nerdexam
IAPP

CIPM · Question #286

Under Article 35 of the GDPR, a data controller must take a risk-based approach to determine whether to complete?

The correct answer is D. Data Protection Impact Assessment (DPIA). See the full explanation below for the reasoning.

Question

Under Article 35 of the GDPR, a data controller must take a risk-based approach to determine whether to complete?

Options

  • APrivacy program review.
  • BPrivacy threshold assessment.
  • CTransfer Impact Assessment (TIA).
  • DData Protection Impact Assessment (DPIA).

How the community answered

(63 responses)
  • A
    5% (3)
  • B
    6% (4)
  • C
    14% (9)
  • D
    75% (47)

Community Discussion

No community discussion yet for this question.

Full CIPM Practice