← All CDPSE Flashcard Decks

Impact Assessments Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Impact Assessments flashcards as text
  1. An organization transfers personal data to a country lacking an EU adequacy decision. How does this affect the DPIA process?

    Answer: The transfer must be assessed as an additional risk factor within the DPIA

    International transfers without adequacy decisions introduce additional legal and operational risks that must be identified and addressed as part of the DPIA's risk assessment.

  2. In an Algorithmic Impact Assessment (AIA), what is the primary focus beyond standard privacy risk?

    Answer: Evaluating fairness, bias, and discriminatory outcomes for affected individuals

    An AIA extends privacy impact analysis to include fairness, bias, and whether the algorithm produces discriminatory outcomes that could violate individuals' rights.

  3. Which privacy impact assessment approach requires organizations to consult with actual data subjects or their representatives?

    Answer: A participatory PIA that includes stakeholder consultation

    Participatory PIAs seek input from data subjects or their representatives to ensure real-world impacts on individuals are captured, not just theoretical risks.

  4. A health-tech startup processes de-identified patient data for research. Under what condition must a DPIA still be considered?

    Answer: If re-identification risk remains non-trivial given available auxiliary data

    If there is a realistic risk of re-identification using available data linkage techniques, the data may still qualify as personal data and a DPIA may be required.

  5. What distinguishes a 'screening' phase from a 'full DPIA' in a two-stage impact assessment methodology?

    Answer: The screening phase determines whether the processing meets the threshold to require a full DPIA

    A screening or threshold assessment evaluates whether the proposed processing is likely to result in high risk, which then triggers the obligation to conduct a full DPIA.

  6. Which metric is MOST appropriate for measuring the severity of privacy harm in an impact assessment?

    Answer: Degree of impact on individuals' ability to exercise their rights and freedoms

    Severity in a privacy impact assessment is measured by the real-world effect on individuals — their dignity, autonomy, financial welfare, and ability to exercise their legal rights.

  7. A DPIA is completed for a new CRM system. Two years later, the organization adds an AI-driven lead scoring module. What action is required?

    Answer: Review and update the existing DPIA to capture the new risks introduced by the AI module

    A material change in processing — such as adding AI-driven profiling — requires revisiting and updating the DPIA to ensure all new risks are assessed.