ExamGecko
Home Home / IAPP / CIPM
Question list
Search
Search

List of questions

Search

Related questions











Question 123 - CIPM discussion

Report
Export

A minimum requirement for carrying out a Data Protection Impact Assessment (DPIA) would include?

A.

Processing on a large scale of special categories of data.

Answers
A.

Processing on a large scale of special categories of data.

B.

Monitoring of a publicly accessible area on a large scale.

Answers
B.

Monitoring of a publicly accessible area on a large scale.

C.

Assessment of the necessity and proportionality.

Answers
C.

Assessment of the necessity and proportionality.

D.

Assessment of security measures.

Answers
D.

Assessment of security measures.

Suggested answer: A

Explanation:

Processing on a large scale of special categories of data is a minimum requirement for carrying out a Data Protection Impact Assessment (DPIA) under the General Data Protection Regulation (GDPR). A DPIA is a type of Privacy Impact Assessment (PIA) that is specifically required by the GDPR when a processing activity is likely to result in a high risk to the rights and freedoms of natural persons. According to Article 35(3)(b) of the GDPR, a DPIA is mandatory when the processing involves a large scale of special categories of data or personal data relating to criminal convictions and offences. Special categories of data are personal data that reveal racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation. These types of data are considered more sensitive and require more protection, as they may pose higher risks of discrimination, identity theft, fraud, or other harms to the data subjects.

CIPM Body of Knowledge (2021), Domain IV: Privacy Program Operational Life Cycle, Section C: Monitoring and Managing Program Performance Subsection 1: Privacy Impact Assessments

CIPM Study Guide (2021), Chapter 9: Monitoring and Managing Program Performance Section 9.1: Privacy Impact Assessments

CIPM Textbook (2019), Chapter 9: Monitoring and Managing Program Performance Section 9.1: Privacy Impact Assessments

CIPM Practice Exam (2021), Question 147

GDPR Article 35(3)(b) and Article 9

asked 22/11/2024
Johan Benavides
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first