nerdexam
IAPP

CIPP-E · Question #110

In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?

The correct answer is B. When personal data is being collected and combined with other personal data to profile the. According to the GDPR, a data protection impact assessment (DPIA) is a process to help identify and minimize the data protection risks of a project. A DPIA is required when the processing is likely to result in a high risk to the rights and freedoms of natural persons, taking…

Compliance with European Data Protection Law

Question

In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?

Options

  • AWhen the controller is collecting email addresses from individuals via an online registration form
  • BWhen personal data is being collected and combined with other personal data to profile the
  • CWhen the controller is required to have a Data Protection Officer.
  • DWhen personal data is being transferred outside of the EEA.

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    72% (13)
  • C
    6% (1)
  • D
    17% (3)

Explanation

According to the GDPR, a data protection impact assessment (DPIA) is a process to help identify and minimize the data protection risks of a project. A DPIA is required when the processing is likely to result in a high risk to the rights and freedoms of natural persons, taking into account the nature, scope, context and purposes of the processing. The GDPR provides a list of examples of processing operations that require a DPIA, such as: Systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person. Processing on a large scale of special categories of data or of personal data relating to criminal convictions and offences. Systematic monitoring of a publicly accessible area on a large scale. Therefore, an example of a scenario where a controller is most likely required to undertake a DPIA is when personal data is being collected and combined with other personal data to profile the creditworthiness of individuals, as this involves a systematic and extensive evaluation of personal aspects based on automated processing and profiling, and may have significant effects on the individuals.

Topics

#DPIA#Article 35#profiling#high risk processing

Community Discussion

No community discussion yet for this question.

Full CIPP-E Practice