Complete a DPIA: Acting as the GDPR data controller, which combination of measures must be in place before
As controller the bank must run a DPIA, bind the US vendor with an Article 28 contract and a Chapter V transfer tool, and provide Article 22 human-oversight safeguards.
The question
An EU bank plans to launch a model that makes solely-automated credit decisions on consumers, hosted by a US cloud vendor that processes the personal data abroad, with monthly retraining on new applicant data. Acting as the GDPR data controller, which combination of measures must be in place before go-live?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Rely on legitimate interests as the sole basis, treat the US vendor as an independent controller, and keep decision logs for audit while omitting any human-review pathway for applicants.Plausible because legitimate interests and audit logging are real GDPR tools, but Article 22 requires human-intervention safeguards for solely-automated decisions and a processor is not an independent controller.
- Obtain explicit consent to cover retraining, classify the vendor as a sub-processor acting for the data subject, and rely on a general adequacy assumption to legitimize all of the US data transfers.Almost right because consent is one Art. 22 basis, but a vendor is a processor for the controller (not the data subject) and there is no blanket adequacy assumption covering all US transfers.
- Register the model with the supervisory authority, appoint a dedicated DPO inside the vendor, and grant each applicant a statutory right to demand a second fully automated decision on appeal.Plausible-sounding but GDPR has no general model-registration duty, the DPO sits with the controller, and Art. 22 grants human review rather than a right to a second automated decision.
- Complete a DPIA, sign an Article 28 processor contract with the vendor plus a valid Chapter V transfer mechanism, and give applicants Article 22 safeguards such as human intervention and contest. ✓Correct: high-risk profiling with legal effect triggers a DPIA (Art. 35(3)(a)), the vendor is a processor needing an Art. 28 contract, transfers abroad need a Ch. V mechanism, and Art. 22 requires safeguards.
The trap
Believing audit logging and legitimate interests substitute for the Article 22 human-intervention safeguards. How to remember it
As controller the bank must run a DPIA, bind the US vendor with an Article 28 contract and a Chapter V transfer tool, and provide Article 22 human-oversight safeguards.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Building data-protection safeguards into the system: Which action best reflects that principle at the design →
- Biometric templates used to uniquely identify staff are: Under GDPR, which analysis best fits processing this →
- Copyright can restrict use of the scraped works: Considering intellectual property law and the EU AI Act →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.