Conducting a data protection impact assessment: Under GDPR, which obligation is most directly triggered before
High-risk processing like large-scale profiling with new technology requires a DPIA before processing begins.
The question
A controller plans large-scale automated profiling of individuals with significant effects, using a new AI system. Under GDPR, which obligation is most directly triggered before processing begins?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Registering the AI system as a high-risk product with a national market-surveillance authority before any launch date.Plausible but wrong: that concept comes from product/AI-Act regimes, not the GDPR obligation triggered here.
- Conducting a data protection impact assessment, since high-risk profiling with new technology triggers the DPIA duty. ✓Correct: high-risk processing such as large-scale profiling with new technology requires a DPIA before processing.
- Publishing the model's full source code so that affected data subjects can independently audit every decision it makes.Wrong: GDPR requires no publication of source code.
- Appointing an external auditor to certify the model's accuracy before any personal data may lawfully be processed at all.Wrong: no external accuracy certification is required as a precondition to processing.
The trap
Confusing the GDPR DPIA duty with EU AI Act product registration or certification concepts. How to remember it
High-risk processing like large-scale profiling with new technology requires a DPIA before processing begins.
How many of these would you get right?
One of 499 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Inclusive growth: Which option lists the OECD AI principles rather than another framework's structure? →
- A design-defect theory: Which product-liability theory most directly fits a flaw inherent in the design? →
- Transparency, which requires informing individuals about: Applying core data protection principles, which →
- All 125 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.