An organization's AI policy states that all AI systems processing sensitive personal data must conduct a Data Protection Impact Assessment (DPIA). An AI system analyzes employee emails to detect insider threats. Which DPIA finding would MOST likely require escalation to the supervisory authority under GDPR?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — c is correct because under GDPR Article 36, when a DPIA indicates that the processing would result in high risks that the controller cannot sufficiently mitigate, the controller must consult the supervisory authority before proceeding. If residual risks remain high after all feasible mitigations, this is precisely the trigger for prior consultation with the data protection authority.
Full explanation below image
Full Explanation
C is correct because under GDPR Article 36, when a DPIA indicates that the processing would result in high risks that the controller cannot sufficiently mitigate, the controller must consult the supervisory authority before proceeding. If residual risks remain high after all feasible mitigations, this is precisely the trigger for prior consultation with the data protection authority. The number of employees (A) is relevant to DPIA triggering thresholds but not to authority escalation. Precision below 80% (B) is a performance concern. Retention duration (D) may be a compliance issue but does not alone trigger authority escalation.