AIGP - Understanding how laws, standards and frameworks apply to AI (25% of the exam) - Section 2.2

Understand how obligations on data controllers apply to AI, covering privacy impact assessments, third-party processors, cross-border transfers, data subject rights, and breach notification.

Apply data controller obligations to AI deployments, covering DPIAs, third-party processor agreements, cross-border data transfers, data subject rights, and breach notification. Distinguish when an AI system triggers each obligation and what documentation it requires.

DPIAdata subject rightscross-border data transfersbreach notification

Practice question for this objective

Free sampleUnderstanding how laws, standards and frameworks apply to AIhard

A data protection impact assessment under the GDPR and a fundamental rights impact assessment under the EU AI Act can both apply to the same high-risk AI system that processes personal data. Which statement correctly distinguishes what each assessment is concerned with?

  • ABoth assessments examine the identical question and apply the same legal trigger, so completing one of them automatically discharges the controller's duty to complete the other for that AI system.
  • BThe data protection impact assessment is a voluntary best practice, while the fundamental rights impact assessment is the only one of the two that is ever legally mandatory.
  • CThe fundamental rights impact assessment covers only cybersecurity threats to the AI system, while the data protection impact assessment covers everything else about the deployment.
  • DThe data protection impact assessment focuses on risks to individuals' personal data and privacy, while the fundamental rights impact assessment addresses broader effects of the AI system on fundamental rights. Correct
A GDPR data protection impact assessment centres on personal-data and privacy risks, while an EU AI Act fundamental rights impact assessment addresses broader effects on fundamental rights. These are two distinct instruments. The GDPR data protection impact assessment evaluates risks to individuals' rights and freedoms that flow from processing personal data, while the EU AI Act fundamental rights impact assessment evaluates how a high-risk AI system may affect fundamental rights more broadly. Their scopes overlap and their findings can be reused, but neither is voluntary where it applies, and completing one does not automatically discharge the duty to complete the other.

Why A is wrong: The overlap between the two assessments makes this tempting, but they arise under different instruments with different scopes, so one does not automatically satisfy the other even though their findings can inform each other.

Why B is wrong: Casting the data protection impact assessment as voluntary is wrong, since the GDPR makes it mandatory for high-risk processing; both assessments can be legally required depending on the circumstances.

Why C is wrong: Reducing the fundamental rights impact assessment to cybersecurity misstates its scope, which concerns effects on fundamental rights, so although security is one consideration this mischaracterises what the assessment is for.

Why D is correct: The GDPR data protection impact assessment is centred on risks to the rights and freedoms arising from the processing of personal data, whereas the EU AI Act fundamental rights impact assessment looks more broadly at how a high-risk AI system may affect fundamental rights, which is the correct distinction.

See more AIGP practice questions, answers explained.

Exam traps in Understanding how laws, standards and frameworks apply to AI

Answers that look right on this material and are not. Each one is a distractor from a different question in the AIGP bank for this domain.

  • Notify the competent supervisory authority directly within 72 hours of becoming aware of the breach, since the processor handled the affected personal data when the incident occurred.

    Why it is wrong: The 72-hour clock is real, but it binds the controller's duty to the supervisory authority; a processor that notifies the authority directly is performing the wrong party's obligation under the GDPR's breach-notification scheme.

  • Notify the supervisory authority within 72 hours, but never notify the affected individuals, since that is solely the processor's responsibility.

    Why it is wrong: The 72 hour figure is correct for the authority, which makes this partly right, but the duty to communicate a high-risk breach to data subjects rests with the controller, not the processor, so the second half is wrong.

  • The processor may appoint any sub-processor at will, as long as it tells the controller within a reasonable time after the sub-processor has started work.

    Why it is wrong: After-the-fact notice sounds cooperative, but the GDPR requires the controller's authorisation before another processor is engaged, so allowing free appointment with later notice does not meet the standard.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.