Article 35(3) specifically requires a DPIA for:
- A.All marketing activities, citing Article 28(2), which permits a processor to engage a sub-processor without the controller's prior authorisation wherever the sub-processor is inside the Union
- B.Systematic and extensive evaluation of personal aspects based on automated processing, large-scale processing of special categories, or systematic monitoring of publicly accessible areas
- C.Only online data collection
- D.Only employee monitoring
Why B is correct
Article 35(3) lists three specific cases: systematic/extensive profiling with significant effects, large-scale special category processing, and large-scale public area monitoring.
Know someone studying for GDPR? Send them this one.