nerdexam
EXIN

PDPF · Question #136

According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?

The correct answer is B. When processing is likely to result in a high risk to the rights of data subjects. When a project includes technologies or processes that use personal data. Incorrect. Only for technologies and processes that are likely to result in a high risk to the rights of data subjects is the When processing is likely to result in a high risk to the rights of data…

Privacy by Design and by Default

Question

According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?

Options

  • AWhen a project includes technologies or processes that use personal data
  • BWhen processing is likely to result in a high risk to the rights of data subjects
  • CWhen similar processing operations with comparable risks are repeated

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    88% (15)
  • C
    6% (1)

Explanation

When a project includes technologies or processes that use personal data. Incorrect. Only for technologies and processes that are likely to result in a high risk to the rights of data subjects is the When processing is likely to result in a high risk to the rights of data subjects. Correct. For processing operations which are likely to result in a high risk, a DPIA is obligatory to assess those risks and to design mitigation measures. (Literature: A, Chapter 6; GDPR Article 35) When similar processing operations with comparable risks are repeated. Incorrect. This is a case in which a DPIA does not need to be repeated.

Topics

#DPIA#high risk processing#Article 35#risk assessment

Community Discussion

No community discussion yet for this question.

Full PDPF Practice