IT enables continuous keystroke logging for every remote worker without a DPIA. Which statement best reflects GDPR accountability expectations?
Select an answer to reveal the explanation.
Short Explanation
Logging every keystroke for the whole remote workforce is not a casual IT tweak—it’s high-intrusion monitoring. Do the risk homework (often a DPIA) before you flip the switch. Skipping that is accountability theatre.
Full Explanation
Article 35 GDPR requires a DPIA where processing is likely to result in a high risk to individuals, including systematic monitoring on a large scale. Continuous keystroke logging of employees is highly intrusive and typically triggers that expectation. Completing a DPIA before deployment supports necessity, proportionality, and mitigation choices and demonstrates accountability.