According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?
When a project includes technologies or processes that use personal data. Incorrect. Only for technologies and processes that are likely to result in a high risk to the rights of data subjects is the DPIA mandatory.
When processing is likely to result in a high risk to the rights of data subjects. Correct. For processing operations which are likely to result in a high risk, a DPIA is obligatory to assess those risks and to design mitigation measures. (Literature: A, Chapter 6; GDPR Article 35)
When similar processing operations with comparable risks are repeated. Incorrect. This is a case in which a DPIA does not need to be repeated.
Jade
5 months agoLindsey
5 months agoDanica
5 months agoTawny
6 months agoNiesha
6 months agoNu
6 months agoCassandra
6 months agoNovella
6 months agoGarry
6 months agoLoise
6 months agoTeri
6 months agoCherry
6 months agoCristen
6 months agoMalinda
6 months agoDorsey
6 months agoFarrah
6 months agoJettie
6 months agoJeanice
7 months agoKing
7 months agoNikita
7 months agoJunita
7 months agoFlorinda
7 months ago