A controller is about to begin a data protection impact assessment for a new patient-monitoring platform. The organisation has designated a data protection officer. As the controller carries out the assessment, what does the GDPR specifically require it to do in relation to that data protection officer?
- ATransfer responsibility for completing the assessment entirely to the data protection officer, who must sign it off personally.
- BObtain the data protection officer's written authorisation before any data subjects can be consulted about the processing.
- CSeek the advice of the data protection officer when carrying out the assessment. Correct
- DSend the completed assessment to the data protection officer only after the processing has gone live, for record-keeping.
Why A is wrong: This overstates the DPO's role; accountability for the DPIA rests with the controller, and making the DPO the responsible author would compromise the independent monitoring function the DPO is meant to perform.
Why B is wrong: Consulting data subjects is a separate matter governed by Article 35(9), which is framed as appropriate where relevant; it is the controller, not the DPO, who decides on and conducts that consultation, and no DPO authorisation gate exists.
Why C is correct: Article 35(2) GDPR requires the controller to seek the advice of the DPO, where one is designated, when carrying out a DPIA; advising on and monitoring DPIA performance is also one of the DPO's tasks under Article 39(1).
Why D is wrong: Involving the DPO only after go-live defeats the purpose of advice during the assessment; Article 35(2) requires the controller to seek the DPO's advice while carrying out the DPIA, not merely to archive it afterwards.