D

Explanation

The data controller is the organization that determines the purposes and means of processing personal data, thus setting the rules for data handling. The business associate, hosting provider, and data processor do not have the authority to set these rules; they must follow the guidelines established by the data controller.