exam questions

Exam CIPM All Questions

View all questions & answers for the CIPM exam

Exam CIPM topic 1 question 147 discussion

Actual exam question from IAPP's CIPM
Question #: 147
Topic #: 1
[All CIPM Questions]

A minimum requirement for carrying out a Data Protection Impact Assessment (DPIA) would include?

  • A. Processing on a large scale of special categories of data.
  • B. Monitoring of a publicly accessible area on a large scale.
  • C. Assessment of the necessity and proportionality.
  • D. Assessment of security measures.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
0ef35ef
14 hours, 40 minutes ago
Selected Answer: C
A is one of the scenarios that would trigger a DPIA, but it’s not the minimum requirement. The DPIA is necessary not just for special categories of data but whenever the processing is likely to result in high risks to individuals’ rights.
upvoted 1 times
...
Bhimesh
1 week, 6 days ago
Selected Answer: C
The GDPR sets out the minimum features of a DPIA: A description of the processing, including its purpose and the legitimate interest being pursued he necessity of the processing, its proportionality, and the risks that it poses to data subjects Measures to address the risks identified
upvoted 2 times
...
Vinz_
1 month ago
Selected Answer: C
It should be C. Necessity and proportionality is a minimum requirement because without the necessity of a DPIA, there is no point of proceeding with the assessment. See here for more details: Answer A is a scenario where a DPIA would be necessary, but it is not the only one, for instance a DPIA would still be necessary for sensitive data handled by a newly released system even when they are not in a large scale.
upvoted 2 times
...
DPRamone
5 months ago
Selected Answer: A
Assessment of necessty and proportionality (C) is required in a DPIA too, but would typically come AFTER identification and description of what you are processing.
upvoted 1 times
...
carlosbui
8 months, 2 weeks ago
should be A
upvoted 1 times
...
Ssourav
10 months, 3 weeks ago
Selected Answer: A
The correct answer is A. Processing on a large scale of special categories of data. A Data Protection Impact Assessment (DPIA) is a document that helps organizations to identify, assess, and mitigate the privacy risks associated with a new or changed processing activity. It is a requirement under the General Data Protection Regulation (GDPR) for certain types of processing activities, including the processing on a large scale of special categories of data.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago