All RE5 questions
POPIA Data Protection Privacy
An FSP stores its client files with a cloud provider. The provider is hacked and clients' identity numbers and bank details are exposed. Which statement reflects the Protection of Personal Information Act?
RE5 practice question with a worked answer. This is one of hundreds of FSCA RE5 questions in the RegulatoryExams question bank.
- a) The FSP remains accountable as responsible party, and must notify the Information Regulator and the affected clients.Correct
- b) The cloud provider alone is accountable, because the information was in its possession when the breach occurred.
- c) The FSP is accountable only if its contract with the cloud provider says so.
- d) Nobody need be notified unless a client can show that he suffered a financial loss.
Why this is the answer
The FSP decides why and how client information is processed, so it is the responsible party; the cloud provider is an operator processing on its behalf under a written contract. The responsible party stays accountable for security, and where there are reasonable grounds to believe personal information has been accessed by an unauthorised person, it must notify the Information Regulator and the data subjects as soon as reasonably possible.
Want to test yourself on 700+ more questions like this?
Start your free RE5 simulator today — timed mock exams, full answer explanations and cloud-synced progress tracking.