โ† All CDPSE Flashcard Decks

Impact Assessments Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Impact Assessments flashcards as text
  1. Under GDPR Article 35, which criterion ALONE is sufficient to trigger a mandatory Data Protection Impact Assessment?

    Answer: Systematic and extensive profiling used to make significant decisions about individuals

    GDPR Article 35 mandates a DPIA when processing involves systematic and extensive profiling used as the basis for decisions that significantly affect individuals.

  2. A DPIA concludes that residual risk remains high after all mitigations are applied. What is the required next step under GDPR?

    Answer: Consult with the supervisory authority before proceeding

    When residual risk remains high after mitigation, GDPR Article 36 requires mandatory prior consultation with the competent supervisory authority.

  3. Which element distinguishes a Privacy Impact Assessment (PIA) from a general risk assessment?

    Answer: A PIA specifically evaluates risks to individuals' privacy rights and freedoms

    A PIA specifically evaluates how a project or system affects the privacy rights and freedoms of individuals, not just organizational or financial risk.

  4. During a DPIA, what is the primary purpose of consulting with the Data Protection Officer (DPO)?

    Answer: To seek independent advice on compliance and risk mitigation

    The DPO provides independent expert advice on whether the DPIA is conducted correctly and whether residual risks are acceptable.

  5. A company plans to introduce employee monitoring software that tracks keystrokes and screenshots. Which impact assessment consideration is MOST critical?

    Answer: Whether the monitoring is proportionate to the stated legitimate purpose

    Proportionality is a core privacy principle; the intrusiveness of keystroke/screenshot monitoring must be weighed against the legitimate business purpose it serves.

  6. In the context of a DPIA, what does 'necessity and proportionality' assessment require an organization to demonstrate?

    Answer: That the processing is limited to what is strictly needed to achieve the specified purpose

    Necessity and proportionality require showing that no less privacy-invasive means could achieve the same purpose and that data collection is not excessive.

  7. Which scenario would most likely require a DPIA under GDPR's 'large-scale processing' criterion?

    Answer: A national hospital network processing health data of patients across an entire country

    GDPR's WP29 guidance identifies national-scale health data processing as a clear example of 'large-scale' that triggers a mandatory DPIA.