GDPR Practice Question: A Data Protection Impact Assessment (DPIA) must be carried out when... | CyberCertPrep
EUGDPRDpo GovernanceEASYFree question
A Data Protection Impact Assessment (DPIA) must be carried out when processing is likely to result in:
A.Any collection of personal data
B.Processing of any employee data
C.A high risk to the rights and freedoms of natural persons
D.Any use of technology
Why C is correct
Article 35(1) requires a DPIA when processing, particularly using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons.
Know someone studying for GDPR? Send them this one.
Where this fits in the GDPR exam
Dpo Governance
Covers dpo governance concepts and practices within GDPR.
This question belongs to the "Controller & Processor Obligations" domain, which makes up about 20% of the GDPR exam.
CyberCertPrep gives you 20 free GDPR questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
GDPR and EU are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by EU or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.