A Data Protection Impact Assessment: Under GDPR controller obligations, which step is required before
Systematic automated profiling with significant effects is a mandatory DPIA trigger under Article 35(3)(a).
The question
A lender wants to introduce an AI model that systematically evaluates applicants through automated profiling and materially affects who receives credit. Under GDPR controller obligations, which step is required before processing begins?
Preparing for AIGP? Take the free 5-min readiness quiz →
- A Data Protection Impact Assessment, because systematic and extensive automated evaluation producing significant effects on individuals is a mandatory trigger for a DPIA. ✓Correct: Art. 35(3)(a) makes a DPIA mandatory for systematic, extensive automated evaluation with legal or similarly significant effects on individuals.
- A short internal memo noting the model exists is enough, because a formal assessment is only ever needed once the model has already produced its first adverse credit decisions.Plausible-sounding but the assessment must precede processing; waiting until the first adverse decision misstates the timing of the obligation.
- A cross-border transfer agreement, because any credit-scoring model that profiles applicants is deemed to move their personal data into another jurisdiction for processing.Almost plausible but transfer agreements are only needed when data actually crosses borders, which the scenario does not establish; the trigger here is high-risk profiling.
- A breach notification to the supervisory authority, because deploying an automated profiling model is treated as an incident that must be reported before it goes live.Plausible-sounding but deployment is not a personal-data breach, so breach notification is not the pre-processing step required here.
The trap
Believing the impact assessment can wait until after the model makes its first decisions. How to remember it
Systematic automated profiling with significant effects is a mandatory DPIA trigger under Article 35(3)(a).
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Data minimization and privacy by design: Which data-protection concept does this approach most directly →
- Processing special-category data such as health: Under GDPR, which statement best describes the baseline rule →
- The research-only licence does not authorize commercial: Considering intellectual property law, which →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.