A hospital privacy officer is implementing an AI feature that analyzes patient symptom descriptions to suggest potential diagnoses. When is a DPIA most clearly required?
- A.Only if the system processes data of more than 10,000 patients in the first month
- B.Only after the system goes live, once actual processing volumes are known
- C.Before deployment, because the system systematically processes special category health data at scale with automated decision-making implications
- D.Only if the system transmits data to a cloud provider outside the hospital's jurisdiction
Why C is correct
Processing health data (a special category under GDPR Article 9) at scale with automated decision-support implications is exactly the scenario requiring a prior DPIA per Article 35. The assessment must occur BEFORE deployment, not after. Patient count thresholds are not defined in GDPR - "large scale" is assessed contextually. Cross-border transfer triggers separate obligations but is not the only DPIA trigger for this scenario.
Know someone studying for AI Security Fundamentals? Send them this one.