A DPIA for a new analytics platform leaves the international-transfer section blank even though EU personal data will be hosted and accessed from outside the EEA. What accountability expectation is unmet?
Select an answer to reveal the explanation.
Short Explanation
If data are leaving the EEA, the risk story has a boarding-pass chapter—you don’t leave that page empty. DPIAs and transfer assessments should talk about where data go and what could go wrong abroad. A random encryption shout-out in an appendix is not the same as analysing the transfer.
Full Explanation
Accountability and risk-assessment practice expect controllers to identify and evaluate international transfer risks when processing involves exporting or remotely accessing personal data outside the EEA. That analysis may appear in a DPIA and/or a dedicated transfer impact assessment aligned with EDPB themes. Omitting transfers, relying on a vague encryption mention, or inventing arbitrary numeric thresholds does not meet that expectation.