A privacy team builds a shortlist of processing that likely needs a DPIA, including systematic monitoring and large-scale special-category processing. What does that shortlist correctly reflect?
Select an answer to reveal the explanation.
Short Explanation
Think of a DPIA shortlist like a fire-code checklist for risky kitchens—systematic watching of people or special-category data at scale is the grease fire waiting to happen. Those known triggers tell you when a deeper risk look is expected.
Full Explanation
GDPR and EDPB/WP29 guidance identify types of processing likely to result in high risk—such as systematic monitoring and large-scale processing of special categories—for which a DPIA is required. Using those criteria to inventory candidates is sound accountability practice. DPIAs are not optional brochures, and authorities do not ban risk inventories.