CDPSE Impact Assessments 4 — Questions and Answers
Question 1: An organization transfers personal data to a country lacking an EU adequacy decision. How does this affect the DPIA process?
- No additional steps are needed if standard contractual clauses are in place
- The transfer must be assessed as an additional risk factor within the DPIA (Correct answer)
- The DPIA is automatically invalid and must be restarted
- The supervisory authority must approve each individual transfer
Correct answer: The transfer must be assessed as an additional risk factor within the DPIA
International transfers without adequacy decisions introduce additional legal and operational risks that must be identified and addressed as part of the DPIA's risk assessment.
Question 2: In an Algorithmic Impact Assessment (AIA), what is the primary focus beyond standard privacy risk?
- Assessing the financial return on investment of the algorithm
- Evaluating fairness, bias, and discriminatory outcomes for affected individuals (Correct answer)
- Determining the algorithm's computational efficiency
- Reviewing intellectual property protection for the model
Correct answer: Evaluating fairness, bias, and discriminatory outcomes for affected individuals
An AIA extends privacy impact analysis to include fairness, bias, and whether the algorithm produces discriminatory outcomes that could violate individuals' rights.
Question 3: Which privacy impact assessment approach requires organizations to consult with actual data subjects or their representatives?
- A purely internal desk review
- A participatory PIA that includes stakeholder consultation (Correct answer)
- An automated compliance scan
- A post-implementation review conducted solely by IT
Correct answer: A participatory PIA that includes stakeholder consultation
Participatory PIAs seek input from data subjects or their representatives to ensure real-world impacts on individuals are captured, not just theoretical risks.
Question 4: A health-tech startup processes de-identified patient data for research. Under what condition must a DPIA still be considered?
- De-identification always removes the need for a DPIA
- If re-identification risk remains non-trivial given available auxiliary data (Correct answer)
- Only if the research involves more than 10,000 records
- Only if the data was originally collected by a hospital
Correct answer: If re-identification risk remains non-trivial given available auxiliary data
If there is a realistic risk of re-identification using available data linkage techniques, the data may still qualify as personal data and a DPIA may be required.
Question 5: What distinguishes a 'screening' phase from a 'full DPIA' in a two-stage impact assessment methodology?
- The screening phase is performed by external auditors only
- The screening phase determines whether the processing meets the threshold to require a full DPIA (Correct answer)
- The screening phase replaces the need for senior management review
- The screening phase focuses only on cybersecurity controls
Correct answer: The screening phase determines whether the processing meets the threshold to require a full DPIA
A screening or threshold assessment evaluates whether the proposed processing is likely to result in high risk, which then triggers the obligation to conduct a full DPIA.
Question 6: Which metric is MOST appropriate for measuring the severity of privacy harm in an impact assessment?
- Number of servers storing the data
- Degree of impact on individuals' ability to exercise their rights and freedoms (Correct answer)
- Total annual revenue of the processing organization
- Number of employees with data access
Correct answer: Degree of impact on individuals' ability to exercise their rights and freedoms
Severity in a privacy impact assessment is measured by the real-world effect on individuals — their dignity, autonomy, financial welfare, and ability to exercise their legal rights.
Question 7: A DPIA is completed for a new CRM system. Two years later, the organization adds an AI-driven lead scoring module. What action is required?
- No action, since the original DPIA covers all future modifications
- Review and update the existing DPIA to capture the new risks introduced by the AI module (Correct answer)
- Conduct an entirely new unrelated DPIA as though the CRM does not exist
- Submit the AI module to the supervisory authority for pre-approval regardless of risk level
Correct answer: Review and update the existing DPIA to capture the new risks introduced by the AI module
A material change in processing — such as adding AI-driven profiling — requires revisiting and updating the DPIA to ensure all new risks are assessed.
An organization transfers personal data to a country lacking an EU adequacy decision.
How does this affect the DPIA process?