An AI risk manager at a large insurance company receives a request to deploy an AI model that uses telematics data from smartphones to assess driver risk for auto insurance. The model uses 47 features derived from smartphone accelerometer and GPS data. Which privacy risk assessment step is MOST important before deployment?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because continuous smartphone-based location and behavioral monitoring represents high-risk processing of sensitive personal data that requires a full DPIA under GDPR (and similar regulations). The DPIA must assess proportionality (is 47-feature smartphone monitoring necessary for the purpose?), data subject rights (can customers access, correct, or delete their data?), and consent quality.
Full explanation below image
Full Explanation
B is correct because continuous smartphone-based location and behavioral monitoring represents high-risk processing of sensitive personal data that requires a full DPIA under GDPR (and similar regulations). The DPIA must assess proportionality (is 47-feature smartphone monitoring necessary for the purpose?), data subject rights (can customers access, correct, or delete their data?), and consent quality. Encryption (A) is a security control, not the primary privacy assessment step. Feature content (C) misses the broader privacy impact of behavioral monitoring. Storage location (D) is an operational security concern.