ExamGecko
Home Home / IAPP / CIPM
Question list
Search
Search

List of questions

Search

Related questions











Question 109 - CIPM discussion

Report
Export

Under the General Data Protection Regulation (GDPR), which situation would be LEAST likely to require a Data Protection Impact Assessment (DPIA)?

A.

A health clinic processing its patients' genetic and health data

Answers
A.

A health clinic processing its patients' genetic and health data

B.

The use of a camera system to monitor driving behavior on highways

Answers
B.

The use of a camera system to monitor driving behavior on highways

C.

A Human Resources department using a tool to monitor its employees' internet activity

Answers
C.

A Human Resources department using a tool to monitor its employees' internet activity

D.

An online magazine using a mailing list to send a generic daily digest to marketing emails

Answers
D.

An online magazine using a mailing list to send a generic daily digest to marketing emails

Suggested answer: D

Explanation:

A Data Protection Impact Assessment (DPIA) is a process to help identify and minimize the data protection risks of a project. Under the GDPR, a DPIA is required when the processing is likely to result in a high risk to the rights and freedoms of individuals, especially when using new technologies. The GDPR provides some examples of high-risk processing activities, such as systematic and extensive evaluation of personal aspects, large-scale processing of special categories of data, or systematic monitoring of public areas. The other options are more likely to require a DPIA than the online magazine using a mailing list to send a generic daily digest to marketing emails, as they involve more sensitive or intrusive types of processing.Reference:

[Data protection impact assessments | ICO]

[Art. 35 GDPR -- Data protection impact assessment - GDPR.eu]

asked 22/11/2024
Nandor Gombos
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first