AIGP - Understanding how laws, standards and frameworks apply to AI - Section 2.2

Understand how obligations on data controllers apply to AI, covering privacy impact assessments, third-party processors, cross-border transfers, data subject rights, and breach notification.

Apply data controller obligations to AI deployments, covering DPIAs, third-party processor agreements, cross-border data transfers, data subject rights, and breach notification. Distinguish when an AI system triggers each obligation and what documentation it requires.

DPIAdata subject rightscross-border data transfersbreach notification

Practice question for this objective

Free sampleUnderstanding how laws, standards and frameworks apply to AIhard

A data protection impact assessment under the GDPR and a fundamental rights impact assessment under the EU AI Act can both apply to the same high-risk AI system that processes personal data. Which statement correctly distinguishes what each assessment is concerned with?

  • ABoth assessments examine the identical question and apply the same legal trigger, so completing one of them automatically discharges the controller's duty to complete the other for that AI system.
  • BThe data protection impact assessment is a voluntary best practice, while the fundamental rights impact assessment is the only one of the two that is ever legally mandatory.
  • CThe fundamental rights impact assessment covers only cybersecurity threats to the AI system, while the data protection impact assessment covers everything else about the deployment.
  • DThe data protection impact assessment focuses on risks to individuals' personal data and privacy, while the fundamental rights impact assessment addresses broader effects of the AI system on fundamental rights. Correct
A GDPR data protection impact assessment centres on personal-data and privacy risks, while an EU AI Act fundamental rights impact assessment addresses broader effects on fundamental rights. These are two distinct instruments. The GDPR data protection impact assessment evaluates risks to individuals' rights and freedoms that flow from processing personal data, while the EU AI Act fundamental rights impact assessment evaluates how a high-risk AI system may affect fundamental rights more broadly. Their scopes overlap and their findings can be reused, but neither is voluntary where it applies, and completing one does not automatically discharge the duty to complete the other.

Why A is wrong: The overlap between the two assessments makes this tempting, but they arise under different instruments with different scopes, so one does not automatically satisfy the other even though their findings can inform each other.

Why B is wrong: Casting the data protection impact assessment as voluntary is wrong, since the GDPR makes it mandatory for high-risk processing; both assessments can be legally required depending on the circumstances.

Why C is wrong: Reducing the fundamental rights impact assessment to cybersecurity misstates its scope, which concerns effects on fundamental rights, so although security is one consideration this mischaracterises what the assessment is for.

Why D is correct: The GDPR data protection impact assessment is centred on risks to the rights and freedoms arising from the processing of personal data, whereas the EU AI Act fundamental rights impact assessment looks more broadly at how a high-risk AI system may affect fundamental rights, which is the correct distinction.

See more AIGP practice questions, answers explained.

More in this domain

Back to all Understanding how laws, standards and frameworks apply to AI objectives, or the AIGP cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.