Conducting a data protection impact assessment to evaluate: Before deployment, which controller obligation is
Systematic, extensive automated evaluation with significant effects triggers a data protection impact assessment before deployment.
The question
A bank plans to deploy an AI system that will systematically and extensively evaluate loan applicants through automated profiling, producing decisions that significantly affect them. Before deployment, which controller obligation is most directly triggered by this kind of processing?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Appointing an external auditor to certify the model's statistical accuracy before it may lawfully operate at allPlausible but wrong: privacy law does not require external accuracy certification as the triggered pre-deployment duty here.
- Obtaining explicit written consent from every applicant to store their financial records on the serversPlausible but wrong: consent for storage is a different issue and is not the specific obligation this processing profile triggers.
- Notifying the supervisory authority of a personal data breach within the applicable reporting windowPlausible but wrong: breach notification applies after an incident occurs, not as a pre-deployment assessment duty.
- Conducting a data protection impact assessment to evaluate and mitigate the high risks of the processing ✓Correct: systematic, extensive automated evaluation with significant effects is a classic trigger for a data protection impact assessment.
The trap
Choosing a reactive breach-notification duty over the pre-deployment impact assessment. How to remember it
Systematic, extensive automated evaluation with significant effects triggers a data protection impact assessment before deployment.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Privacy by design paired with data minimization: Which pair of data protection concepts best matches this →
- It is treated as a special category warranting heightened: Compared with ordinary personal data, how do data →
- Intellectual property law: Which legal domain most directly governs whether that training use of the material →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.