When a GDPR Data Protection Impact Assessment (DPIA) identifies a high residual risk that cannot be mitigated, what must the data controller do?
-
A
Proceed with processing and document the risk
-
B
Consult with the supervisory authority before processing
-
C
Appoint an external Data Protection Officer
-
D
Obtain explicit consent from all data subjects