A healthcare organization is planning to implement a new city-wide patient portal that uses AI to predict potential health risks based on consolidated electronic health records. According to GDPR Article 35, a Data Protection Impact Assessment (DPIA) is mandatory. After conducting the DPIA, the privacy engineering team concludes that the processing would result in a high risk to patients' rights and freedoms, and they are unable to identify sufficient mitigating measures. What is the required next step?
-
A
Proceed with the project but implement continuous monitoring and auditing.
-
B
Consult the supervisory authority prior to commencing the processing.
-
C
Archive the DPIA report and seek an external legal opinion.
-
D
Obtain explicit consent from all potential data subjects before launch.