nerdexam
Isaca

CDPSE · Question #142

Which of the following scenarios should trigger the completion of a privacy impact assessment (PIA)?

The correct answer is B. New inter-organizational data flows. A Privacy Impact Assessment (PIA) is triggered when new or significantly changed personal data processing activities are introduced - particularly when they introduce new privacy risks. New inter-organizational data flows represent exactly this: personal data is being shared…

Privacy Governance

Question

Which of the following scenarios should trigger the completion of a privacy impact assessment (PIA)?

Options

  • AUpdates to data quality standards
  • BNew inter-organizational data flows
  • CNew data retention and backup policies
  • DUpdates to the enterprise data policy

How the community answered

(46 responses)
  • A
    13% (6)
  • B
    78% (36)
  • C
    7% (3)
  • D
    2% (1)

Explanation

A Privacy Impact Assessment (PIA) is triggered when new or significantly changed personal data processing activities are introduced - particularly when they introduce new privacy risks. New inter-organizational data flows represent exactly this: personal data is being shared with or received from another organization, creating new exposure, legal obligations, and risk surfaces that must be assessed. Updates to data quality standards (A), retention and backup policies (C), and enterprise data policies (D) are governance or administrative updates that do not introduce a new data processing activity requiring a PIA. The PIA is concerned with how, where, and with whom personal data flows - not internal policy housekeeping.

Topics

#Privacy Impact Assessment (PIA)#PIA Triggers#Data Sharing#Risk Management

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice