A controller plans black-box profiling of vulnerable individuals yet completes only a one-page form ticking ‘low risk’ with no analysis of impacts or mitigations. How should that DPIA practice be judged?
Select an answer to reveal the explanation.
Short Explanation
Calling skydiving ‘low risk’ on a sticky note is not a safety review. High-risk black-box profiling of vulnerable people needs a real look at harms and safeguards. A one-page tick does not earn Article 35 credit.
Full Explanation
Article 35 requires an assessment of the impact of envisaged processing on personal data protection where high risk is likely, including systematic and extensive evaluation based on automated processing/profiling. The DPIA must describe processing, assess necessity/proportionality, evaluate risks, and identify measures. Superficial tickboxes fail that standard. Controllers remain responsible for the assessment; ML use does not waive DPIA duties.