A financial services company is developing a new mobile application that will use customer transaction data to provide personalized investment recommendations using an AI-powered algorithm. According to GDPR Article 35, which of the following is the MOST critical first step in the privacy risk management process for this new application?
-
A
Conducting a vendor security assessment of the AI algorithm provider.
-
B
Developing an incident response plan for potential data breaches.
-
C
Performing a Data Protection Impact Assessment (DPIA).
-
D
Obtaining explicit user consent for data processing via a pop-up.