Digital SkillsHard

An agent of the European Union Delegation in a third country is managing a digital cooperation mission. During an internal audit, it is detected that the communication system used by the mission transmitted personal data of EU citizens to a cloud server located outside the EU, without an adequate transfer mechanism. The agent argues that, given that the mission operates under the mandate of the European External Action Service (EEAS) and its objective is to promote human rights and sustainable development, the data protection principles of the General Data Protection Regulation (GDPR) do not apply in the same way as to EU institutions established in Brussels. Based on EU law and the mandate of the EEAS, what is the correct assessment of the situation and the applicable legal framework?

Want adaptive practice that measures your real level?

Start free preparation →

More Digital Skills questions

A digital project officer for the European External Action S...You are a digital communications officer for the European Ex...An EU delegation member needs to securely share a document c...As a digital security officer for an EU delegation participa...A junior diplomat in the European External Action Service (E...