Certified Information Privacy Professional – Europe (CIPP/E) — Question 89
Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?
Answer options
- A. A company wants to combine location data with other data in order to offer more personalized service for the customer.
- B. A company wants to use location data to infer information on a person’s clothes purchasing habits.
- C. A company wants to build a dating app that creates candidate profiles based on location data and data from third-party sources.
- D. A company wants to use location data to track delivery trucks in order to make the routes more efficient.
Correct answer: C
Explanation
The correct answer is C because building a dating app that uses sensitive personal data from various sources raises significant privacy risks, thus requiring a DPIA under GDPR. Options A and B involve less risky processing of data and do not necessarily require a DPIA. Option D focuses on operational efficiency without significant privacy concerns, which is why it does not trigger a DPIA.