A lender deploys an ML credit-scoring model affecting EU consumers without bias testing, explainability review, or GDPR-aligned assessment of profiling safeguards. Which conclusion fits CIPP/E Domain 5 technology compliance?
Select an answer to reveal the explanation.
Short Explanation
Credit scores change lives—so 'ship the model and hope' is not a privacy strategy. Bias, opacity, and missing human-review paths collide with GDPR fairness and ADM rules. Do the hard review before the model decides someone's loan.
Full Explanation
Profiling and automated decision-making that significantly affect individuals engage GDPR principles of fairness, transparency, and accuracy, and may trigger Art. 22 safeguards and DPIA obligations for high-risk processing. Ethical AI concerns such as bias and opacity are not separate theatre: they map onto those legal duties in lending contexts. Controllers should assess and document safeguards rather than treating model secrecy or sector licensing as a GDPR exemption.