Certified Information Privacy Professional CIPPE · Free Practice Question Easy

Question 6

When should an organization complete a Data Protection Impact Assessment under the GDPR?

  • A

    When it is processing personal data on the basis of a legal obligation

  • B

    When it uses a mailing list to send a newsletter to customers

  • C

    Where an organization has completed a substantially similar DPIA


  • D When it creates an automated process to record employee personal data
Reveal correct answer

Correct answer: D

Explanation

A DPIA is required as the organization is using new technological solution to process data of vulnerable data subjects(employees).

Article 35(3) sets out three types of processing which always require a DPIA:  Systematic and extensive profiling with significant effects, Large scale use of sensitive data and Public monitoring.  The Article 29 working party of EU data protection authorities (WP29) published guidelines with nine criteria which may act as indicators of likely high risk processing:

1Evaluation or scoring

2Automated decision-making with legal or similar significant effect

3Systematic monitoring Sensitive data or data of a highly personal nature

4Data processed on a large scale. Matching or combining datasets

5Data concerning vulnerable data subjects

6Innovative use or applying new technological or organisational solutions

7Preventing data subjects from exercising a right or using a service or contract

In most cases, a combination of two of these factors indicates the need for a DPIA. However, this is not a strict rule.  In some cases, a DPIA may be required  if only one factor is present 

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need