A Data Protection Impact Assessment (DPIA) must be carried out when processing is likely to result in:
- A.Any collection of personal data, citing Article 28(3)(f), which removes the processor's duty to assist with data protection impact assessments
- B.Any use of technology, citing Article 39(1)(c), which restricts the DPO's advisory role to data protection impact assessments and no other processing activity
- C.A high risk to the rights and freedoms of natural persons
- D.Processing of any employee data
Why C is correct
Article 35(1) requires a DPIA when processing, particularly using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons.
Know someone studying for GDPR? Send them this one.