Carry out a data protection impact assessment: Considering the controller's obligations, which step is
Solely-automated decisions with legal or similarly significant effects are a mandatory DPIA trigger the controller must satisfy before processing.
The question
A retailer deploys a third-party vendor's model that makes solely-automated credit decisions producing legal effects for applicants. Considering the controller's obligations, which step is required before this processing begins?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Sign a data processing agreement with the vendor and treat a separate impact assessment as optional, since the vendor already tested the model.Plausible because a processor contract is required, but vendor testing does not discharge the controller's own DPIA duty here.
- Notify the supervisory authority of a personal data breach within 72 hours of switching the automated decision system live.Plausible as a real controller duty, but breach notification applies to breaches, not to launching lawful automated processing.
- Carry out a data protection impact assessment, because systematic automated evaluation with significant effects is a mandatory trigger. ✓Correct: systematic, extensive automated evaluation producing legal or similarly significant effects is a mandatory DPIA trigger for the controller.
- Obtain explicit consent from every applicant, which on its own removes any need for an impact assessment or added safeguards.Plausible since consent can permit automated decisions, but consent does not eliminate a mandatory DPIA or the required safeguards.
The trap
Assuming that using a third-party processor or obtaining consent removes the controller's obligation to perform a DPIA. How to remember it
Solely-automated decisions with legal or similarly significant effects are a mandatory DPIA trigger the controller must satisfy before processing.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Collect only the personal data that is adequate: Which practice best reflects the data minimization and →
- Processing is prohibited by default and requires: Because this involves a special category of personal data, →
- Copyright may prohibit or limit using the material: From an intellectual-property standpoint, which →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.