CIPP-E - European Data Protection: Scope and Accountability - Section 4.3

Understand the role of data protection impact assessments (DPIAs), know the criteria for when they are mandatory, and understand the requirement for mandatory data protection officers (DPOs).

Explain when a data protection impact assessment is mandatory under Article 35 GDPR - such as large-scale processing of special categories or systematic monitoring of public areas - and describe the steps involved. Understand the Article 37 criteria that oblige an organisation to designate a data protection officer and the independence requirements that role carries.

DPIAArticle 35 GDPRDPOArticle 37 GDPR

Practice question for this objective

Free sampleEuropean Data Protection: Scope and Accountabilitymedium

A controller is about to begin a data protection impact assessment for a new patient-monitoring platform. The organisation has designated a data protection officer. As the controller carries out the assessment, what does the GDPR specifically require it to do in relation to that data protection officer?

  • ATransfer responsibility for completing the assessment entirely to the data protection officer, who must sign it off personally.
  • BObtain the data protection officer's written authorisation before any data subjects can be consulted about the processing.
  • CSeek the advice of the data protection officer when carrying out the assessment. Correct
  • DSend the completed assessment to the data protection officer only after the processing has gone live, for record-keeping.
Know that Article 35(2) GDPR obliges a controller to seek the advice of its designated DPO when carrying out a data protection impact assessment. Article 35(2) places a duty on the controller to seek the DPO's advice where a DPO has been designated, and Article 39(1)(c) lists advising on and monitoring the DPIA as a DPO task. The controller remains accountable for the assessment; the DPO advises rather than owns or approves it.

Why A is wrong: This overstates the DPO's role; accountability for the DPIA rests with the controller, and making the DPO the responsible author would compromise the independent monitoring function the DPO is meant to perform.

Why B is wrong: Consulting data subjects is a separate matter governed by Article 35(9), which is framed as appropriate where relevant; it is the controller, not the DPO, who decides on and conducts that consultation, and no DPO authorisation gate exists.

Why C is correct: Article 35(2) GDPR requires the controller to seek the advice of the DPO, where one is designated, when carrying out a DPIA; advising on and monitoring DPIA performance is also one of the DPO's tasks under Article 39(1).

Why D is wrong: Involving the DPO only after go-live defeats the purpose of advice during the assessment; Article 35(2) requires the controller to seek the DPO's advice while carrying out the DPIA, not merely to archive it afterwards.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all European Data Protection: Scope and Accountability objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.