Which of the following is TRUE about the Data Protection Impact Assessment (DPIA) process as required under the General Data Protection Regulation (GDPR)?
A.
The DPIA result must be reported to the corresponding supervisory authority.
B.
The DPIA report must be published to demonstrate the transparency of the data processing.
C.
The DPIA must include a description of the proposed processing operation and its purpose.
D.
The DPIA is required if the processing activity entails risk to the rights and freedoms of an EU individual.
C. The DPIA must include a description of the proposed processing operation and its purpose.
The GDPR requires that a DPIA contain "a systematic description of the envisaged processing operations and the purposes of the processing" as one of its key elements. This is clearly stated in Article 35 of the GDPR which outlines the requirements for conducting a DPIA.
For D,The DPIA is specifically required when the data processing is "likely to result in a high risk to the rights and freedoms of natural persons", not just if there is any risk involved.
upvoted 4 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Dhrumal
3 weeks, 4 days agoRocketly
4 months, 4 weeks agothecheaterz
6 months, 2 weeks agoxBowseRx
7 months, 2 weeks ago