Carry out a data protection impact assessment: Considering | AIGP
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

Carry out a data protection impact assessment: Considering the controller's obligations, which step is

AIGP Understanding How Laws, Standards and Frameworks Apply to AI Medium

Solely-automated decisions with legal or similarly significant effects are a mandatory DPIA trigger the controller must satisfy before processing.

The question

A retailer deploys a third-party vendor's model that makes solely-automated credit decisions producing legal effects for applicants. Considering the controller's obligations, which step is required before this processing begins?

Preparing for AIGP? Take the free 5-min readiness quiz →

  1. Sign a data processing agreement with the vendor and treat a separate impact assessment as optional, since the vendor already tested the model.
    Plausible because a processor contract is required, but vendor testing does not discharge the controller's own DPIA duty here.
  2. Notify the supervisory authority of a personal data breach within 72 hours of switching the automated decision system live.
    Plausible as a real controller duty, but breach notification applies to breaches, not to launching lawful automated processing.
  3. Carry out a data protection impact assessment, because systematic automated evaluation with significant effects is a mandatory trigger.
    Correct: systematic, extensive automated evaluation producing legal or similarly significant effects is a mandatory DPIA trigger for the controller.
  4. Obtain explicit consent from every applicant, which on its own removes any need for an impact assessment or added safeguards.
    Plausible since consent can permit automated decisions, but consent does not eliminate a mandatory DPIA or the required safeguards.
The trap
Assuming that using a third-party processor or obtaining consent removes the controller's obligation to perform a DPIA.

How to remember it

Solely-automated decisions with legal or similarly significant effects are a mandatory DPIA trigger the controller must satisfy before processing.

How many of these would you get right?

One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.

Test your AIGP readiness — free

More Understanding How Laws, Standards and Frameworks Apply to AI questions

Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI · Every answer, right and wrong, comes with its own explanation.