PDPF · Question #136
According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?
The correct answer is B. When processing is likely to result in a high risk to the rights of data subjects. When a project includes technologies or processes that use personal data. Incorrect. Only for technologies and processes that are likely to result in a high risk to the rights of data subjects is the When processing is likely to result in a high risk to the rights of data…
Question
According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?
Options
- AWhen a project includes technologies or processes that use personal data
- BWhen processing is likely to result in a high risk to the rights of data subjects
- CWhen similar processing operations with comparable risks are repeated
How the community answered
(17 responses)- A6% (1)
- B88% (15)
- C6% (1)
Explanation
When a project includes technologies or processes that use personal data. Incorrect. Only for technologies and processes that are likely to result in a high risk to the rights of data subjects is the When processing is likely to result in a high risk to the rights of data subjects. Correct. For processing operations which are likely to result in a high risk, a DPIA is obligatory to assess those risks and to design mitigation measures. (Literature: A, Chapter 6; GDPR Article 35) When similar processing operations with comparable risks are repeated. Incorrect. This is a case in which a DPIA does not need to be repeated.
Topics
Community Discussion
No community discussion yet for this question.