Impact Assessments Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Impact Assessments flashcards as text
When should a DPIA ideally be initiated in the system development lifecycle?
Answer: Before processing begins, during the design phase
A DPIA should be conducted early in the design phase so privacy risks can be addressed before systems are built, not retrofitted.
A DPIA identifies a risk that cannot be mitigated using current technology. What should the organization document in the DPIA report?
Answer: The unmitigated risk, the reasoning for acceptance, and senior management sign-off
Accepted residual risks must be documented along with the justification and evidence of senior accountability for the decision.
Under the NIST Privacy Framework, which function specifically covers the assessment of privacy risks to individuals?
Answer: Identify
The NIST Privacy Framework's 'Identify' function includes the 'Risk Assessment' category, where organizations assess privacy risks to individuals from data processing.
A third-party vendor will process personal data on behalf of your organization. Who bears primary responsibility for ensuring a DPIA is completed?
Answer: The controller (your organization), as the entity determining the purpose of processing
Under GDPR, the controller determines the purpose and means of processing and therefore holds primary responsibility for conducting a DPIA.
What is the role of 'likelihood' in calculating privacy risk during an impact assessment?
Answer: It estimates how probable it is that a threat will actually materialize and cause harm
Risk = Likelihood × Severity; likelihood estimates the probability that a given threat will exploit a vulnerability and result in harm to individuals.
Which of the following is a correct statement about DPIA records retention?
Answer: DPIAs should be retained and updated throughout the lifecycle of the processing activity
DPIAs are living documents that should be maintained and revised whenever the processing activity changes or new risks emerge.
A new mobile app will use biometric data for authentication. What makes this scenario particularly significant from a DPIA perspective?
Answer: Biometric data is a special category under GDPR requiring heightened protection
Biometric data used for unique identification is classified as a special category under GDPR Article 9, which imposes stricter processing conditions and heightens the need for a DPIA.