CDPSE · Question #137
Which of the following should be done FIRST when a data collection process is deemed to be a high-level risk?
The correct answer is C. Conduct a privacy Impact assessment (PIA). When a data collection process is identified as high-risk, a Privacy Impact Assessment (PIA) must be conducted first. A PIA is a structured, systematic analysis that identifies what personal data is collected, why, how it is used, who has access, what risks exist, and what…
Question
Which of the following should be done FIRST when a data collection process is deemed to be a high-level risk?
Options
- APerform a business impact analysis (BIA).
- BImplement remediation actions to mitigate privacy risk.
- CConduct a privacy Impact assessment (PIA).
- DCreate a system of records notice (SORN).
How the community answered
(29 responses)- A3% (1)
- B10% (3)
- C69% (20)
- D17% (5)
Explanation
When a data collection process is identified as high-risk, a Privacy Impact Assessment (PIA) must be conducted first. A PIA is a structured, systematic analysis that identifies what personal data is collected, why, how it is used, who has access, what risks exist, and what mitigations are appropriate. It produces the evidence base needed to make informed decisions. Without completing a PIA, any remediation actions (B) would be uninformed and possibly misdirected. A Business Impact Analysis (A) focuses on operational continuity, not privacy risk. A System of Records Notice (D) is a U.S. federal government publication requirement that comes after the assessment and decision-making process, not before.
Topics
Community Discussion
No community discussion yet for this question.