GDPR Practice Question: Article 35(3) specifically requires a DPIA for: | CyberCertPrep
EUGDPRDpo GovernanceEASYFree question
Article 35(3) specifically requires a DPIA for:
A.All marketing activities
B.Only employee monitoring
C.Only online data collection
D.Systematic and extensive evaluation of personal aspects based on automated processing, large-scale processing of special categories, or systematic monitoring of publicly accessible areas
Why D is correct
Article 35(3) lists three specific cases: systematic/extensive profiling with significant effects, large-scale special category processing, and large-scale public area monitoring.
Know someone studying for GDPR? Send them this one.
Where this fits in the GDPR exam
Dpo Governance
Covers dpo governance concepts and practices within GDPR.
This question belongs to the "Controller & Processor Obligations" domain, which makes up about 20% of the GDPR exam.
CyberCertPrep gives you 20 free GDPR questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
GDPR and EU are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by EU or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
A Data Protection Impact Assessment (DPIA) must be carried out when processing is likely to result in: