nerdexam
EXIN

PDPF · Question #118

When is a Data Protection Impact Assessment (DPIA) under the General Data Protection Regulation (GDPR) mandatory?

The correct answer is A. Application of new technologies that may imply a high risk to the rights and freedoms of data. Whenever a new technology is applied, a DPIA must be performed. In addition, a DPIA must be performed before starting the processing of personal data. This is important to check for risks to data subjects since data collection. In its Article 35 the GDPR legislates on the…

Privacy by Design and by Default

Question

When is a Data Protection Impact Assessment (DPIA) under the General Data Protection Regulation (GDPR) mandatory?

Options

  • AApplication of new technologies that may imply a high risk to the rights and freedoms of data
  • BThere is no security policy and information security risk analysis.
  • CIn all types of personal data processing.

How the community answered

(43 responses)
  • A
    91% (39)
  • B
    7% (3)
  • C
    2% (1)

Explanation

Whenever a new technology is applied, a DPIA must be performed. In addition, a DPIA must be performed before starting the processing of personal data. This is important to check for risks to data subjects since data collection. In its Article 35 the GDPR legislates on the Impact assessment on data protection. 1. Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high

Topics

#DPIA#mandatory assessment#high risk processing#new technologies

Community Discussion

No community discussion yet for this question.

Full PDPF Practice