Certified Information Privacy Professional CIPPE · Free Practice Question Easy
Question 6
When should an organization complete a Data Protection Impact Assessment under the GDPR?
-
A
When it is processing personal data on the basis of a legal obligation
-
B
When it uses a mailing list to send a newsletter to customers
-
C
Where an organization has completed a substantially similar DPIA
- D When it creates an automated process to record employee personal data
Reveal correct answer
Correct answer: D
Explanation
A DPIA is required as the organization is using new technological solution to process data of vulnerable data subjects(employees).
Article 35(3) sets out three types of processing which always require a DPIA: Systematic and extensive profiling with significant effects, Large scale use of sensitive data and Public monitoring. The Article 29 working party of EU data protection authorities (WP29) published guidelines with nine criteria which may act as indicators of likely high risk processing:
1Evaluation or scoring
2Automated decision-making with legal or similar significant effect
3Systematic monitoring Sensitive data or data of a highly personal nature
4Data processed on a large scale. Matching or combining datasets
5Data concerning vulnerable data subjects
6Innovative use or applying new technological or organisational solutions
7Preventing data subjects from exercising a right or using a service or contract
In most cases, a combination of two of these factors indicates the need for a DPIA. However, this is not a strict rule. In some cases, a DPIA may be required if only one factor is present
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
