A DPIA concludes that residual risk to data subjects remains high after all planned measures. The controller wants to start processing immediately. What must the controller do first under GDPR?
Select an answer to reveal the explanation.
Short Explanation
If the safety check still screams 'danger' after you bolted on every fix, you don't just open the ride—you call the inspector. Same idea: high residual risk after a DPIA means talk to the supervisory authority before you go live.
Full Explanation
Where a DPIA indicates that processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk, and residual risk remains high, the controller must consult the supervisory authority prior to processing. Skipping consultation to start immediately undermines the prior-consultation safeguard. Destroying the DPIA or inventing unrelated criminal steps does not satisfy Article 36.