Impact Assessments Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Impact Assessments flashcards as text
Under GDPR Article 35, which criterion ALONE is sufficient to trigger a mandatory Data Protection Impact Assessment?
Answer: Systematic and extensive profiling used to make significant decisions about individuals
GDPR Article 35 mandates a DPIA when processing involves systematic and extensive profiling used as the basis for decisions that significantly affect individuals.
A DPIA concludes that residual risk remains high after all mitigations are applied. What is the required next step under GDPR?
Answer: Consult with the supervisory authority before proceeding
When residual risk remains high after mitigation, GDPR Article 36 requires mandatory prior consultation with the competent supervisory authority.
Which element distinguishes a Privacy Impact Assessment (PIA) from a general risk assessment?
Answer: A PIA specifically evaluates risks to individuals' privacy rights and freedoms
A PIA specifically evaluates how a project or system affects the privacy rights and freedoms of individuals, not just organizational or financial risk.
During a DPIA, what is the primary purpose of consulting with the Data Protection Officer (DPO)?
Answer: To seek independent advice on compliance and risk mitigation
The DPO provides independent expert advice on whether the DPIA is conducted correctly and whether residual risks are acceptable.
A company plans to introduce employee monitoring software that tracks keystrokes and screenshots. Which impact assessment consideration is MOST critical?
Answer: Whether the monitoring is proportionate to the stated legitimate purpose
Proportionality is a core privacy principle; the intrusiveness of keystroke/screenshot monitoring must be weighed against the legitimate business purpose it serves.
In the context of a DPIA, what does 'necessity and proportionality' assessment require an organization to demonstrate?
Answer: That the processing is limited to what is strictly needed to achieve the specified purpose
Necessity and proportionality require showing that no less privacy-invasive means could achieve the same purpose and that data collection is not excessive.
Which scenario would most likely require a DPIA under GDPR's 'large-scale processing' criterion?
Answer: A national hospital network processing health data of patients across an entire country
GDPR's WP29 guidance identifies national-scale health data processing as a clear example of 'large-scale' that triggers a mandatory DPIA.