A Data Protection Impact Assessment: Under GDPR controller | AIGP
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

A Data Protection Impact Assessment: Under GDPR controller obligations, which step is required before

AIGP Understanding How Laws, Standards and Frameworks Apply to AI Medium

Systematic automated profiling with significant effects is a mandatory DPIA trigger under Article 35(3)(a).

The question

A lender wants to introduce an AI model that systematically evaluates applicants through automated profiling and materially affects who receives credit. Under GDPR controller obligations, which step is required before processing begins?

Preparing for AIGP? Take the free 5-min readiness quiz →

  1. A Data Protection Impact Assessment, because systematic and extensive automated evaluation producing significant effects on individuals is a mandatory trigger for a DPIA.
    Correct: Art. 35(3)(a) makes a DPIA mandatory for systematic, extensive automated evaluation with legal or similarly significant effects on individuals.
  2. A short internal memo noting the model exists is enough, because a formal assessment is only ever needed once the model has already produced its first adverse credit decisions.
    Plausible-sounding but the assessment must precede processing; waiting until the first adverse decision misstates the timing of the obligation.
  3. A cross-border transfer agreement, because any credit-scoring model that profiles applicants is deemed to move their personal data into another jurisdiction for processing.
    Almost plausible but transfer agreements are only needed when data actually crosses borders, which the scenario does not establish; the trigger here is high-risk profiling.
  4. A breach notification to the supervisory authority, because deploying an automated profiling model is treated as an incident that must be reported before it goes live.
    Plausible-sounding but deployment is not a personal-data breach, so breach notification is not the pre-processing step required here.
The trap
Believing the impact assessment can wait until after the model makes its first decisions.

How to remember it

Systematic automated profiling with significant effects is a mandatory DPIA trigger under Article 35(3)(a).

How many of these would you get right?

One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.

Test your AIGP readiness — free

More Understanding How Laws, Standards and Frameworks Apply to AI questions

Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI · Every answer, right and wrong, comes with its own explanation.