CDPSE Impact Assessments 3 — Questions and Answers
Question 1: When should a DPIA ideally be initiated in the system development lifecycle?
- After the system has been deployed and user complaints are received
- Before processing begins, during the design phase (Correct answer)
- During the annual compliance audit cycle
- When a data breach has been reported to regulators
Correct answer: Before processing begins, during the design phase
A DPIA should be conducted early in the design phase so privacy risks can be addressed before systems are built, not retrofitted.
Question 2: A DPIA identifies a risk that cannot be mitigated using current technology. What should the organization document in the DPIA report?
- A plan to ignore the risk until better technology is available
- The unmitigated risk, the reasoning for acceptance, and senior management sign-off (Correct answer)
- Immediate termination of the project
- Transfer of the risk to the data processor via contract
Correct answer: The unmitigated risk, the reasoning for acceptance, and senior management sign-off
Accepted residual risks must be documented along with the justification and evidence of senior accountability for the decision.
Question 3: Under the NIST Privacy Framework, which function specifically covers the assessment of privacy risks to individuals?
- Protect
- Detect
- Identify (Correct answer)
- Respond
Correct answer: Identify
The NIST Privacy Framework's 'Identify' function includes the 'Risk Assessment' category, where organizations assess privacy risks to individuals from data processing.
Question 4: A third-party vendor will process personal data on behalf of your organization. Who bears primary responsibility for ensuring a DPIA is completed?
- The vendor, as the party physically handling the data
- The controller (your organization), as the entity determining the purpose of processing (Correct answer)
- The supervisory authority, since third parties are involved
- The data subjects, since they can withdraw consent
Correct answer: The controller (your organization), as the entity determining the purpose of processing
Under GDPR, the controller determines the purpose and means of processing and therefore holds primary responsibility for conducting a DPIA.
Question 5: What is the role of 'likelihood' in calculating privacy risk during an impact assessment?
- It measures the financial cost of a potential breach
- It estimates how probable it is that a threat will actually materialize and cause harm (Correct answer)
- It determines the number of data subjects affected
- It assesses the legal penalties applicable to the violation
Correct answer: It estimates how probable it is that a threat will actually materialize and cause harm
Risk = Likelihood × Severity; likelihood estimates the probability that a given threat will exploit a vulnerability and result in harm to individuals.
Question 6: Which of the following is a correct statement about DPIA records retention?
- DPIAs can be discarded once the processing activity ends
- DPIAs should be retained and updated throughout the lifecycle of the processing activity (Correct answer)
- DPIAs are confidential and must never be shared with supervisory authorities
- DPIAs only need to be retained for one year after completion
Correct answer: DPIAs should be retained and updated throughout the lifecycle of the processing activity
DPIAs are living documents that should be maintained and revised whenever the processing activity changes or new risks emerge.
Question 7: A new mobile app will use biometric data for authentication. What makes this scenario particularly significant from a DPIA perspective?
- Mobile apps are always exempt from GDPR requirements
- Biometric data is a special category under GDPR requiring heightened protection (Correct answer)
- Authentication data is not considered personal data
- The app stores data only locally on the device
Correct answer: Biometric data is a special category under GDPR requiring heightened protection
Biometric data used for unique identification is classified as a special category under GDPR Article 9, which imposes stricter processing conditions and heightens the need for a DPIA.
When should a DPIA ideally be initiated in the system development lifecycle?