Complete a DPIA: Acting as the GDPR data controller | AIGP
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

Complete a DPIA: Acting as the GDPR data controller, which combination of measures must be in place before

AIGP Understanding How Laws, Standards and Frameworks Apply to AI Hard

As controller the bank must run a DPIA, bind the US vendor with an Article 28 contract and a Chapter V transfer tool, and provide Article 22 human-oversight safeguards.

The question

An EU bank plans to launch a model that makes solely-automated credit decisions on consumers, hosted by a US cloud vendor that processes the personal data abroad, with monthly retraining on new applicant data. Acting as the GDPR data controller, which combination of measures must be in place before go-live?

Preparing for AIGP? Take the free 5-min readiness quiz →

  1. Rely on legitimate interests as the sole basis, treat the US vendor as an independent controller, and keep decision logs for audit while omitting any human-review pathway for applicants.
    Plausible because legitimate interests and audit logging are real GDPR tools, but Article 22 requires human-intervention safeguards for solely-automated decisions and a processor is not an independent controller.
  2. Obtain explicit consent to cover retraining, classify the vendor as a sub-processor acting for the data subject, and rely on a general adequacy assumption to legitimize all of the US data transfers.
    Almost right because consent is one Art. 22 basis, but a vendor is a processor for the controller (not the data subject) and there is no blanket adequacy assumption covering all US transfers.
  3. Register the model with the supervisory authority, appoint a dedicated DPO inside the vendor, and grant each applicant a statutory right to demand a second fully automated decision on appeal.
    Plausible-sounding but GDPR has no general model-registration duty, the DPO sits with the controller, and Art. 22 grants human review rather than a right to a second automated decision.
  4. Complete a DPIA, sign an Article 28 processor contract with the vendor plus a valid Chapter V transfer mechanism, and give applicants Article 22 safeguards such as human intervention and contest.
    Correct: high-risk profiling with legal effect triggers a DPIA (Art. 35(3)(a)), the vendor is a processor needing an Art. 28 contract, transfers abroad need a Ch. V mechanism, and Art. 22 requires safeguards.
The trap
Believing audit logging and legitimate interests substitute for the Article 22 human-intervention safeguards.

How to remember it

As controller the bank must run a DPIA, bind the US vendor with an Article 28 contract and a Chapter V transfer tool, and provide Article 22 human-oversight safeguards.

How many of these would you get right?

One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.

Test your AIGP readiness — free

More Understanding How Laws, Standards and Frameworks Apply to AI questions

Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI · Every answer, right and wrong, comes with its own explanation.